In context
Hackers claim they stole data on all FBI agents
First published 24 September 2026, 12:39 UTC.
What happened
ShinyHunters claims it breached FBI servers on Monday night and began giving reporters samples on Tuesday, saying it holds names, roles, badge numbers, home addresses, phone numbers and spouse details for about 38,000 bureau staff. The FBI said on X that it is aware of the claim and is "actively and aggressively investigating", including working with third-party providers that support FBIJobs.gov to establish whether its own systems or a supplier were breached.
This account currently relies on BBC News. We have not independently corroborated it.
Why it matters
If the claim holds up, home addresses and family details of federal agents working on Chinese and Russian intelligence cases and drug cartels would be a personal safety and counterintelligence problem that no patch can undo. The competing reading is that ShinyHunters has a record of exaggerating access to raise its profile, and the FBI's own carefully worded statement leaves open that a contractor system, not the bureau, was breached. Watch whether the FBI names the source and whether the group follows through on its threat to publish.
How we got here
ShinyHunters is an international hacking collective, believed by the BBC to have started in France, that has spent several years stealing and selling large customer databases from technology, retail and finance companies. Its business model has shifted over time from selling stolen records on criminal forums towards direct extortion of the companies whose data it takes, often by exploiting access to cloud platforms rather than breaking into corporate networks directly. In May the FBI issued a public service announcement describing the group as threat actors who use real or exaggerated claims of access to sensitive data to extract payment. The group now says it was offended by that description and is demanding a retraction, which would make this an attack aimed at reputation rather than revenue. Large breaches of United States federal personnel data are not new: the 2015 theft of Office of Personnel Management background investigation files exposed records on more than 21 million people.
How we got here, dated
- 2015OPM breach exposes federal background files. The US Office of Personnel Management disclosed thefts affecting more than 21 million people, including security clearance background investigation records, later attributed by US officials to Chinese state hackers. Source
- 2020ShinyHunters emerges as a data broker. The group surfaced selling databases from companies including Tokopedia and Wattpad on criminal forums, building a reputation for bulk theft of customer records. Source
- 2022Lapsus$ arrests show the model's weakness. British police arrested teenagers linked to the Lapsus$ extortion group after it breached firms including Nvidia and Okta, a reminder that publicity-seeking hackers often get caught. Source
- 2024Cloud data warehouse attacks hit large companies. A campaign against customers of the cloud data platform Snowflake led to mass data theft from companies including AT&T and Ticketmaster, with arrests following in Canada and Turkey. Source
- May 2025FBI publicly names ShinyHunters as a threat. An FBI public service announcement described the group as threat actors who use real or exaggerated claims of access to sensitive data to prompt payment from victims across tech, finance and retail. Source
- 2025High-profile breaches attributed to the group. The BBC reports the group was behind breaches including Rockstar Games in April and a disruptive hack on the education platform Canvas in May. Source
- February 2026Claimed FBI breach and retraction demand. ShinyHunters says it breached FBI servers via an Oracle cloud vulnerability and holds records on about 38,000 staff, demanding the May advisory be withdrawn within a week; the FBI says it is investigating. Source
A useful comparison
The Office of Personnel Management data breach, disclosed in 2015. Both involve the theft of highly sensitive personnel and background-check records on United States federal employees, with obvious counterintelligence value because they link named officials to security clearances, addresses and family members.
Where the comparison breaks down: The OPM theft was quiet state-linked espionage attributed by US officials to China, discovered only after the fact. Here a criminal collective is publicising the breach immediately and demanding a public retraction rather than money or secrecy, and the intrusion itself is still unconfirmed and may have happened at a supplier rather than inside the FBI.
What remains unclear
- The FBI has not confirmed that any breach occurred, or whether any compromise was of its own systems or a third-party provider.
- The claim of data on all roughly 38,000 staff is the hackers' own figure; the BBC says it saw only a small portion of the data, which appeared genuine.
- The group's claim to have exploited an Oracle cloud vulnerability to reach systems including FBI BEAST, MedLink and BICS is unverified.
- It is unknown whether the group will publish the full databases after its stated one-week deadline, or how the FBI will respond to the retraction demand.
What to watch
Whether the FBI confirms the source of any compromise, names an affected supplier, or notifies staff, and what happens when the group's stated one-week deadline expires.
Sources and evidence
- BBC News: FBI investigating claim hackers have stolen details of all its agents · Full article · 24 September 2026
Read the original reporting at the links above. Our analysis can be wrong and may change as evidence develops.
Related background
- This Is How They Tell Me the World Ends — Nicole Perlroth
- Sandworm — Andy Greenberg
- Office of Personnel Management data breach — Wikipedia