← Back to live feed

Monday, Sep 28, 2026

1
ShinyHunters Will Not Release Stolen FBI Personnel Records↩︎ORCL

Current and former agents are contacting news organizations to verify if their personal details were leaked after the Federal Bureau of Investigation’s recruiting portal was breached. The cybercrime group known as ShinyHunters told 404 Media that it does not intend to publish the bulk of the stolen data, though some Social Security numbers and psychiatric records have already been shared with reporters as proof of the intrusion. The agency's personnel have since resorted to asking journalists for verification of their exposure.

The theft involves 2 to 3 TB of sensitive information from the bureau's HR and medical databases, affecting almost all employees and applicants. The FBI has declared a "cyber security incident" stemming from the exploitation of an Oracle PeopleSoft vulnerability with a CVSS score of 9.8, which CISA had already flagged as actively used in the wild. The attackers described the incident as a retaliatory "marketing initiative" triggered by an agency report that profiled the group's operations earlier this year.

Image via @darkwebinformer on X
Continues from Thursday, Sep 24
FBI Confirms Personnel SSN Theft in First Breach Admission
56 tweets • 30 sources
See all 57 tweets →