News Editors
Latest news
Investigation
News report

FBI scrambling after breach exposes personnel data, officials say

Hackers claimed to have stolen sensitive information on bureau employees; the FBI vowed to pursue the group

FBI scrambling after breach exposes personnel data, officials say
News Editors
News Editors

Editorial team

Published Sep 28, 2026

Updated Monday, September 28, 2026 - 12:00 PMSep 28, 2026, 12:00 PM

Sources and methodology disclosed belowHow we verify stories

The brief

What to know

  • A hacking group claimed it stole sensitive FBI personnel data.
  • The compromise appears tied to a jobs-related system rather than core investigative networks.
  • The FBI has publicly vowed to pursue the attackers and is assessing employee risk.

Why it matters

Personnel data exposure can endanger agents and staff and reveals weaknesses in systems that sit outside the bureau's most hardened networks.

The FBI is investigating a breach of a personnel-related system after a well-known hacking group claimed it stole sensitive data on bureau employees, according to officials and public statements from the group.

In an internal memo described by people familiar with it, the bureau said it believed the intruders may have obtained information covering a large share of its workforce. The precise categories of data and the number of affected employees remain under assessment.

What is known

The compromise appears to have involved a jobs or applicant-related website rather than the FBI's core investigative networks. Even so, personnel records can include home addresses, contact information and other details that raise safety concerns for agents and staff.

Brett Leatherman, a senior cyber official at the FBI, released a video statement saying the bureau knows how to find the perpetrators and will pursue them. The statement did not disclose the full scope of the loss.

The hacking group

The group known as ShinyHunters has a track record of stealing large volumes of personal data and offering it for sale. Security researchers have linked the group to multiple high-profile breaches in recent years across technology and government-adjacent targets.

Attribution in cyber cases is often provisional in the early days. The FBI has not publicly confirmed every claim made by the group, but it has treated the incident as a serious personnel-security event.

Response and risks

Employees have been advised to monitor for phishing and physical-security risks. The bureau is working with partner agencies to assess whether any of the exposed data has appeared on criminal markets.

Lawmakers who oversee the FBI said they expect a classified briefing on the breach and on steps to harden personnel systems that sit outside the main investigative infrastructure.

Transparency

Sources & reading notes

How we write

This report is based on public statements, court filings and contemporaneous coverage of the events described.

Spot something that needs attention? Review our corrections process.