FBI Staff Personal and Medical Data Reportedly Stolen in Cyberattack

FBI employees were reportedly told that hackers stole personal and medical data after breaching the bureau’s job application system through PeopleSoft.

Sep 28, 2026 - 14:27
 3
FBI Staff Personal and Medical Data Reportedly Stolen in Cyberattack
Image Credit: TechAmerica.ai / AI-generated image

The FBI has reportedly notified employees that hackers obtained personal information belonging to agents and support staff in a cyberattack targeting the bureau’s job application system.

The internal notification marks a significant development from the FBI’s earlier public position. In a statement last week, the bureau said it was aware of claims by a hacking group but that it still did not know whether data had been stolen.

According to reporting shared by Ken Dilanian, the FBI has since declared a “cybersecurity incident” internally and told employees that information including names, addresses, job titles and Social Security numbers was exposed.

Medical Records Reportedly Included in Stolen Data

The compromised information reportedly extends beyond basic personnel records. Some stolen files included records involving blood and urine samples, while other reporting indicates that psychiatric and other medical records were also taken.

The hacking group ShinyHunters claims it obtained information on a large portion of FBI personnel, as well as a substantial amount of data from applicants who used the FBIJobs.gov portal.

The attackers are believed to have gained access by exploiting a vulnerability affecting Oracle PeopleSoft systems. The FBI’s recruitment infrastructure used the software to hold human resources information connected to employees and job applicants.

ShinyHunters has said it is not seeking a financial ransom. Instead, the group has demanded that the FBI correct an earlier report that the hackers say inaccurately described their activities.

Security Experts Warn of Counterintelligence Risks

National security expert Justin Sherman described the breach as a “counterintelligence disaster”, warning that stolen personnel information could expose FBI employees to profiling, phishing attempts and approaches by foreign intelligence services.

The incident could also trigger reporting requirements to Congress. Under federal cybersecurity guidance, agencies must notify lawmakers when an intrusion qualifies as a major incident, including certain breaches involving personally identifiable information that could cause demonstrable harm to U.S. national security.

The supplied reporting does not make clear whether the FBI has formally classified this breach as a major incident or notified congressional oversight committees.

FBI Has Faced Another Major Breach This Year

If congressional notification is required, it would be the FBI’s second known breach-related notification to lawmakers this year. Earlier in 2026, suspected Chinese hackers breached an FBI surveillance system, exposing information connected to surveillance targets and investigations.

A White House spokesperson deferred questions about the latest incident to the FBI. Meanwhile, the FBI’s employment portal, the primary way to apply for bureau jobs since 2017, remained offline at the time the source reported.

The combination of Social Security numbers, employment information and sensitive medical records makes the incident particularly serious for affected FBI personnel and applicants. At the same time, questions remain about the full scale of the breach and the bureau’s formal response.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav’s current bio says she reports on technology-focused developments “in India”, but the same profile publishes stories about U.S. NHTSA investigations, Hugging Face, global AI startups and other international topics.