Job seekers and staff often hand HR systems a stack of personal details. On September 22, 2026, BleepingComputer, TechCrunch, and CNN reported that the extortion group ShinyHunters claimed it breached FBI systems and stole sensitive data on current and former employees and job applicants, including personal information and health-related details per the group's claim. The FBI said it is aware of claims about unauthorized activity affecting FBIjobs.gov and is investigating. It has not publicly confirmed a full breach or data theft in those reports.

BleepingComputer (Lawrence Abrams, September 22, 2026) wrote that the group claimed initial access through an unpatched Oracle PeopleSoft zero-day, then movement into FBI-managed AWS GovCloud holding employee and applicant data. The outlet has not independently verified the zero-day, the lateral movement, or the volume the group claimed, about 2 to 3 terabytes. TechCrunch (Zack Whittaker, September 22, 2026) covered the same claims. 404 Media said it received a sample of about 5,000 purported employee records and that some names and phone numbers matched public records and DOJ personnel listings.
The group reportedly defaced apply.fbijobs.gov. FBI Jobs and the Special Agent Applicant Portal showed maintenance or unavailable messages. CNN (September 22, 2026) reported the FBI statement that it is investigating unauthorized activity linked to FBIjobs.gov.
Serey tries to respect user privacy and avoid holding a warehouse of sellable identity or KYC-style files. Smaller stores of sensitive applicant data can shrink what an attack can take, without promising that systems are always safe or that hacking finds nothing.

