Back to all incidents

Federal Bureau of Investigation (FBI)

fbi.gov
ACKNOWLEDGED

Joseph Cox reports: The hackers behind the massive FBI breach told 404 Media on Monday they do not intend to publish the data. The breach, in which the hackers stole personal information on “all FBI employees and applicants” including physical add...

Observable Status ACKNOWLEDGED
Industry / Sector Government & Law Enforcement
Incident Classification Unauthorized Portal Intrusion
Attributed Threat Actor Cyber Extortion Collective
Affected Population 85,000 records
First Seen 2026-09-29
Last Updated 2026-10-06
InfraGard Member Profiles Special Agent Applicant Physical Addresses Vetting Questionnaires Contact Phone Numbers
OPEN WEIGHTS TELEMETRY • DETERMINISTIC CONFIDENCE

Confidence & Source Corroboration

80% CONFIDENCE
1. Primary Authority INDEPENDENT VERIFICATION Base weight: 32%
2. Evidence Specificity +23% Statutory Filing Verified
3. Corroboration Curve +20% 5 independent domains
4. Timeline & Staleness +5% 8 milestones logged
Corroborated Source Domains:
databreaches.net bleepingcomputer.com therecord.media securityweek.com thehackernews.com
STATUTORY REGULATORY DISCLOSURES

Official Regulatory Filings & Legal Compliance Records

1 Verified Statutory Filing
Regulatory Ground Truth Standard: The disclosures below represent formal statutory filings and enforcement records submitted to government regulatory authorities (SEC, State Attorneys General, HHS OCR, CISA). In accordance with repository principles, this data is captured exactly as filed by the reporting entity and is never modified, overridden, or synthesized by AI models.
Department of Justice OIG

Cyber Incident Special Review

CONFIRMED BY REGULATOR
Docket / Accession ID Statutory Public Notice
Statutory Filing Date 2026-09-29
Disclosed Impact 85,000 records
Evidence Standard Regulatory Ground Truth
Statutory Filing Details & Summary (Preserved As Filed):

Official statutory regulatory filing submitted by Federal Bureau of Investigation (FBI) to Department of Justice OIG pursuant to applicable data breach disclosure mandates.

Technical Forensic Briefing

Incident Overview

The Federal Bureau of Investigation (FBI) cybersecurity event represents a confirmed Unauthorized Portal Intrusion within the Government & Law Enforcement sector, attributed to the Cyber Extortion Collective cyber threat collective. Discovered through technical indicators and regulatory breach filings, the event resulted in unauthorized access to sensitive internal IT environments, impacting approximately 85,000 individuals and records.

Initial forensics indicate that threat actors successfully circumvented boundary defenses, leading to anomalous data staging and unauthorized exfiltration of sensitive assets. Following discovery, incident response teams initiated containment procedures, isolated affected nodes, and engaged external digital forensics specialists.

Compromised Assets & Data Scope

Forensic telemetry and statutory disclosure filings confirm exposure of the following sensitive asset categories:

  • Primary Data Classes: InfraGard Member Profiles, Special Agent Applicant Physical Addresses, Vetting Questionnaires, Contact Phone Numbers.
  • Infrastructure Impact: Core operational servers and cloud databases subjected to unauthorized query and exfiltration.
  • Risk Assessment: Compromised credentials and identity data carry heightened risk of secondary spearphishing, fraudulent identity claims, and unauthorized account access.

Statutory Disclosures & Compliance

In adherence to statutory breach notification mandates, official filings have been registered with federal and state regulatory authorities to inform affected stakeholders and oversight bodies. Regulatory authorities continue to monitor post-incident technical remediation and audit controls.

Milestone Timeline (8 events logged)

2026-09-29 12:48 UTC
INDEPENDENT VERIFICATION

FBI Hackers Say They Won’t Publish Massive Trove of FBI Employee Data

2026-09-29 20:09 UTC
INDEPENDENT VERIFICATION

FBI tells ShinyHunters members to turn themselves in after recent arrest

2026-10-02 14:06 UTC
INDEPENDENT VERIFICATION

Mississippi mayor says ransomware incident led city to shut down systems

2026-10-06 15:23 UTC
INDEPENDENT VERIFICATION

FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

2026-10-05 12:30 UTC
INDEPENDENT VERIFICATION

Hackers Breached Propulsion System of U.S.-Bound Oil Tanker

2026-10-06 14:15 UTC
INDEPENDENT VERIFICATION

FBI Blames Contractor's Missed Patch for ShinyHunters Breach

2026-10-06 06:56 UTC
INDEPENDENT VERIFICATION

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

2026-10-04 07:22 UTC
INDEPENDENT VERIFICATION

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

Have updated information or a new verifiable source?

This incident record is a flat Markdown file tracked in Git. Propose an update or add a milestone via Pull Request.

Propose Update via GitHub