FBI Investigating Claims That fbijobs.gov Recruiting Portal Was Compromised
The FBI said Wednesday it is investigating claims that its fbijobs.gov recruiting portal was compromised and that personally identifiable information, or PII, tied to FBI employees may have been affected, a public acknowledgment of a cyber incident involving a sensitive federal hiring system.
In a statement dated Sept. 23, the bureau said it is aware of the claims, is working with third-party providers that support the portal and “we are actively and aggressively investigating this matter.” The acknowledgment followed reports that a group using the ShinyHunters name had claimed responsibility. According to 404 Media, which reported on the matter Tuesday, a representative for the group contacted the outlet and said, “We hacked the FBI. We hold data on all FBI employees and applicants,” while providing a sample dataset that the outlet said appeared to contain about 5,000 alleged employee and applicant records.
Reporting by 404 Media, The Record and the Los Angeles Times also showed visible disruption to the FBI jobs site and applicant portal. Those outlets reported that the site was briefly defaced and then taken offline or placed into maintenance mode beginning Sept. 21 and 22, with the portal still unavailable or under maintenance as coverage continued into Wednesday. 404 Media and other outlets said they spot-checked portions of the sample data against publicly available information and found some matches, a limited form of verification that suggests at least some of the records may be authentic.
But the broadest claims made by the attackers remain unconfirmed. The FBI has not verified that all employees or applicants were affected, and neither the bureau nor relevant vendors have publicly confirmed the full size of any dataset or the technical path the hackers say they used to gain access. Major news organizations including The Associated Press have reported that those claims about how the intrusion happened and how much data may have been taken have not been independently verified.
That distinction matters because the confirmed facts are narrower: The FBI has acknowledged the incident, said it is investigating, and the jobs portal has been disrupted. Reporters have seen and spot-checked a sample of alleged records. What is not established is the overall scope of any breach or whether the incident extended beyond the recruiting portal and related systems.
ShinyHunters is a known name in cybercrime reporting. In a May 15 public service announcement, the FBI’s Internet Crime Complaint Center, or IC3, described ShinyHunters as “a cyber criminal group specializing in large-scale data breaches and extortion.”
Any exposure of law enforcement employee PII is especially sensitive because home addresses, phone numbers, birth dates and family details can create security risks; the stakes help explain why breaches involving federal personnel data, including the 2015 Office of Personnel Management hack, are treated with unusual seriousness.