---
title: "ShinyHunters Claim FBI Breach: Hackers Boast About Data of Thousands of Agency Employees"
description: "ShinyHunters claimed a breach of the FBIJobs.gov portal and the theft of data of thousands of FBI employees. Journalists were able to confirm only nine matches, and there is no independent confirmation of the attack's scale."
date: 2026-09-23T04:22:00.000Z
lang: en
url: https://xab.info/en/posts/shinyhunters-fbi-breach-employee-data
tags: [shinyhunters, fbi, cyberattack, data-breach, fbi-jobs, hacking, us-security]
publisher: "XAB.info"
---

# ShinyHunters Claim FBI Breach: Hackers Boast About Data of Thousands of Agency Employees

![Anonymous hacker in a mask and hood at a computer with code screens and a world map — illustration of the FBI system breach by ShinyHunters](https://xab.info/media/2026/09/23/shinyhunters-vz-sistemy-fbr-dannye-sotrudnikov/shinyhunters-vz-sistemy-fbr-dannye-sotrudnikov-1.webp)

## 🎯 Key Points

- ShinyHunters claimed access to FBI systems via the FBIJobs.gov portal and the theft of data of thousands of employees
- According to the hackers, the attack was a response to the FBI's May 2026 publication on ShinyHunters' methods
- 404 Media received a sample of ~5,000 records with names, addresses, and spouse data
- Journalists were able to confirm only 9 matches with real individuals, without proof of origin from FBI systems
- The FBI did not comment on the claims; there is no independent confirmation of the attack's scale

The ShinyHunters hacking group has publicly claimed to have gained unauthorized access to the systems of the U.S. Federal Bureau of Investigation (FBI) and stolen the personal data of thousands of current employees, former agency workers, and job candidates. According to the hackers themselves, the main target of the attack was the FBIJobs.gov portal — the official website through which the FBI publishes job openings and accepts applications from candidates. The statement came against the backdrop of the FBI publishing a report in May 2026 on ShinyHunters' methods of operation, which, according to the group, served as the direct trigger for the retaliatory cyberattack.

### Targets and Stated Motivation of the Attack

ShinyHunters representatives emphasize that the choice of target was not accidental: the FBIJobs.gov portal is a public interface for the FBI's interaction with job applicants and, by the hackers' logic, contains extensive arrays of personal data. The group positions its action as a "response" to the FBI's publication in May 2026, in which the agency revealed ShinyHunters' tactics and tools. Thus, the hackers are constructing a narrative of a symmetric response to the informational pressure from U.S. law enforcement agencies. At the same time, the full scale of the claimed attack remains unknown to all parties as of the time of publication.

### What Is Known About the Stolen Data

Earlier, the outlet 404 Media reported that it had received from ShinyHunters a sample database of approximately five thousand records. According to the editorial team's claims, the sample contains the names, home addresses, and phone numbers of employees, as well as information about the spouses of some of them. The hackers link this dataset to the FBI's internal database, however, independent attribution of the data to specific agency systems has not been carried out to date. It is important to note that 404 Media's possession of a sample is not equivalent to proof that the information was extracted specifically from the FBI's protected infrastructure rather than from open or semi-open sources.

### Partial Verification by Journalists

Journalists who gained access to the data published by the hackers managed to conduct a partial check: nine matches with real individuals were found. This confirms that the sample contains current personal information; however, as the researchers themselves emphasize, nine matches do not allow a conclusion that the information was stolen directly from FBI systems. The data could have been collected from open sources, job candidate databases, or third-party aggregators. Thus, the verification remains fragmentary and does not resolve the question of the actual scale of the compromise.

### FBI Response and Lack of Independent Confirmation

The FBI did not provide Reuters with an immediate comment on ShinyHunters' claims. As of the time of preparing this article, the agency neither confirmed nor denied the fact of unauthorized access to its systems. No independent technical audit that would definitively establish that ShinyHunters actually gained access to the claimed data arrays has been conducted to date. The only thing confirmed at the factual level is that the group made a public statement, and 404 Media received and published a data sample that the hackers link to the FBI.

### Contradictory Data

There is a significant gap between ShinyHunters' claims and the results of the journalistic verification. The hackers claim the compromise of "thousands" of current and former employees, whereas journalists were able to confirm only nine matches with real individuals, and without proof that the data originated from FBI systems. On the one hand, 404 Media's possession of a sample of five thousand records with detailed personal data (including information about spouses) indicates that some array of information did indeed leak. On the other hand, neither the FBI nor independent cybersecurity laboratories have confirmed that these data were extracted from the bureau's protected infrastructure. Thus, the reader is presented with a picture in which the fact of the statement and the existence of a data sample are confirmed, while the actual scale and source of the compromise remain a matter of debate.

## 🔍 Fact-Check Verification

- [ShinyHunters hackers claim breach of the FBI system and theft of its employees' data](https://www.rbc.ua/ukr/news/hakeri-shinyhunters-zayavili-zlam-sistemi-1790137015.html) - Источник подтверждает факт заявления ShinyHunters, упоминание FBIJobs.gov как цели, контекст мая 2026 г., отсутствие комментария ФБР для Reuters, 9 совпадений при частичной проверке и образец ~5000 записей у 404 Media. Независимого подтверждения полного масштаба нет.

## ❓ FAQ

### Q: What exactly do ShinyHunters claim about the FBI breach?
**A:** The group claims that it gained access to FBI systems through the FBIJobs.gov portal and stole the personal data of thousands of current employees, former workers, and job candidates.

### Q: Did the FBI confirm the fact of the breach?
**A:** No. The FBI did not provide Reuters with an immediate comment and neither confirmed nor denied ShinyHunters' claims. There is currently no independent technical confirmation of a compromise of the bureau's systems.

### Q: What were the journalists able to verify?
**A:** Journalists were able to find nine matches between the data published by the hackers and real individuals. 404 Media also received a sample of approximately five thousand records. However, this does not confirm that the data was stolen specifically from FBI systems.

### Q: Why did ShinyHunters attack the FBI?
**A:** According to the hackers themselves, the attack was a response to the FBI's May 2026 publication, in which the agency revealed ShinyHunters' methods of operation.