WASHINGTON — The FBI is “aggressively” investigating a breach of its jobs portal after the cybercriminal collective known as ShinyHunters claimed to steal sensitive employment and personnel-related data, NPR reported Wednesday, citing bureau statements and current and former employees familiar with the probe.
In a social-media video, Brett Leatherman, assistant director of the FBI’s cyber division, warned ShinyHunters members to come forward, saying, “You know how to find us, and we know how to find you.” A bureau spokesperson told NPR investigators are working “around the clock” on the FBIJobs.gov incident and communicating with people who may be affected.
A defacement message appeared on the jobs site late last week claiming credit for ShinyHunters before the site was temporarily taken down. Media outlets and threat researchers have authenticated some of the stolen materials, though the full volume remains unclear. Current and former employees speaking anonymously to NPR described possible multi-terabyte text archives that could include job applications, promotion details, sensitive posting information, family details, and medical data.
Some retirees — including people who once worked undercover — expressed frustration with leadership communication under Director Kash Patel and worry about relocation or identity-protection needs if data is exposed. The FBI told NPR it sent multiple bureau-wide notices within 24 hours of public reporting and treats workforce security as a top priority.
A former senior official told NPR the incident could approach the scale of the 2015 Office of Personnel Management breach in terms of impact on government personnel data, while noting a sharper fear that criminal or nation-state actors could weaponize the files. ShinyHunters has said it did not intend to leak the material and set a Sept. 30 deadline tied to disputed FBI press releases about the group — a claim that does not guarantee the data stays contained.
Google’s Mandiant has published research linking ShinyHunters activity to exploitation of a vulnerability in Oracle’s PeopleSoft human-resources software, which NPR noted is used by the FBI and many other organizations. Mandiant previously disclosed the issue in June; some customers relied on firewalls rather than patches, controls researchers say attackers have bypassed.
Former FBI cyber deputy director Cynthia Kaiser called targeting the FBI “reckless,” noting the bureau’s policy against paying ransoms. Separately, Dutch police recently arrested an alleged ShinyHunters member in Amsterdam — an operation the FBI thanked partners for — though NPR reported that arrest preceded the FBIJobs.gov theft and may or may not have motivated retaliation.
Based on NPR reporting by Jenna McLaughlin (Sept. 30, 2026). Technical attribution to PeopleSoft/Mandiant as described by NPR; the FBI has not publicly confirmed the intrusion vector in the cited statement.