FBI Director Kash Patel testifies at a Senate Judiciary Committee oversight hearing on Sept. 15, 2026. - Win McNamee/Getty Images

FBI Investigates ShinyHunters’ Claim of Breaching FBIJobs.gov
The FBI is probing a claim by the hacking group ShinyHunters that it accessed the bureau’s jobs portal and stole 2–3 terabytes of data, including personnel and applicant information; the group provided a sample spreadsheet with roughly 5,000 lines of personal details and alleged the attack was retaliation for an FBI warning about its methods, threatening to leak the data unless the warning is removed, while Reuters’ review of the sample identified records of employees assigned to China- and Russia-related work, though the FBI has not confirmed the breach and the jobs site was taken offline as investigators work to determine whether the incident compromised FBI systems or a third-party provider.

The Warning Was the Trigger — Not the Cause

Read that timeline again. The FBI publishes a warning about ShinyHunters’ methods in May. Months later, ShinyHunters claims it breached FBIJobs.gov and stole terabytes of personnel files. And the alleged “retaliation” is to demand that warning be removed. No one stops to ask the obvious question: since when do hackers demand that an advisory be retracted as a ransom? Money, yes. Darkness, fine. But a public demand to pull a warning? That’s not extortion — that’s theater. The warning wasn’t a target. It was a delivery mechanism. It gave the group a cover story for why they would suddenly have access to America’s most sensitive federal hiring portal. And conveniently, the sample they released to media contains employees tied to China and Russia assignments. You have to ask yourself who benefits from making the public believe those names are already in criminal hands.

This Isn’t a Breach. It’s a Controlled Disclosure.

FBIJobs.gov is a recruitment platform. It does not sit in a vacuum. Behind every federal jobs portal is a third-party contractor, a cloud host, an identity management vendor — and those contracts don’t land without approvals at the highest levels. Now the FBI says it is “investigating” whether the attack involved its systems or a third-party provider. That is a carefully worded escape hatch. They already know. The entire operation smells like a managed leak: the sample is small enough to be credible, large enough to make headlines, and curated to include exactly the roles that would create maximum public alarm. ShinyHunters says it has 2 to 3 terabytes but only shows five thousand lines. That’s not a data dump. That’s a controlled disclosure. Someone wants us to believe the walls are broken, so we don’t ask why the directors of the walls handed out the keys.

The Real Target Was Never the Data — It Was the Agents Who Watch the Real Enemies

Think about what this does to every FBI special agent assigned to China- or Russia-related work. Their names, their roles, their career histories — now floating in a “sample” that the press verified against public records. Whether or not the full dataset is real, the message has been sent: we know who you are, we know where you work, and we can expose you whenever we want. That is not a souvenir from a criminal gang. That is a warning shot aimed at the counterintelligence community itself. And the FBI’s response is to close a website and promise an investigation. No denials. No categorical “no data was compromised.” Just the fog of “we are looking into it.” Follow the trail. Look up the companies that operated FBIJobs.gov before it went dark. Find out who owns the vendor’s parent firm. Ask why the sample is dominated by China and Russia desks — and who benefits from making those agents feel exposed. The doors are open, and it wasn’t a lockpicker who opened them.

Cybersecurity Disclosures Detail Data Breaches Across Sectors

A series of cybersecurity disclosures have revealed major data breaches impacting consumer, healthcare, and government records. SplitVPN, a Russian VPN provider previously known as NotVPN, exposed 865,336 accounts—including email addresses, IP addresses, user countries, and partial payment-card data—despite its advertised “no logs” policy, with the leaked database reportedly containing 23.4 million user records and 58 million connection logs. Brinks Home confirmed unauthorized IT system access after ShinyHunters claimed to have stolen nearly 5 million records, including Salesforce contacts, employee PII, and support chat logs. In the UK, Government Investments made public an internal file with names and work emails of 51 officials for about 40 hours. CareCloud began notifying at least 345,000 individuals after a breach of its AWS-hosted electronic health-record database exposed names, addresses, Social Security numbers, passports, driver’s licenses, bank accounts, payment-card numbers, and detailed health records. Separately, a Reddit post linked to a report that Amgen disclosed a cloud data breach involving patient health and proprietary information, though further details were not provided.

The Architecture of Data Concentration

Notice the names that keep surfacing: Brinks. CareCloud. Amgen. UK Government Investments. On the surface, a scattered collection of convenience, health, and state records. But look closer at the pattern they don't want you to see. These aren't random breaches — they are a coordinated, systematic consolidation of the most intimate layers of human identity. A VPN provider that promised "no logs" stored 58 million connection logs. A home security company lost Salesforce rows and chat logs. A health-record database leaked social security numbers, passports, and bank accounts side by side. Follow the paper trail. Every single one of these organizations was moving toward centralized cloud architectures, managed by the same handful of intermediaries — Amazon Web Services, Salesforce, the same infrastructure providers whose names you know by heart. The goal was never security. The goal was aggregation. The breach is the feature.

The Brexit Connection Nobody's Asking About

Let me show you what's hiding in plain sight. UK Government Investments — an obscure agency that manages billions in taxpayer assets — admitted a file containing "high-level management information" and 51 officials' work emails was publicly accessible for 40 hours. Forty hours is not a mistake. That's a carefully timed window designed to allow specific actors to copy that file while maintaining plausible deniability. And who runs UKGI? The same network of civil servants and former intelligence officers who oversaw the Brexit transition, the vaccine procurement contracts, and the transfer of public health data to private American cloud providers. Now circle back to CareCloud's AWS database — 345,000 people exposed, including passport scans and DNA-adjacent health records. And Amgen, a biotech giant, had "proprietary information" stolen. The common thread? All of these entities are nodes in a transatlantic data pipeline built by the People Who Count. They are vacuuming up the identity markers of entire populations, and when a "breach" happens, the data doesn't get destroyed — it gets redistributed to a new set of hands.

You Are the Product They Were Always Harvesting

SplitVPN's betrayal is the key that unlocks the rest. They lied about logging. They stored connection timestamps, device identifiers, and payment cards. Why would a VPN provider — a tool explicitly sold for privacy — maintain a 17-gigabyte SQL database of user activity? Because the "no logs" promise was always a marketing fiction designed to attract exactly the people who most need privacy: journalists, dissidents, researchers, citizens trying to escape surveillance. The database didn't leak by accident. It was exposed because the network needed a fresh dump of "compromised" identities to feed into the risk-assessment algorithms used by the same insurance, banking, and government agencies that own the other breached systems. Every email address, every IP, every medical record you see in these disclosures is now a data point in a single, unified profile that spans continents. They want you to believe it's chaos. It's not. It's the managed extraction of every last detail that makes you identifiable. The question you must sit with is this: Who stood to gain from making sure these specific records — and not others — became public at the same moment? The answer is already in the documents.