Full Breakdown
FBI Jobs Portal Hack and Dutch Arrest Highlight Growing Cybercrime Threat
By Drooid · · How we work
The Hack and Immediate Fallout
On September 22, the cyber-extortion group ShinyHunters announced it had breached the FBI’s jobs portal (apply.fbijobs.gov), defaced the site and extracted 2–3 TB of personnel data. The group demanded the FBI retract a May 2026 advisory describing ShinyHunters as a “threat actor,” giving a deadline of September 29. The deadline passed without change, and ShinyHunters’ public website went offline on September 30.
Background & Context
ShinyHunters has a long record of targeting corporations and government agencies for data theft and extortion.
Timeline
| Date | Event |
|---|---|
| May 27 | Began exploiting a critical Oracle PeopleSoft vulnerability (CVE-2026-35273). |
| June 10 | Oracle disclosed the PeopleSoft flaw. |
| Sept 15 | Dutch police arrested a 24-year-old Amsterdam man suspected of involvement. |
| Sept 22 | ShinyHunters announced the FBI jobs-portal breach. |
| Sept 23 | FBI said it was “actively and aggressively investigating.” |
| Sept 25 | Mandiant and Google’s Threat Intelligence Group confirmed a second wave of PeopleSoft exploitation. |
| Sept 30 | ShinyHunters’ website went offline after the deadline. |
Data & Statistics
- ShinyHunters claimed to have stolen 2–3 TB of data, including Social Security numbers, home addresses, phone numbers, badge numbers and medical records.
- The FBI’s internal memo said personally identifiable information of all bureau employees may have been obtained.
- Reported scope varies: the BBC cited “around 38,000” staff; other outlets described the breach as affecting “thousands” of employees.
Official Statements & Responses
- The FBI’s Cyber Division, led by Assistant Director Brett Leatherman, said the bureau was “working around the clock” and urged staff to remain vigilant.
- Dutch National Police confirmed the arrest of the 24-year-old suspect, identified as Pepijn van der Stap, and seized laptops containing “a large amount of information,” including alleged murder-for-hire plot details.
Verbatim Quotes
- “As we speak FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest," Patel wrote.” — Kash Patel, FBI director
- “To the remaining members of ShinyHunters: You’ve heard about the arrest of your colleague,” — Brett Leatherman, division assistant director
Conflicting Reports & Gaps
Sources differ on the exact volume of data stolen and the number of individuals affected. While the BBC and Dutch officials cite roughly 38,000 personnel, other U.S. outlets describe the breach as involving “thousands.” Reuters could not verify the provenance of the psychiatric and medical files shared by the hackers. No public evidence confirms ShinyHunters’ claim of accessing additional FBI systems beyond the jobs portal.
Why It Matters
The breach potentially exposed sensitive law-enforcement assignments, medical records and personal identifiers of a large portion of the U.S. investigative workforce. Comparisons have been drawn to the 2015 Office of Personnel Management breach, which prompted sweeping reforms in federal data security. The incident highlights the risk posed by zero-day exploits in widely used enterprise software and the challenges of attributing attacks across borders.
What’s Next
The FBI says its investigation remains ongoing, with multiple divisions assessing the full scope and providing identity-protection services to affected employees. Dutch authorities have not ruled out further arrests and continue to examine seized devices for additional evidence. Both agencies emphasize continued collaboration with international partners as they pursue leads stemming from the September 15 arrest.
