The Federal Bureau of Investigation is actively working to determine the origin of a cybersecurity incident involving its official jobs website, FBIJobs.gov. This investigation comes as a criminal hacking collective has asserted it acquired sensitive personal information belonging to bureau employees and individuals who applied for positions.
On Thursday, the agency acknowledged the situation in a post, stating, "The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII)." The statement further elaborated, "While the point of breach is still undetermined — whether a third-party or the FBI’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk."
Hacking Group Alleges Extensive Data Theft
The group claiming responsibility for the intrusion is ShinyHunters, a known criminal hacking and extortion organization. They have indicated that the stolen data encompasses details for nearly all FBI agents and prospective applicants. According to reports, a sample of the alleged data included agents’ names, residential addresses, Social Security numbers, job assignments, and, in some instances, names of family members.
Expert Warns of Heightened Security and Counterintelligence Risks
Jason Pack, CEO of Media Rep Global Strategies and a former FBI supervisory special agent, emphasized the crucial distinction between a breach of personnel data and unauthorized access to the FBI’s classified systems. He highlighted that investigators must clearly define the scope of the incident.
Pack noted that combining personal identifying information with details about an FBI employee's professional role could significantly amplify security vulnerabilities. "If an adversary knows who somebody is, where they work and what they do, they can build a much more believable scam around that person," he explained.
Furthermore, Pack pointed to potential counterintelligence ramifications if assignment-specific information were to fall into the hands of foreign intelligence services. "There is also a counterintelligence concern. If a foreign intelligence service can associate particular people with certain assignments, it can help them identify individuals they may want to learn more about, approach or potentially assess for recruitment," he stated. He clarified, however, that this observation is hypothetical: "That does not mean that is happening here. It simply explains why assignment information can have value to an adversary."
Ongoing Investigation and Mitigation Efforts
Pack underscored that the claims made by the hackers remain distinct from what the FBI has officially confirmed. He stressed the bureau's ongoing need to ascertain precisely what information was accessed, how the breach occurred, and who may have been affected.
He also cautioned against assuming that the danger ceases once a technical vulnerability is patched. "The danger from stolen personal information does not necessarily end when the computer vulnerability is fixed," Pack said. "Criminals may hold onto that information and use it weeks or months later."
The FBI has confirmed its continued collaboration with the third-party providers responsible for supporting the FBIJobs.gov portal as it works to identify the source of the breach and alleviate any potential risks associated with the incident.




