By Jeff Lanza, Retired FBI Special Agent and Cybercrime Expert

If the personal information of FBI employees can be compromised, what does that say about the rest of us?

That’s one of the important lessons emerging from a developing cybersecurity incident involving FBIJobs.gov and potentially sensitive information belonging to FBI personnel.

On September 23, 2026, the FBI acknowledged that a cybercriminal group was claiming it had compromised the FBIJobs.gov portal and affected personally identifiable information, or PII, belonging to FBI employees.

The FBI said it was “actively and aggressively investigating” the incident. Importantly, the Bureau said it had not yet determined whether the point of compromise was within the FBI’s own enterprise or through a third-party provider supporting FBIJobs.gov.

Since then, the story has become more concerning.

This is exactly the kind of incident I unpack for audiences in my keynote on the current cybersecurity landscape — how fast-moving breach news like this translates into real risk for your employees and customers. Book Jeff to speak at your next event →

What Information May Have Been Exposed?

The cybercriminal group known as ShinyHunters has claimed responsibility for the incident.

According to Reuters, journalists reviewing samples provided by the hackers found information involving FBI employees, including details connected to sensitive intelligence assignments. Reuters subsequently reported that material supplied by the hackers also included psychiatric and medical evaluation records. Reuters said it was able to partially authenticate some of the information.

Those reports do not mean that every claim made by the hackers has been verified. The FBI continues to investigate the scope of the incident and how the compromise occurred.

That distinction is important.

During a developing cyber incident, criminal groups may make claims about what they accessed, how they obtained it and how much information they stole. Those claims should not automatically be treated as established fact.

But there is already enough here to teach us something important about identity theft and cybersecurity.

The Lesson Isn’t That the FBI Doesn’t Understand Cybersecurity

As a retired FBI Special Agent, I spent more than 20 years investigating crime. Today, I speak to organizations and individuals across the country about cybercrime, identity theft and fraud prevention.

One thing I emphasize is this:

You can do everything right and still have your personal information exposed.

Why?

Because we don’t control every organization that possesses our information.

Employers have it. Financial institutions have it. Healthcare providers have it. Government agencies have it. Insurance companies have it. Retailers and technology companies may have it.

And those organizations frequently rely on still more organizations — vendors, cloud providers and other third parties — to store or process that information.

In the FBI incident, the Bureau has specifically said that investigators are still determining whether the point of compromise was within the FBI’s enterprise or a third party supporting FBIJobs.gov.

That’s a cybersecurity reality that affects all of us — individuals and businesses alike.

A Data Breach Can Be the Beginning of the Scam

People sometimes think the primary danger of a data breach is that a criminal will immediately steal money from their bank account.

That’s only part of the risk.

Stolen personal information can make the next scam much more believable.

Imagine receiving a telephone call, text message or email from someone who already knows your:

  • Full name
  • Address
  • Telephone number
  • Employer
  • Job title
  • Date of birth
  • Family information
  • Or other personal details

Suddenly, the person contacting you doesn’t sound like a stranger.

They sound legitimate.

A criminal might impersonate your bank, an employer, law enforcement, a government agency or another trusted organization.

And this is where personal information becomes extremely valuable to scammers.

The criminal isn’t necessarily trying to steal your identity in the traditional sense.

They may be using your identity information to earn your trust.

Personal Information Is Not Proof of Identity

This is one of the most important lessons consumers can take from any data breach:

Someone knowing information about you does not prove that they are who they claim to be.

Your address isn’t a secret.

Your telephone number may not be a secret.

Your relatives may not be a secret.

Your employment history may not be a secret.

And after a data breach, even information that was previously difficult to obtain may be available to criminals.

So when someone contacts you and uses personal information to establish credibility, don’t automatically trust them.

Instead:

STOP.

Use logic, not emotion.

Verify before you trust.

If someone claims to represent your bank, don’t rely on the telephone number, link or contact information they provide.

Contact the organization independently using information you know is legitimate.

What Should You Do After Your Information Is Exposed?

The exact response depends on what information was compromised, but several safeguards are particularly important.

1. Freeze Your Credit

A credit freeze can make it significantly harder for an identity thief to open a new credit account in your name.

