The FBI is investigating a major data breach after learning the federal agency’s job application portal was compromised, according to a September 2026 report by 404 Media. The cyberattack on FBIJobs.gov may have exposed the personal records of thousands of job applicants alongside current and former FBI personnel.
On September 23, the FBI shared in a statement that they were “aggressively investigating this matter,” and on September 29, shared a video on X reporting that Dutch authorities had arrested an alleged leader of ShinyHunters, the global cybercrime group known who took responsibility for the FBI data breach. In the video, Brett Leatherman, Assistant Director of the FBI’s Cyber Division, warned remaining members of ShinyHunters that the FBI knew where to find them and suggested they reach out to the FBI first while they still have the choice.
Inside the FBI Jobs Portal Cyberattack
The intrusion targeted the FBI Candidate Gateway, where the hacker group claims to have extracted sensitive personally identifiable information (PII). According to the group and media reviews of leaked sample data, this compromised dataset contains the PII of federal job applicants, prospective candidates, active special agents, and former FBI employees. Exposed records allegedly include full legal names, home addresses, phone numbers, email addresses, spousal information, job titles, and Social Security numbers.
In a statement circulated on the dark-web by ShinyHunters, the group attempted to use the stolen database to extort the agency, giving officials one week to retract a public advisory that had identified ShinyHunters as a criminal syndicate. After the deadline passed and the advisory remained live, the group claimed they would not publish the database publicly. However, breached records frequently wind up circulating in cybercriminal forums.
How Breach Data Creates Additional Threats
When news breaks that sensitive personnel data from a high-profile agency has been exposed, the risks extend beyond immediate identity theft. Cybercriminals can leverage this stolen data to launch two categories of attacks:
- Internal Spear-Phishing and System Infiltration: Hackers could use stolen internal personnel registries, agent titles, and applicant profiles to target current FBI staff. By citing real colleague names, internal job postings, or specific department codes, bad actors can craft hyper-targeted phishing emails to trick employees into surrendering internal network credentials. The goal of this attack would be to gain access to restricted databases, confidential files, and sensitive intelligence networks.
- External Impersonation and Consumer Fraud: Scammers could also exploit stolen agent credentials to trick the general public. By matching leaked names with real public offices, fraudsters could contact civilians claiming to be active federal agents conducting official investigations, pressuring targets into paying fake fines or forfeiting financial credentials.
Watch for Warning Signs of FBI Impersonation Scams
Because this breach may have exposed real personnel details, impersonation attempts carry heightened risk. Scammers could pair verified agent names, genuine department titles, and realistic internal background details with fake caller ID tags, making fraudulent outreach appear legitimate. Be extra vigilant for these red flags that you may be dealing with an impersonation scam:
- Demands for immediate payment. Federal agencies will never call to demand immediate payment, and do not accept payment via gift cards, cryptocurrency, wire transfers, or cash couriers.
- Threats of arrest or legal action. Impersonators use high-pressure tactics, claiming you face active arrest warrants or federal lawsuits if you do not pay or comply on the spot.
- Pressure to remain on the line. Scammers try to prevent you from independently verifying their identity. Legitimate law enforcement officers will allow you to hang up and call official public agency numbers.
- Spoofed caller ID and credentials. Scammers manipulate caller ID displays to mirror official FBI field office phone numbers or send emails containing legitimate bureau logos.
How to Protect Yourself from Impersonation Scams
Protect against impersonation schemes by verifying all unexpected contacts independently.
- Hang up and verify directly. If you receive a call claiming to be from the FBI or another federal agency, hang up immediately. Search for the official phone number of your local FBI field office on fbi.gov and call them directly to confirm if the inquiry is legitimate.
- Do not trust caller ID. Phone numbers displayed on caller ID can be spoofed to match real government offices.
- Avoid clicking links in unsolicited messages. If you receive an email or text message regarding an FBI application or investigation, do not click embedded links. Type the official URL ending in .gov directly into your browser.
What to Do If Your PII Was Compromised or You’ve Been Targeted by Scammers
If you shared personal details or sent funds to a scammer, or if you previously submitted job applications or personal information through federal career sites, take immediate action to secure your identity and accounts:
- Stop contact with scammers and cease payments. Block all phone numbers, email addresses, and messaging channels used by the scammer immediately. Do not transfer additional money.
- Notify your financial institutions. If you’ve initiated payment with a suspected scammer or notice charges that you did not approve, contact your bank, credit card issuer, or payment app provider right away to report fraudulent transactions and request charge reversals or account holds.
- Update passwords and activate multi-factor authentication (MFA). Change login passwords across all online accounts, starting with primary email and financial logins, and enable MFA using an authenticator app.
- Freeze your credit. Contact Equifax, Experian, and TransUnion to freeze your credit files, preventing attackers from opening loans or credit lines in your name.
- File an identity theft report. If your Social Security number or identity details were exposed, visit IdentityTheft.gov to submit a report and receive a personalized recovery plan.
- Preserve evidence. Save phone logs, text messages, emails, wire receipts, and digital wallet addresses associated with the scam.
Report Cybercrime to Help Make a Safer Internet
Reporting cybercrime and impersonation attempts helps law enforcement trace criminal networks like the ShinyHunters hacker group and shut down active fraud operations. Submit reports through these official channels:
- FBI Internet Crime Complaint Center (IC3): Submit a complaint regarding cyber breaches and online scams through the IC3 reporting portal.
- Federal Trade Commission (FTC): Rport fraud, impersonation, and identity theft directly to the FTC fraud reporting page.
- Federal Communications Commission (FCC): File complaints about illegal robocalls and caller ID spoofing via the FCC consumer complaint portal.
- Local Police Department: Contact local law enforcement if you experienced monetary loss or direct extortion threats.
- The FBI: Report direct agent impersonation through the official FBI contact page.
Prompt reporting provides law enforcement with vital intelligence to track threat actors and protect others from emerging scams.