{*}
Add news
March 2010 April 2010 May 2010 June 2010 July 2010
August 2010
September 2010 October 2010 November 2010 December 2010 January 2011 February 2011 March 2011 April 2011 May 2011 June 2011 July 2011 August 2011 September 2011 October 2011 November 2011 December 2011 January 2012 February 2012 March 2012 April 2012 May 2012 June 2012 July 2012 August 2012 September 2012 October 2012 November 2012 December 2012 January 2013 February 2013 March 2013 April 2013 May 2013 June 2013 July 2013 August 2013 September 2013 October 2013 November 2013 December 2013 January 2014 February 2014 March 2014 April 2014 May 2014 June 2014 July 2014 August 2014 September 2014 October 2014 November 2014 December 2014 January 2015 February 2015 March 2015 April 2015 May 2015 June 2015 July 2015 August 2015 September 2015 October 2015 November 2015 December 2015 January 2016 February 2016 March 2016 April 2016 May 2016 June 2016 July 2016 August 2016 September 2016 October 2016 November 2016 December 2016 January 2017 February 2017 March 2017 April 2017 May 2017 June 2017 July 2017 August 2017 September 2017 October 2017 November 2017 December 2017 January 2018 February 2018 March 2018 April 2018 May 2018 June 2018 July 2018 August 2018 September 2018 October 2018 November 2018 December 2018 January 2019 February 2019 March 2019 April 2019 May 2019 June 2019 July 2019 August 2019 September 2019 October 2019 November 2019 December 2019 January 2020 February 2020 March 2020 April 2020 May 2020 June 2020 July 2020 August 2020 September 2020 October 2020 November 2020 December 2020 January 2021 February 2021 March 2021 April 2021 May 2021 June 2021 July 2021 August 2021 September 2021 October 2021 November 2021 December 2021 January 2022 February 2022 March 2022 April 2022 May 2022 June 2022 July 2022 August 2022 September 2022 October 2022 November 2022 December 2022 January 2023 February 2023 March 2023 April 2023 May 2023 June 2023 July 2023 August 2023 September 2023 October 2023 November 2023 December 2023 January 2024 February 2024 March 2024 April 2024 May 2024 June 2024 July 2024 August 2024 September 2024 October 2024 November 2024 December 2024 January 2025 February 2025 March 2025 April 2025 May 2025 June 2025 July 2025 August 2025 September 2025 October 2025 November 2025 December 2025 January 2026 February 2026 March 2026 April 2026 May 2026 June 2026 July 2026 August 2026 September 2026 October 2026
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
News Every Day |

FBI hack claim raises fears over sensitive personal data

If you have ever filled out a job application, handed over your Social Security number for a background check or trusted an organization with information about your family, pay attention to what happened at the FBI.

The cybercriminal group ShinyHunters claims it compromised FBIJobs.gov and stole highly sensitive information connected to current and former FBI personnel and people who applied for jobs at the bureau. The group says its haul reaches far beyond basic contact information.

On Sept. 23, the FBI acknowledged the group's claims and said it was "actively and aggressively investigating" the incident. The bureau said investigators had not yet determined whether the point of breach involved an FBI system or a third-party provider supporting FBIJobs.gov. 

That uncertainty is important. At the same time, samples provided to journalists contain enough real-world information to make the situation difficult to dismiss. For anyone whose details may be included, the potential fallout goes well beyond having an email address leaked.

FBI SAYS SOURCE OF ITS JOBS PORTAL BREACH STILL UNKNOWN AS HACKERS ALLEGE EMPLOYEE DATA COMPROMISED

Since that statement, the FBI has struck back by announcing the arrest of an alleged ShinyHunters leader in the Netherlands after a joint operation with Dutch authorities. Dutch police said a 24-year-old Amsterdam man was arrested Sept. 15.

Missed CyberGuy LIVE? Watch the replay and discover 5 ways AI can help you get better healthcare.

Our free CyberGuy LIVE class, Get Better Healthcare With AI, has ended, but you can still watch the full replay. Kurt "CyberGuy" Knutsson walks you through five practical ways AI can help you organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare smarter questions for your doctor. No technical experience is needed.

Watch the free replay + downloadable checklist now at CyberGuyLive.com

In its Sept. 23 statement, the FBI addressed both the alleged compromise and the uncertainty surrounding where the attackers may have gained access. 

"The FBI is aware of a cybercriminal enterprise group claiming a compromise of the fbijobs.gov portal," the bureau said. It added that the point of breach remained undetermined and said it was "actively and aggressively investigating this matter." 

The FBI also said investigators were working closely with third-party providers that support FBIJobs.gov to reduce potential risk. The FBI confirmed the investigation and the unresolved question about where the breach occurred. It did not verify ShinyHunters' full account of what the group says it stole.

The FBI's Special Agent Applicant Portal also became unavailable as the incident unfolded. A notice posted Sept. 22 said FBIJobs.gov and the Special Agent Applicant Portal were unavailable. The applicant portal supports people who have progressed through portions of the special-agent hiring process, making the type of information potentially involved especially sensitive.