The Federal Trade Commission says credit freezes are free, do not affect your credit score and remain in effect until you remove or temporarily lift them.

You need to freeze your credit separately with Equifax, Experian and TransUnion.

2. Review Your Credit Reports

Look for accounts or activity you don’t recognize. Consumers can obtain free credit reports and should continue checking them periodically.

3. Use Strong, Unique Passwords

Never reuse an important password across multiple accounts.

If one company’s database is compromised and you’ve reused the same password elsewhere, criminals may try those credentials against your email, financial and other accounts.

4. Use Multi-Factor Authentication — and Passkeys When Available

Multi-factor authentication provides another layer of protection if a password is compromised.

For important accounts, phishing-resistant authentication such as passkeys or security keys can provide even stronger protection.

5. Turn on Account Alerts

Banks and credit card companies can notify you about transactions and other account activity. The sooner you know something is wrong, the sooner you can react.

6. Be Especially Suspicious of Unexpected Contact After a Breach

This may be one of the most overlooked protections.

If criminals possess information about you, expect them to use it.

A convincing email or telephone call doesn’t become legitimate simply because the person contacting you knows personal details.

Slow the interaction down and independently verify it.

Want your team or association to hear this directly from an FBI veteran? Book Jeff Lanza for a keynote on cybercrime and identity theft prevention that turns headlines like this one into practical, non-technical takeaways your audience will actually use.

Why This FBI Incident Matters to Everyone

Most people reading this aren’t FBI employees.

But that’s exactly why this story matters.

The lesson isn’t simply that another organization experienced a cyber incident.

The bigger lesson is that we live in an environment where enormous amounts of information about us are stored in places we don’t control.

We can’t prevent every data breach.

What we can control is what happens next.

We can make stolen information less useful.

We can freeze our credit.

We can protect our accounts.

We can use stronger authentication.

And, perhaps most importantly, we can refuse to allow a criminal’s knowledge about us to become the reason we trust them.

Technology will continue to change.

The scams will continue to evolve.

But one of our most effective defenses remains remarkably simple:

STOP. Use logic, not emotion. Verify before you trust.

Frequently Asked Questions

Was the FBI hacked in 2026?

The FBI has confirmed that it is investigating a cybercriminal group’s claim involving a compromise of the FBIJobs.gov portal and alleged exposure of FBI employee personally identifiable information. As of this writing, the FBI says the point of compromise remains under investigation and could involve either a third-party provider or the FBI’s enterprise.

Who is ShinyHunters?

ShinyHunters is the name associated with a cybercriminal ecosystem that has been linked to numerous large-scale data theft and extortion incidents. The group has claimed responsibility for the FBIJobs.gov incident.

What information was reportedly exposed?

Hackers have made extensive claims about information they obtained. Reuters has reviewed samples containing information involving FBI employees, including sensitive intelligence-role information, and subsequently reported reviewing psychiatric and medical records. Some of the information was partially authenticated by Reuters. The full scope of the incident has not been publicly established by the FBI.

Should I freeze my credit after a data breach?

A credit freeze is one of the strongest steps consumers can take to reduce the risk of criminals opening new credit accounts in their names. The Federal Trade Commission says anyone can freeze their credit for free, even if they have not experienced identity theft.

Where can victims of identity theft get help?

The Federal Trade Commission operates IdentityTheft.gov, which provides reporting tools and personalized recovery steps for victims of identity theft.

Book Jeff Lanza for Your Next Event

Stories like the FBIJobs.gov breach break every few weeks — and most organizations only react after their own people have already been targeted. Jeff Lanza spent more than 20 years as an FBI Special Agent investigating the exact crimes he now helps audiences prevent. His keynotes on identity theft prevention, cybercrime for business, and the current cybersecurity landscape turn stories like this one into practical, memorable takeaways for your team, association, or conference.

Book Jeff to Speak →


About Jeff Lanza

Jeff Lanza is a retired FBI Special Agent who spent more than 20 years investigating crime, including cybercrime and fraud. Today, he speaks to organizations across the country about identity theft, cybercrime, fraud prevention and how individuals and businesses can protect themselves from today’s evolving threats. Read Jeff’s full bio →