
AI-generated summary
The FBI's job application portal, FBIJobs.gov, has been the primary method for applying to bureau positions since 2017. The portal remains offline following the breach. Earlier this year, a suspected Chinese hacking group infiltrated an FBI surveillance system, exposing targets of investigations.
The Federal Bureau of Investigation has reportedly told its agents and support staff that their personal information was stolen in a recent cyberattack that targeted the bureau’s job application portal.
It’s the bureau’s first acknowledgement that the personal information of FBI agents was taken in the breach. The FBI has not publicly confirmed a breach beyond a statement last week, in which it said it was aware that a hacking group had claimed a cyberattack, but that the theft of data was “still undetermined.”
As reported by MS NOW reporter Ken Dilanian over the weekend, the FBI has since declared a “cyber security incident” in an internal notification to staff, telling employees that their names, addresses, job titles, and their Social Security numbers were exposed.
Several media outlets have since confirmed that some of the stolen data included medical information, such as records relating to blood and urine samples, as well as psychiatric reports.
The hacking group called ShinyHunters previously told TechCrunch that they “have data on mostly all of FBI,” and a “substantial” amount of information on applicants who applied through the FBIJobs.gov portal. The hackers broke in by exploiting a vulnerability in an Oracle PeopleSoft server, which hosts reams of human resources information on agents and now-employees who applied through the portal.
The hackers told TechCrunch that they are not seeking a financial ransom, but are demanding the correction of an earlier FBI-issued report, which they say misrepresents their activities.
Justin Sherman, a national security expert, called the data breach a “counterintelligence disaster” for the U.S. government in a blog post for Lawfare. He warned that the data theft would “expose thousands of FBI personnel to profiling, phishing, foreign intelligence approaches, and much more.”
While the bureau has notified employees, it’s less clear if the FBI has disclosed the incident to lawmakers in Congress who have oversight of the FBI. Under federal law, alerting Congress is required when an intrusion meets the bar of a “major incident” — such as if a data breach involves the theft of personally identifiable information that is “likely to result in demonstrable harm” to U.S. national security.
It’s likely that bureau lawyers are trying to figure that out right now. If a disclosure is required, it would be the FBI’s second known notification to lawmakers this year about a data breach, after hackers, suspected to be Chinese, broke into a surveillance system that exposed targets of FBI surveillance and investigations earlier this year.
A spokesperson for the FBI did not respond to TechCrunch’s request for comment on Monday, and a White House spokesperson also did not respond to an email asking if the bureau had declared a major incident.
Representatives for several lawmakers whose jurisdictions cover oversight of the FBI did not have any immediate answers.
ABC News reports that the FBI’s job site has been the primary way to apply for a job with the bureau since 2017. The portal remains down at the time of publication.
AI outlook — possibilities, not facts
The FBI will be required to notify Congress about the breach as a major incident under federal law.
Likely · Within weeks
The FBI's job application portal will remain offline for an extended period while security vulnerabilities are addressed.
Very likely · Within weeks

SiMa.ai, a startup developing energy-efficient AI chips for robots, drones, and cameras, has secured a $150 million Series C funding round led by Fidelity Management & Research Company and Amplify, valuing the company at $1.45 billion. Founded in 2018 by former Groq COO Krishna Rangasayee, the company aims to capture the growing physical AI device market with low-latency, affordable alternatives to Nvidia GPUs.

At TechCrunch Disrupt 2026, Anthropic's Cat de Jong, Gamma's Grant Lee, and Clay's Kareem Amin will discuss enterprise AI deployment on the AI Stage, covering patterns from real-world implementations, challenges in moving from pilot to production, and insights on building AI products that solve actual customer problems and integrate into workflows.

The Dreame X50 Ultra robot vacuum and mop hybrid is discounted to $899.99 for Amazon Prime members, down from $1,599.99, with features including autonomous mop washing and drying, self-emptying bin for up to 100 days, and ability to climb thresholds up to 6 cm. Other deals include refurbished Asus ROG Ally handhelds and SteelSeries Arctis Nova Pro headsets on Woot, and Samsung's Movingstyle Essential 4K smart screen at $200 off.

TechCrunch announces 20 judges for Startup Battlefield 200 at Disrupt 2026, where 200 selected startups will compete in San Francisco October 13-15 for a $100,000 equity-free prize, with final five judges to be revealed soon.

ElevenLabs has released its v4 and v4 Turbo speech models, featuring enhanced expression control, faster voice cloning, and support for 90 languages. The update aims to improve conversational fluidity for enterprise voice agents and follows a period of rapid growth.

Truecaller has launched Scam Checker, a free web and Android service that allows users to check suspicious phone numbers, links, or messages for fraud using its community-driven ScamFeed database, initially available in India with plans to expand to Latin America, the Middle East, Africa, and Southeast Asia.