CyberGuy reached out to the FBI for an update on the incident, including whether employee or applicant data was accessed and whether affected individuals are being notified or offered identity protection. We did not hear back before our deadline.

ShinyHunters provided journalists with a spreadsheet containing about 5,000 alleged FBI personnel records. Reuters reported that the spreadsheet included names, home addresses, phone numbers, dates of birth, Social Security numbers and emergency contact information. It also included information about field office assignments and, in some cases, sensitive intelligence or counterespionage work.

Reuters said it could not authenticate the entire spreadsheet. However, reporters independently verified details belonging to more than 22 people by comparing the information with credit records and earlier leaked data. Reuters also matched career information or job titles for eight people against court filings, news reports, public profiles and online posts.

That still does not establish where every record came from. Real information can appear in several databases or previous breaches. Yet the matches add credibility to at least portions of the sample. 404 Media separately reported that the 5,000-person sample contained names, home addresses, phone numbers and information involving FBI employees' spouses.

The personal information alone creates obvious privacy concerns. The reported job information raises another level of risk. Reuters found records identifying people connected to China-related investigations, Russian intelligence work, human intelligence operations and electronic surveillance. Other entries referenced covert access, clandestine technical operations and telecommunications interception. Reuters said it could not verify that every assignment was authentic or up to date.

On Sept. 23, 404 Media also reported that the data appeared to expose members of the FBI's Remote Operations Unit. The outlet describes the ROU as a secretive FBI team involved in developing and using hacking tools to gain access to target devices. Think about what that combination of information could provide to someone with bad intentions. 

A name may lead to a home address. An emergency contact could identify a spouse or child. Job information might reveal the kind of investigations someone works on. For an FBI employee working in a sensitive position, that creates risks far beyond ordinary financial fraud.

IS YOUR SOCIAL SECURITY NUMBER ON THE DARK WEB?

ShinyHunters says it breached the FBI and stole between 2 and 3 terabytes of information connected to FBI personnel and job applicants. The group has also claimed that Justice Department worker data was obtained. The hackers claim they exploited a previously unknown vulnerability involving Oracle PeopleSoft, software used for human resources and other enterprise functions.

FBI documents reportedly show its recruiting operation uses PeopleSoft and AWS GovCloud. However, that does not prove the hackers' claimed method of attack. The alleged PeopleSoft vulnerability, the claimed 2-to-3-terabyte haul and a broader compromise of FBI systems had not been independently verified.

Reuters also reported that ShinyHunters claimed to possess files involving employee and applicant vetting, contracted background investigations and sensitive medical information. Reuters said it could not verify what additional information the hackers actually possessed. That caveat is critical. ShinyHunters has an obvious interest in making its access sound as extensive as possible. For now, there are signs that portions of the information supplied by the hackers correspond to real people. Major questions about the source, scope and attack path remain unresolved in the FBI's public statement.

ShinyHunters says retaliation, rather than a demand for money, motivated the attack. The group points to warnings the FBI issued about ShinyHunters-related cyber activity earlier in 2026. On May 15, the FBI's Internet Crime Complaint Center published an advisory describing ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion.

The advisory warned that actors using the name may use real or exaggerated claims about stolen information to pressure victims. It also described threatening communications, harassment of family members and swatting among tactics associated with ShinyHunters actors. ShinyHunters disputes portions of the FBI's description of its activities. Reuters reported that the group said it targeted the FBI because of the May warning and said it was holding the allegedly stolen data while demanding that the bureau rescind the statement.

You may read a headline about FBI employees and assume this has little to do with you. Yet the way the alleged data could be abused should feel familiar to anyone who has handed personal information to an employer, bank, health provider, insurance company or government agency. Organizations often collect far more than your name and email address. They may hold your home address, Social Security number, birthdate, employment history and emergency contacts. Job applications can contain years of background information.

You may have done everything right and still have that information exposed because the organization holding it or one of its technology providers was attacked. That third-party piece deserves attention here. In its Sept. 23 statement, the FBI specifically said investigators had not determined whether the breach point involved its own enterprise or a third party.

The same setup exists throughout everyday life. Your employer might use an outside payroll provider. Your doctor's office may rely on billing software from another company. Retailers routinely send information through outside payment systems. Once you hand over your personal data, you often have little visibility into how many systems eventually store or process it.

Suppose someone emails you and knows your full name, employer and home address. Then the person mentions your spouse or a job application you actually submitted. That message feels very different from a generic scam email. This is why personal data can be so useful to attackers. They can combine stolen records with information already available from data brokers, social media or previous breaches. The result can be a phishing message tailored closely enough to make you hesitate before questioning it.

Cybercriminals could pose as an FBI recruiter or someone from an employer's human resources department. They could even claim they are contacting you to help protect information exposed in the breach. The FBI's May advisory warned that stolen personal information can help attackers create targeted campaigns and pressure victims.

Even while investigators work to establish the full scope, anyone who believes their information may be involved can take precautions.

If you applied for an FBI job, be suspicious of calls, texts or emails claiming you need to reenter information because of the portal incident. Do not use a link or phone number contained in an unexpected message. Contact your existing applicant coordinator or reach the FBI through a channel you already know. The FBI's own ShinyHunters guidance recommends verifying unusual requests through another method before responding.

