Breaches · 7h ago
The FBI has internally told staff that a breach of its job application portal exposed names, addresses, job titles, Social Security numbers, and some medical and psychiatric records. The hack was claimed by ShinyHunters, and reporting says the stolen data came from an Oracle PeopleSoft system tied to FBI human-resources records.
The exposure matters because that mix of identity and health information is enough to build dossiers on agents and applicants, not just to commit ordinary fraud. Once an attacker has those records, they can sort people by role, location, and personal detail, which makes later targeting, coercion, or profiling much easier.
For agencies that keep applicant and employee data in HR systems, the lasting risk is not the portal itself but the personnel file it opens onto. If those stores contain SSNs and medical records, a breach can become a counterintelligence problem as well as a privacy one.
2 sources covering this story
The bureau has not yet publicly confirmed a breach, but has told its agents that their personal information and Social Security numbers were exposed.
FBI probes cyberattack tied to third-party jobs portal
The potentially serious breach highlights the supply chain risks facing even the most sophisticated organizations.
Part of the PlainSec briefing for 2026-09-28