Federal Bureau of Investigation (FBI) Data Breach Exposes Employee and Applicant Personal Information

Published: 22 September 2026
Other Commercial data breach illustration
Breach Discovery: September 2026Breach Notification: September 2026

Hackers calling themselves ShinyHunters claim they breached FBI networks in September 2026 using an unpatched Oracle PeopleSoft flaw, stealing terabytes of data on current and former employees and job applicants, including health-related records. The FBI reportedly took systems offline once it detected the intrusion. Affected individuals should monitor credit reports and watch for phishing attempts immediately.

CompanyFederal Bureau of Investigation (FBI)
IndustryOther Commercial
Data Types ExposedFull Names, Phone Numbers, Employment Records, Job Application Details, Human Resources Records, Health-Related Information, Criminal Justice Records
People AffectedNot Publicly Disclosed
Attack MethodZero-Day Exploit
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Federal Bureau of Investigation (FBI) Data Breach?

A hacking group calling itself ShinyHunters claims it broke into internal Federal Bureau of Investigation systems and stole a large volume of sensitive data. According to the group, unauthorized access to the network occurred in September 2026. The attackers say they used a previously unknown flaw in Oracle PeopleSoft software to get in.

ShinyHunters told reporters that the flaw allows remote code execution. The group claims it used this weakness late one evening to reach FBI systems. From there, the attackers say they moved laterally into FBI-managed cloud infrastructure hosted on Amazon Web Services GovCloud.

As proof, the group defaced the public FBI Jobs website with a message claiming ownership of the intrusion. The defacement stated that employee and applicant data had been compromised. It also referenced sensitive personal and health information tied to both current and former FBI staff.

The FBI reportedly noticed the intrusion quickly. As a result, the agency took affected systems offline and cut network access almost immediately. The FBI Jobs site currently shows a maintenance message while the situation is reviewed.

Independent journalists have reviewed a sample of the allegedly stolen data. They confirmed that some details, including phone numbers, matched real individuals connected to the Department of Justice. However, the full scope of the intrusion, including the existence of the claimed zero-day flaw, has not been independently confirmed by Oracle or outside security researchers.

Who was affected?

The individuals potentially affected include current and former FBI employees along with job applicants who submitted information through FBI hiring systems. Because the attackers claim to have compromised human resources, medical, and criminal justice-related services, the exposure may reach far beyond a single database.

The exact number of people affected hasn’t been publicly disclosed. ShinyHunters claims to have stolen between two and three terabytes of data. That volume suggests a wide range of records, though the precise headcount tied to personal information remains unconfirmed.

Because the FBI is a national law enforcement agency, the population affected could span every state. This is not limited to one region or office. In addition, both active personnel and people who merely applied for jobs years ago could be impacted.

What Information Was Potentially Exposed?

Based on claims made by the attackers and details reviewed by journalists, several categories of sensitive personal data may have been exposed. The following list reflects what has been alleged so far.

  • Full names
  • Phone numbers
  • Employment records for current and former FBI staff
  • Job application details
  • Human resources records
  • Health-related information (Medlink medical services data)
  • Internal law enforcement and criminal justice records

If confirmed, this combination of data creates serious risk. Names paired with phone numbers and employment history can help criminals build convincing phishing or impersonation schemes. Because some victims work in law enforcement, targeted harassment or swatting attempts are also a realistic concern.

Health-related information deserves special attention. If medical records tied to the Medlink service were truly accessed, affected individuals could face medical identity theft. This means someone could use stolen health details to file fraudulent insurance claims or obtain medical services under another person’s name.

What is the company doing?

According to the attackers, the FBI responded rapidly once it detected the intrusion. The agency reportedly pulled affected systems offline and cut access across multiple internal networks at the same time. This kind of rapid containment is a standard early step after suspected unauthorized access.

The FBI Jobs website has since been replaced with a maintenance notice while the incident is reviewed. Meanwhile, cybersecurity researchers and technology companies have been contacted to determine whether the claimed Oracle PeopleSoft vulnerability is real and whether it has been used against other victims. Because this incident is still developing, further confirmation from the FBI itself has not yet been made public.

Public statements from the FBI addressing the scope of the breach, along with any formal notification to affected individuals, have not been detailed in available reporting. Consequently, people who believe they may be affected should watch for official communication directly from the agency in the coming weeks.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone connected to the FBI as an employee, former employee, or applicant should review their credit reports closely. This is especially important because personal information may have been exposed alongside employment records.

You can request free credit reports from all three major bureaus. Look for accounts you don’t recognize or hard inquiries you didn’t authorize. If you spot anything unusual, report it right away and consider placing a fraud alert on your file.

Consider a Credit Freeze or Fraud Alert

Because names, phone numbers, and other identifying details may have been stolen, a credit freeze offers strong protection. A freeze blocks new creditors from accessing your credit file, which makes it much harder for criminals to open accounts in your name.

A fraud alert is a lighter-touch option. It requires lenders to verify your identity before extending credit. Either step can meaningfully reduce your risk while the investigation into this breach continues.

Protect Yourself Against Medical Identity Theft

Because health-related data tied to the Medlink service is allegedly part of the stolen information, affected individuals should watch for signs of medical identity theft. This includes reviewing insurance statements for unfamiliar claims or services you did not receive.

If you spot suspicious activity, contact your health plan and request a copy of your benefits statement history. In addition, ask for an accounting of disclosures if you suspect your medical information was misused. Acting quickly can limit long-term damage to your medical records.

Stay Alert for Phishing and Impersonation Attempts

Stolen employment and contact information can fuel convincing phishing emails, texts, or phone calls. Scammers often pose as government agencies, employers, or benefits providers to trick victims into revealing more information.

Never click links or share personal details in response to unexpected messages. Instead, verify requests by contacting the organization directly through a known phone number or website. Because this breach involves a law enforcement agency, be especially cautious of anyone claiming to represent the FBI itself.

Consult a Data Breach Attorney

Given the sensitivity of the data allegedly involved, affected individuals may want to speak with an attorney who focuses on data breach cases. A free consultation can help clarify your legal options and whether you qualify for compensation.

Many law firms offer no-cost case evaluations for people affected by large-scale breaches like this one. This means there is little downside to exploring your options early, especially while facts about the incident are still emerging.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

See the latest data breaches we're tracking →