This step becomes particularly important because the reported sample included spouses and emergency contacts. Tell people listed on employment or application records to be cautious if someone suddenly knows their connection to you. Criminals may target a relative because they expect that person to have fewer security safeguards. If someone claims there is an urgent problem involving you, an employer or law enforcement, verify the story independently before sharing information or sending money.

A credit freeze can make it harder for someone to open a new credit account in your name. You need to place the freeze separately with Equifax, Experian and TransUnion. The FTC says credit freezes are free and remain in place until you lift them. A freeze will not prevent every form of identity theft. Continue monitoring accounts you already have.

If your Social Security number may have been exposed, an IRS Identity Protection PIN can help protect you from tax identity theft. The six-digit IP PIN prevents someone else from filing a federal tax return using your Social Security number or Individual Taxpayer Identification Number. Anyone with an SSN or ITIN who can verify their identity can request one. Keep the number private. The IRS says it will never call, email or text you asking for your IP PIN.

Look for new accounts you do not recognize, unfamiliar charges or changes to existing accounts. Also pay attention to unexpected IRS notices, rejected tax filings and medical bills or insurance explanations of benefits for treatment you never received. These can signal types of identity theft that a credit freeze alone may not stop. If you discover identity theft, report it through IdentityTheft.gov and follow the recovery plan for the information that was compromised.

Neither Reuters nor the FBI's Sept. 23 statement said passwords were included in the 5,000-record sample. Still, exposed personal details can make attempts to steal your passwords much more convincing. Use a unique password for every important account. A password manager can help keep track of them. Turn on two-factor authentication (2FA) or passkeys wherever available. Also be cautious about unexpected password-reset requests.

A personalized phishing message can still contain a malicious link or infected attachment. Strong antivirus software can help detect known phishing websites, malicious downloads and malware before they compromise your device. That gives you another layer of protection if a convincing email or text gets through. Security software cannot replace careful clicking, but it can help when a scam looks unusually believable. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.

If your home address, phone number and relatives already appear on people search sites, leaked records can give criminals even more information to work with. Search for yourself online and review what is publicly visible. You can request removal from many data broker and people search sites yourself or use a personal data removal service to handle recurring opt-out requests. Reducing what is publicly available gives a criminal fewer pieces to combine with information from a breach. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting CyberGuy.com.

Dark web monitoring can alert you when information tied to your email address, phone number, Social Security number or other identifiers appears in known breach collections. Some identity theft companies include Dark Web Monitoring that searches for exposed personal information and alerts you when it is found. However, treat an alert as a warning rather than proof that someone has stolen your identity. Monitoring cannot prevent information from circulating once criminals obtain it. Its value comes from giving you an opportunity to secure affected accounts, watch for fraud and take action sooner. See my tips and best picks on best identity theft protection at CyberGuy.com.

The FBI's guidance involving ShinyHunters recommends against paying or engaging with threat actors making demands. Save threatening communications instead. Preserve screenshots, email addresses, phone numbers and other identifying information. You can report cybercrime through the FBI's Internet Crime Complaint Center at IC3.gov. If someone appears to face an immediate physical threat, contact emergency services.

There are still major unanswered questions about the FBIJobs.gov incident. The FBI's Sept. 23 statement left the point of breach unresolved, and the bureau had not publicly validated ShinyHunters' claim that it stole between 2 and 3 terabytes of data. Still, the data samples deserve serious attention. Reuters verified details belonging to more than 22 people and reported that the spreadsheet contained Social Security numbers, home addresses, dates of birth, emergency contacts and information about sensitive assignments. What concerns me most is how useful those pieces become when they are connected. 

A criminal who knows where you work, where you live and who your spouse is has a much easier time building a scam that feels authentic. For FBI personnel tied to intelligence or covert technical work, the exposure could create security concerns that reach well beyond financial fraud. The takeaway for the rest of us is practical. You cannot control the security of every employer, government agency or company holding your information. You can control how much information about you remains publicly available, how strongly your accounts are protected and how quickly you respond when something suspicious appears.

If information this sensitive can potentially be exposed through a system connected to the FBI, how confident are you about the employers, companies and government agencies holding your personal data? Let us know by writing to us at CyberGuy.com.

Sign up for my FREE CyberGuy Report

Copyright 2026 CyberGuy.com. All rights reserved.

Ria.city






Read also

WNBA refs miss opportunity to eject A'ja Wilson over meltdown, entering stands

Enes Kanter Freedom speaks out on A'ja Wilson playoff incident with Fever fan, after Natasha Cloud encounter

Republicans have a midterm problem. Reagan’s American vision is the answer

News, articles, comments, with a minute-by-minute update, now on Today24.pro

Today24.pro — latest news 24/7. You can add your news instantly now — here




Sports today


Новости тенниса


Спорт в России и мире


All sports news today





Sports in Russia today


Новости России


Russian.city



Губернаторы России









Путин в России и мире







Персональные новости
Russian.city





Friends of Today24

Музыкальные новости

Персональные новости