The FBI Breach and the Search for a Starting Point
Back to top
September 28, 2026
The FBI Breach and the Search for a Starting Point
The cyber extortion group known as ShinyHunters claims to have breached the FBI’s employee recruitment portal, FBIJobs.gov, gaining access to data pertaining to a large number of current and former FBI employees.
In a statement, ShinyHunters said that they have records for “...almost ALL FBI Agents, and individuals who filed an application with the FBI for a job,” reported Reuters. The group claims to have stolen between two and three terabytes of files, although news sources were unable to independently verify the specific claim.
On September 22nd, the FBI said that it was aware of the incident and threat actor claims and was investigating the matter.
What Information Was Accessed?
A sample of the data stolen reportedly contained agent names, home addresses, Social Security numbers, job assignments, and in some cases, the names of family members.
Partial verification against credit bureau records and previously breached data found apparent matches in at least ten instances, including for FBI Director Kash Patel.
How Did Hackers Access FBI Systems?
The FBI reports that the point of breach remains undetermined and could exist either within the bureau’s own systems or sit with a third-party vendor.
Tracing an intrusion to its precise origin is a common challenge in security investigations, particularly when internal systems and vendor infrastructure connect through shared access points.
Security tools built on known signatures and predefined rules struggle when evaluating an activity that does not match prior patterns. At the same time, monitoring individual systems individually can fragment information needed to trace activity — particularly in relation to connections linking an organization to its vendors and partners.
Visibility across connection points, in addition to the traditional network perimeter, supports investigations into incident origins and points of vulnerability.
What Can Security Teams Take Away From The Incident?
An inventory of every place where internal systems connect to external ones — covering shared authentication, API access, and hosted portals — gives investigators a starting point for determining an intrusion’s path. When a breach occurs, the inventory gives security teams a defined set of systems to check as they assess its extent.
However, confirming what happened and where requires a record of network traffic, as traffic patterns carry evidence of unusual data volumes, unfamiliar connections, and transfers occurring at unexpected times.
Continuous network traffic visibility reveals intrusions as they unfold and helps investigators establish the full scope of a breach.
For more information about how network visibility supports breach investigations, check out our blog post The Visibility Paradox: Why Your Distributed Security Architecture is Failing in Secret.
Discover more

Senior Manager, Technical Marketing
Jamie Moles is a Senior Manager of Technical Marketing at ExtraHop with 30+ years of hands-on experience dismantling complex threat behaviors. Jamie Moles began his career reverse-engineering early malware in the MS-DOS era and currently focuses on cutting through industry noise to deliver practical, network-backed security strategies. View Jamie Moles’ complete professional profile on LinkedIn.
Share
Key Takeaways
- ShinyHunters claims to have stolen 2-3 terabytes of FBI employee data through the FBIJobs.gov recruitment portal.
- Exposed records may include Social Security numbers, addresses, and family member names for current and former agents.
- The FBI has not determined whether the breach originated internally or through a third-party vendor.
- Tracing an intrusion's precise origin, internal or vendor-related, is a common investigative challenge.
- Continuous network traffic visibility helps investigators trace intrusions in progress and confirm a breach's full scope.


