
A hacking group that claims to have stolen personal data on nearly every FBI agent in the country is now facing a direct warning from the bureau itself, delivered days after Dutch police arrested a suspected member.
Story Snapshot
- ShinyHunters, a cybercriminal group, claims it stole data on almost all FBI agents and job applicants from the bureau’s jobs website.
- The FBI confirmed it is investigating unauthorized activity on FBIJobs.gov but has not publicly confirmed the group’s full claims.
- Dutch police arrested a 24-year-old Amsterdam man suspected of involvement with the group on September 15, 2026.
- An FBI cyber official warned remaining members to “reach out first while the choice is still yours.”
- Reporters say some sample data checks out as real FBI personnel records, but no one has confirmed where the data actually came from.
Hackers Claim They Robbed the FBI’s Own Files
ShinyHunters posted a message on a dark-web site claiming it had “compromised the FBI” and stolen sensitive data on almost all agents and people who applied for bureau jobs. The group told Reuters it targeted the FBI to retaliate against a May 2026 bureau advisory that detailed its tactics and told victims not to pay ransom demands.
The bureau responded carefully. It said it was “aware of claims regarding unauthorized activity affecting FBIjobs.gov” and was investigating, but stopped short of confirming the hackers’ account. Internally, though, staff received a memo telling them to assume the worst. Reuters reported the FBI was operating “under the presumption that hackers stole data pertaining to all bureau employees”.
ShinyHunters’ claims about the size of the breach have shifted. Public reports mention anywhere from basic contact information to two to three terabytes of files, and some accounts describe medical and psychiatric records tied to agents’ fitness for duty. That kind of data, if real, could expose agents and their families to serious harm.
Independent Checks Confirm Some Records, Not Their Source
Reporters at Reuters and the outlet 404 Media checked samples the hackers shared and found some matched real FBI or Justice Department personnel. Neither outlet, however, could confirm the records actually came from FBI computer systems. That gap between “this data is real” and “this data was stolen from the FBI” remains unresolved in public reporting.
The FBI itself acknowledged this uncertainty. A bureau statement said the breach point was still undetermined, adding it could not yet say whether a third party or the FBI’s own systems were the source. That kind of admission from a law enforcement agency, made publicly while the case is active, is itself notable.
Dutch Arrest Sends a Message, But Doesn’t Close the Case
Dutch National Police arrested a 24-year-old man in Amsterdam on September 15, 2026, describing him as a suspect tied to the ShinyHunters investigation. Two weeks later, FBI Cyber Division Assistant Director Brett Leatherman posted a video aimed squarely at the group’s remaining members. “You know how to find us, and we know how to find you,” he said. “I suggest you reach out first while the choice is still yours”.
NBC News reported the FBI was not explicitly linking the Dutch man’s arrest to the FBIJobs.gov breach, noting the hack appeared to happen after he was already detained. That timeline detail matters. It means the arrest, while a real law enforcement win, does not by itself prove who broke into the FBI’s systems or how much data actually left the building.
A Loosely Organized Group Complicates the Picture
Experts describe ShinyHunters less as a single gang with a clear leader and more as a shifting network of hackers who come and go. CBS News reported the group operates as “a fluid ecosystem of threat actors rather than a fixed group,” which makes it harder to confirm who speaks for the organization at any given moment. That structure also means one arrest cannot be assumed to cripple the whole operation.
After the Dutch arrest, ShinyHunters appeared to back off an earlier ultimatum. The group had first demanded the FBI retract its May advisory within a week or see the stolen data published. By September 28, Reuters reported the hackers said they were “not setting a deadline” for that demand, a softer posture than their initial threat.
🔴🧑‍💻 The NYT says the claimed breach by the cybercriminal group ShinyHunters of FBI personnel and applicant data (from the FBIJobs. gov portal and related systems, reportedly via an Oracle PeopleSoft vulnerability).
The stolen information includes names, home addresses, Social… https://t.co/t4BCfmkNp8 pic.twitter.com/Qn3n462wVn
— Kristi L. Talmadge (@KristiTalmadge) September 29, 2026
For everyday Americans, the episode lands as one more sign that no institution, not even the nation’s top law enforcement agency, is fully safe from digital extortion. Whether the final tally of stolen records turns out to be modest or massive, the fact that the FBI itself cannot yet say for certain what happened inside its own systems is likely to fuel public unease about how well government agencies protect the people who work for them.
Sources:
youtube.com, reuters.com, rmb.reuters.com, abcnews.com










