The FBI confirmed it is investigating a cyber incident tied to FBIJobs.gov after the ShinyHunters extortion group claimed it stole two to three terabytes of personnel and applicant data, including information the group said covers home addresses, Social Security numbers, and emergency contacts. Assistant Director Brett Leatherman pledged in a video statement to pursue the actors, while the careers site remained offline with a maintenance banner as of Tuesday—leaving thousands of job seekers unsure whether forms they filed years ago are now in criminal hands.

What the group claims—and what is verified

ShinyHunters told reporters it gained remote code execution through an unpatched PeopleSoft flaw, then moved into FBI-managed Amazon Web Services GovCloud storage. The FBI has not confirmed that chain, saying the breach point could be a third-party provider or an enterprise system. Journalists who reviewed sample spreadsheets reported names, phone numbers, and assignment details for active and former personnel; the group later said it would not publicly dump the full trove but cannot control copies shared with media.

The confrontation carries a political tint: ShinyHunters demanded the bureau retract a May FLASH advisory that described the group’s harassment tactics, giving the FBI a one-week window before threatening wider release. That is not a classic ransom note, but it still leaves victims exposed if samples circulate.

Who outside the FBI should act

Oracle PeopleSoft sits in human-resources stacks at universities, utilities, and state agencies. Mandiant’s Friday note said attackers are bypassing firewall rules by tweaking exploit payloads—meaning “we installed a WAF rule” is not a substitute for vendor patches when Oracle publishes them. Security teams should inventory internet-facing PeopleSoft endpoints, enforce multifactor authentication on administrative accounts, and monitor for anomalous file exports.

Anyone who applied to the FBI online should assume contact data may be abused for phishing. The bureau urged personnel to report unsolicited approaches; applicants should freeze credit at the three major bureaus, enable fraud alerts, and avoid clicking password-reset links that arrive by text or email purporting to be from the FBI.

Why this breach is different from retail card leaks

Card breaches usually expose numbers that banks can reissue. Personnel files can include security-clearance-adjacent metadata, medical screening results reported by Reuters and the BBC, and family contacts—data that cannot be rotated like a payment credential. Former officials told NPR the theft is a counterintelligence headache even if ShinyHunters never publishes, because samples already left the group’s control.

Until the FBI and Oracle document the root cause, the actionable lesson for readers is procedural: treat federal job portals like high-value identity stores, not résumé drop boxes, and watch for impostor calls that reference real application dates pulled from stolen files.