The Federal Bureau of Investigation has issued an internal memo directing its employees to operate under the assumption that their personal information was compromised by the cybercrime group ShinyHunters. This directive follows a claimed breach of the bureau’s recruitment portal, FBIjobs.gov, where the attackers allegedly accessed data pertaining to nearly all current agents and job applicants. According to reports originating from Reuters, the hackers claim to have exfiltrated between 2 and 3 terabytes of sensitive information, including names, phone numbers, home addresses, and details regarding some spouses. The intrusion reportedly began on a Monday night, with visitors to the site encountering a banner indicating seizure by ShinyHunters by Tuesday, September 22.

ShinyHunters asserts that the initial access vector was a zero-day vulnerability in Oracle’s PeopleSoft human resources software, a method the FBI has not yet confirmed. The group stated that the attack was triggered by a May 15 FBI advisory warning that ShinyHunters employs harassment tactics, such as threats against family members and swatting incidents. In response, the hackers demanded a retraction within one week. Concurrently, FBI Cyber Division Chief Brett Leatherman addressed the situation via a video posted on X on September 29, referencing a Dutch arrest made on September 15 and stating, "we know how to find you." While Leatherman urged the group to reach out, ShinyHunters characterized this communication as a marketing campaign and denied any association with the arrested individual. The memo further advises staff to anticipate virtual briefings and remain vigilant for suspicious communications.