This is the confirmation beat, not the first claim. CyberMerge’s Sep 22 brief covered ShinyHunters alleging theft of employee and applicant data, with 404 Media reviewing a ~5,000-record sample and the FBI offering no confirmation. The new fact pattern: the Bureau has internally told staff a cyber security incident is declared and that SSNs and other employee PII were exposed. TechCrunch notes the FBI still has not issued a matching public confirmation beyond last week’s “aware / investigating / theft still undetermined” framing, and a Bureau spokesperson did not respond Monday.
Malwarebytes (Sep 28), citing BBC News, reports journalists have seen samples of stolen fitness-for-work medical examinations that identify agents by name and address and include blood and urine results plus doctors’ notes. BBC also reported staff fear and anger over counterintelligence and family-safety risk. Treat medical-table names (MedLink, BEAST) and “~60,000 staff” figures as attacker or secondary claims until the FBI prints them — CyberMerge leaves the official victim count Undisclosed.
ShinyHunters’ stated demand remains non-financial: retract or correct a May FBI public advisory the group says misrepresents them, with a threatened dump window measured in days (exact deadline shifts across reports). Attack path claims (Oracle PeopleSoft on the jobs portal; third-party vs Bureau environment) are still under investigation per secondary reporting; root cause is not yet confirmed. TechCrunch: the Special Agent application portal remained down at publication.
Context, not double-counting: Nextgov/FCW (Sep 23) earlier quoted the FBI as aware of the jobs-portal claim and investigating with cause undetermined; that is the pre-confirmation line this Monday update supersedes for the ticker. Separately, a suspected China-linked surveillance-system incident earlier in 2026 is a different event; TechCrunch draws the “second congressional notice” comparison.
Update Sep 29: ShinyHunters told Nextgov/FCW (Mon Sep 28, 4:48 PM ET) it “would never publish this data,” calling the confrontation a “marketing campaign” and saying its one-week demand “was not a threat.” That is an attacker claim: the statement does not say the records were deleted, and samples have already circulated to reporters. Nextgov also cites Brian Krebs reporting that Dutch authorities arrested a suspected ShinyHunters associate earlier this month, before the FBI claim. FBI official victim count: still Undisclosed.
POV: For the Breaking desk, the story flipped from claim-with-sample-checks to Bureau-acknowledged incident with SSN-class PII. Keep attacker terabyte / “all FBI” language in quotes. Watch for a formal major-incident notice to Congress (TechCrunch flag; not confirmed). Sources: TechCrunch Sep 28 + BBC/Malwarebytes for medical samples; Sep 22 404 Media for the original sample verification.
