FBI hacked – sensitive agent data leaked
Hackers behind NAIC breach now claim FBI agents' data, including spy-hunting roles
FBI hacked – sensitive agent data leaked
CYBER
By Matthew Sellers
23 Sep 2026

The extortion group that dumped the National Association of Insurance Commissioners' data onto the dark web this summer says it has now breached the FBI. The files it has shared suggest the damage goes well beyond a defaced website.

ShinyHunters took over the bureau's recruitment site, FBIJobs.gov, on Tuesday. It replaced the site's images with its own branding and claimed to hold sensitive data on nearly every FBI agent and on everyone who has applied to work there. The application portals were still offline on Wednesday.

A roughly 5,000-record sample handed to journalists goes well beyond a typical breach dump. According to an exclusive Reuters investigation, it includes Social Security numbers, home addresses, birth dates and emergency contacts, who are often spouses or children. In some cases it also ties named staff to China- and Russia-focused counterintelligence units, electronic surveillance teams and human-intelligence programs.

Reuters said it verified details for more than 22 people but could not authenticate the whole spreadsheet. The hackers say the sample is a small slice of a two- to three-terabyte haul.

Eric O'Neill, a former FBI counterintelligence operative, told Reuters the trove was "a foreign intelligence service goldmine."

The bureau has not said how the attackers got in. In a statement reported by NBC News, the FBI said it had not yet determined whether the breach started with a third-party provider or its own systems. It said it was working with the vendors that support the jobs site.

A familiar door?

The outlet 404 Media reported that the hackers first compromised an Oracle PeopleSoft server, software widely used by HR and recruiting teams, and then moved into an Amazon-hosted government cloud, according to TechCrunch. The FBI has not confirmed that version of accounts.

ShinyHunters exploited the same platform in a spring zero-day campaign that hit more than 100 organizations and put cyber underwriters on alert. The NAIC was one of the victims. The group later posted 3.1TB of data it said came from the regulator, then admitted parts of its description had been overstated.

Read next: NAIC extends private-rating deadlines as it recovers from June ShinyHunters breach

Why it matters for the market

The motive is unusual. ShinyHunters says it is holding the data hostage until the FBI withdraws a May advisory that accused the group of using exaggerated claims to pressure victims into paying. The group also says the attack is not about money.

The tactics, though, match what carriers are already paying claims on. Theft without encryption is becoming standard practice: data-theft-only attacks rose from 49% of extortion claims in the first half of 2025 to 65% in the second half.

Shared platforms also concentrate risk. The earlier ShinyHunters-linked Canvas breach potentially exposed up to 275 million students across roughly 9,000 institutions.

Read next: AssuranceAmerica MGA breach exposes policyholder data in employee-targeted attack

For brokers, the FBI case is a pointed reminder about HR and applicant systems. These systems often hold the most sensitive personal data an organization has, frequently on third-party infrastructure with patch schedules clients don't control. Because family members' details were included, far more people now face possible identity fraud, extortion or worse.

Cynthia Kaiser, the FBI's former deputy cyber director, told NBC News the information could be used "to target or physically harm FBI agents, personnel and their families."

Read next: Allstate breach claim raises questions about scope of exposure

The bureau says its investigation is ongoing. ShinyHunters says it does not plan to release more data for now.

Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB CA.