Hackers claim massive FBI data breach, say they stole records on every employee and applicant
A notorious hacking gang says it broke into the FBI's jobs website and stole personal data on every bureau employee and job applicant, a claim the agency has not confirmed but is now investigating under Director Kash Patel's watch.
The group, known as ShinyHunters, defaced FBIjobs.gov on Tuesday, replacing the site with a message that read: "This site has been seized by ShinyHunters." The hackers shared roughly 5,000 records as a sample, purportedly containing home addresses, phone numbers, dates of birth, and in some cases details about spouses. The FBI's jobs portal was later knocked offline entirely.
A ShinyHunters representative told the Daily Mail the gang struck Monday night by exploiting a previously unknown flaw, a so-called zero-day vulnerability, in Oracle's PeopleSoft software, then claimed to have accessed Amazon's AWS GovCloud servers, a cloud service built to hold sensitive U.S. government data. The hackers say they made off with between two and three terabytes of files.
The FBI offered a terse acknowledgment but stopped well short of confirming any data theft:
"The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."
Neither Oracle nor Amazon had responded to requests for comment at the time of the Daily Mail's reporting. That leaves critical questions unanswered: Did Oracle know about the alleged flaw in PeopleSoft? Did Amazon detect any unauthorized access to its GovCloud servers? And how much of what ShinyHunters claims is verified versus bluster?
ShinyHunters calls it 'coercion,' not extortion
The hackers' stated intentions add an unusual wrinkle. A representative for the group said the operation was "not financially motivated", and described their plans in terms that suggest leverage rather than ransom. As the representative put it:
"What we plan to do is not something I'd call extortion, maybe coercion."
What exactly that coercion looks like remains unclear. But the FBI itself has previously warned that criminals linked to ShinyHunters use stolen personal information to harass victims and their families. If the stolen data is genuine, the potential exposure is severe: home addresses, phone numbers, and family details for current and former FBI personnel, the kind of information that could put agents and their loved ones at physical risk.
The technology outlet 404 Media, which first reported the alleged breach, ran checks on some of the leaked phone numbers and found they matched people with the same names in open-source intelligence databases. Several of those numbers were linked to Justice Department personnel. That partial verification lends some credibility to the hackers' claims, though it falls short of confirming the full scope of the alleged theft.
The defacement message itself carried a mocking edge. The hackers closed with "Thank you for your attention to this matter", a phrase the Daily Mail described as President Trump's trademark sign-off on Truth Social. They also added: "We have a lot more than we claim here."
Kash Patel already facing scrutiny on multiple fronts
The alleged breach lands at a particularly difficult moment for FBI Director Kash Patel, who was sworn in during February. Patel, 46, has spent his early tenure under sustained political pressure, and this incident adds a cybersecurity crisis to a growing list of controversies. In recent years, the handling of classified and sensitive government information has become a flashpoint in Washington, as illustrated by John Bolton's guilty plea on a felony charge of retaining classified information.
Just last week, Patel faced heated questioning at a Senate Judiciary Committee hearing over changes to FBI hiring standards. The changes involved policies related to prostitution and bestiality, specifically, Patel defended them as intended to let victims of those acts apply for FBI jobs without being automatically disqualified. The hearing drew sharp exchanges, consistent with the contentious oversight environment Patel has navigated since taking over the bureau. His earlier Senate appearances have also caused friction with Democratic lawmakers.
Separately, Patel has faced scrutiny over his use of the bureau's $60 million jet. Reports indicated he used the aircraft to travel to a Penn State wrestling event where his girlfriend, country singer Alexis Wilkins, performed. Patel pushed back on the criticism, saying he was "entitled to a personal life just like my other agency counterparts with their partners."
And in April, Patel filed a $250 million defamation lawsuit against The Atlantic over an article alleging mismanagement at the agency and excessive drinking, claims Patel denies. The lawsuit's court and case number have not been publicly reported in detail.
A breach that could dwarf previous federal security failures
If ShinyHunters' claims hold up, this breach would represent one of the most damaging cyberattacks against a U.S. law enforcement agency in memory. The FBI is not just any federal department. Its employees include undercover agents, counterintelligence officers, and personnel embedded in sensitive national security operations. Exposing their personal data, and the data of every person who ever applied for a job at the bureau, creates risks that extend far beyond embarrassment.
The episode also raises hard questions about the federal government's reliance on third-party software and cloud infrastructure. The hackers claim they entered through Oracle's PeopleSoft platform and then moved laterally into Amazon's GovCloud. If accurate, that chain of exploitation suggests the FBI's most sensitive personnel data sat behind commercial software with an unpatched vulnerability, a basic failure of cybersecurity hygiene. The growing concern over federal information security has driven other recent investigations, including a federal leak probe involving subpoenas of reporters over Air Force One security reporting.
The FBI's own track record on cybersecurity has not been spotless. But a breach of this alleged scale, every employee, every applicant, would be in a category of its own. It would also mark a grim irony: the nation's premier law enforcement agency, tasked with investigating cybercrimes, becoming the victim of one.
For now, the bureau says it is investigating. Oracle and Amazon have not spoken publicly. The hackers are making bold claims and sharing samples. And Patel, already managing a defamation lawsuit, congressional scrutiny over hiring policies, and questions about his travel, now has to answer for the security of the agency's own personnel records.
The FBI has spent years warning Americans about the dangers of data breaches. Its agents, the men and women who carry out high-profile federal operations, deserve to know their own agency can protect their personal information at least as well as it expects the private sector to protect ours.
When the people who guard the nation's secrets can't guard their own, every American should wonder who's minding the store.




