The FBI is investigating a breach of its recruitment website after a hacker group claimed to have stolen two to three terabytes of personal data belonging to thousands of current and former employees. The incident, first reported by 404 Media on Tuesday, involves the group ShinyHunters taking down FBIJobs.gov and replacing its homepage with a banner reading "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS."

What was taken

According to ShinyHunters, who told The New York Times the scale of the haul, the stolen data includes names of current and former agents as well as applicants, along with corresponding home addresses, phone numbers, spouses' names, and certain medical information. Bloomberg reported that a sample of the data appears to contain potentially sensitive professional information, including details on counter-intelligence work focused on China, Russia, and Iran, as well as operations targeting street gangs.

None of the data has been leaked publicly as of the reporting. The FBIJobs.gov site itself displayed the seizure banner but the agency has not released a detailed public statement confirming the breach's scope.

Why the group says it struck

ShinyHunters has stated that its motive was not financial. The group claims it does not seek ransom or extortion from the FBI. Instead, it says the attack was intended to force the agency to either remove or edit a May advisory warning about ShinyHunters. The group alleges that the advisory circulated "disinformation in an attempt to 'disrupt' our operations."

The dispute centers on the FBI's characterization of ShinyHunters as a threat actor that uses exaggerated claims to extract payments from victims, conducts swatting attacks against corporate workers, and makes sextortion threats. In a message posted on the dark web and reviewed by Ars Technica, the group said it was "severely offended" by those allegations. "We wish to state unequivocally our threats and claims are very real," the message read. "Not exaggerated and never a bluff." The group specifically denied conducting swatting or sextortion campaigns.

The vulnerability

The breach reportedly exploited a previously unknown bug on the FBI's jobs website. The exact nature of the vulnerability has not been publicly detailed. That it existed on a recruitment portal — a site that would naturally collect extensive personal and professional information from applicants — may explain the breadth and sensitivity of the data that was accessible.

The FBI has not disclosed when the vulnerability was discovered or how long the site was compromised before the seizure banner appeared. The investigation is ongoing.

Why this matters

The potential for retaliation against agents is the most concerning dimension of this incident. If the data includes details about an agent's work focus, assignments, or areas of investigation, it could be used to identify and target individuals. The inclusion of medical information and family details compounds the risk.

The situation also highlights a growing tension between law enforcement agencies and hacker groups over how those groups are publicly characterized. ShinyHunters, which has been active for several years, has long disputed official narratives about its tactics and motives. This incident escalated that dispute from a war of words to a direct attack on FBI infrastructure.

The FBIJobs.gov breach is under active investigation. Until the FBI releases more details about the vulnerability and the scope of what was accessed, the full impact of the incident remains uncertain — though the sensitivity of the data involved suggests the consequences could extend well beyond the agency itself.