The group released a 5,000‑line sample spreadsheet, which it says represents only a fraction of a two‑ to three‑terabyte data trove. The file lists names, addresses, telephone numbers, dates of birth, Social Security numbers, emergency‑contact information and, in many cases, specific job assignments to field offices or sensitive units such as the China criminal enterprise unit, Russia Operations Section, and covert technical operations.

The FBI confirmed it was aware of a “cyber‑criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information.” The bureau said the cause of the breach was still undetermined and that it was “actively and aggressively investigating the matter.”

ShinyHunters said it is holding the data hostage until the FBI rescinds a critical statement the agency issued about the group in May. In a Sept. 23 statement the hackers added they are trying to keep the personnel information from circulating widely and warned that any wider leak would not be their doing.

Reuters was able to verify details for more than 22 individuals by cross‑referencing the leaked information with credit records and prior dark‑web leaks. The agency also matched the career titles of eight people to public court filings, news articles, LinkedIn profiles and social‑media posts, confirming that at least some of the assignment data is authentic.

Former FBI counter‑intelligence operative Eric O’Neill described the stolen data as “a foreign intelligence service goldmine,” noting that adversaries such as China would be eager to identify agents working against them. He warned that the exposure of human‑intelligence operatives and their emergency contacts could endanger both the agents and their families.

Security analysts said the breach, if confirmed, could compromise ongoing investigations, endanger undercover personnel and provide hostile intelligence services with a roadmap to U.S. counter‑espionage efforts. The FBI has not disclosed the total number of affected employees or the full scope of the data stolen.

The bureau’s investigation remains ongoing, and officials have not indicated whether any operational changes will be made to protect the exposed staff. ShinyHunters has not indicated a timeline for releasing the remainder of the claimed data set.