BREACH

FBI declares “cyber security incident” — agent PII including SSNs exposed.

The Bureau has moved past “theft still undetermined.” Per TechCrunch (Sep 28) and weekend reporting by MS NOW’s Ken Dilanian, an internal staff notification says the FBI declared a “cyber security incident” tied to the FBIJobs.gov portal hack and that employee personally identifiable information — including Social Security numbers, names, addresses, and job titles — was exposed. Multiple outlets report medical “fitness-for-work” material in circulating samples. Attacker census and full systems list stay Undisclosed / claim-stage.

Sep 28, 2026 · 3 min read

This is the confirmation beat, not the first claim. CyberMerge’s Sep 22 brief covered ShinyHunters alleging theft of employee and applicant data, with 404 Media reviewing a ~5,000-record sample and the FBI offering no confirmation. The new fact pattern: the Bureau has internally told staff a cyber security incident is declared and that SSNs and other employee PII were exposed. TechCrunch notes the FBI still has not issued a matching public confirmation beyond last week’s “aware / investigating / theft still undetermined” framing, and a Bureau spokesperson did not respond Monday.

Malwarebytes (Sep 28), citing BBC News, reports journalists have seen samples of stolen fitness-for-work medical examinations that identify agents by name and address and include blood and urine results plus doctors’ notes. BBC also reported staff fear and anger over counterintelligence and family-safety risk. Treat medical-table names (MedLink, BEAST) and “~60,000 staff” figures as attacker or secondary claims until the FBI prints them — CyberMerge leaves the official victim count Undisclosed.

ShinyHunters’ stated demand remains non-financial: retract or correct a May FBI public advisory the group says misrepresents them, with a threatened dump window measured in days (exact deadline shifts across reports). Attack path claims (Oracle PeopleSoft on the jobs portal; third-party vs Bureau environment) are still under investigation per secondary reporting; root cause is not yet confirmed. TechCrunch: the Special Agent application portal remained down at publication.

Context, not double-counting: Nextgov/FCW (Sep 23) earlier quoted the FBI as aware of the jobs-portal claim and investigating with cause undetermined; that is the pre-confirmation line this Monday update supersedes for the ticker. Separately, a suspected China-linked surveillance-system incident earlier in 2026 is a different event; TechCrunch draws the “second congressional notice” comparison.

Update Sep 29: ShinyHunters told Nextgov/FCW (Mon Sep 28, 4:48 PM ET) it “would never publish this data,” calling the confrontation a “marketing campaign” and saying its one-week demand “was not a threat.” That is an attacker claim: the statement does not say the records were deleted, and samples have already circulated to reporters. Nextgov also cites Brian Krebs reporting that Dutch authorities arrested a suspected ShinyHunters associate earlier this month, before the FBI claim. FBI official victim count: still Undisclosed.

POV: For the Breaking desk, the story flipped from claim-with-sample-checks to Bureau-acknowledged incident with SSN-class PII. Keep attacker terabyte / “all FBI” language in quotes. Watch for a formal major-incident notice to Congress (TechCrunch flag; not confirmed). Sources: TechCrunch Sep 28 + BBC/Malwarebytes for medical samples; Sep 22 404 Media for the original sample verification.

Sources