---
title: FBI confirms investigation into ShinyHunters data breach
url: https://www.dataloco.com/en/fbi-confirms-investigation-into-shinyhunters-data-breach
published: 2026-09-27T15:22:09+00:00
language: en
section: Security
source: https://www.zdnet.fr/actualites/cybersecurite-le-fbi-aurait-ete-touche-par-une-fuite-massive-de-donnees-orchestree-par-shinyhunters-504455.htm#xtor=RSS-1
organizations: Federal Bureau of Investigation, ShinyHunters, Cl0p
publisher: Dataloco
---

# FBI confirms investigation into ShinyHunters data breach

The Federal Bureau of Investigation has confirmed it is investigating a security compromise affecting its recruitment portal, FBIJobs.gov. The group known as ShinyHunters claims responsibility for the incident and asserts that it has obtained between two and three terabytes of data. To substantiate this claim, the attackers published a spreadsheet containing five thousand rows of information. The leaked document includes names, social security numbers, and geographic assignments for the affected individuals. More critically, the file reveals the affiliation of personnel with elite units. Analysis of the data identifies fourteen staff members working on cases related to China and nine others assigned to operations targeting Russia. The breach also exposes information about agents involved in data interception, clandestine technical operations, and matters concerning Iran. This exposure presents a significant risk to national security by providing a precise map of Washington's counter-espionage efforts.

A former FBI employee told Reuters that China would be highly interested in knowing the identities of individuals working against it. Beyond geopolitical implications, the breach poses a direct threat to the safety of FBI employees. The stolen files include personal contact details and emergency contacts, which directly involves the families of the agents. For the eleven members listed as belonging to human intelligence units, this leak destroys their operational security. Cybersecurity professionals and former investigators express concern over the potential physical repercussions for these agents, whose cover may be permanently compromised. Another former employee noted to Reuters that there are many examples of infiltrated agents who were harmed when their cover was revealed. This attack is part of a series of bold operations conducted by ShinyHunters. The group's motivation in this case does not appear to be financial.

Instead, the hackers are using the data as leverage to force the agency to remove a public statement issued against them in May. To demonstrate their capabilities, the same group recently compromised the infrastructure of the ransomware gang Cl0p. The incident offers lessons for enterprise security architects regarding risk management. Peripheral web portals, such as recruitment sites, often provide an unmonitored path to critical central databases. Aggregating human resources data in single silos creates a major point of failure. The exposure of emergency contact information opens the door to highly targeted phishing campaigns and social engineering attacks against the entourage of high-value targets.

## This story in other languages

- [中文](https://www.dataloco.com/zh/story-24)
