The FBI confirmed it is investigating a breach of its FBIJobs.gov portal after a cyber-criminal enterprise group claimed to have compromised the system and accessed personally identifiable information (PII) of FBI employees. The agency stated it is working with third-party providers to mitigate risk, though the point of breach—whether a third-party or the FBI's own enterprise—remains undetermined.
404 Media, which first reported the breach, identified three entries in the leaked data specifically naming the Remote Operations Unit, the FBI's hacking unit responsible for developing network investigative techniques (NITs) used in dark web and national security operations. The data includes each individual's address, multiple phone numbers, and in some cases spouse names and contact details.
The leak also includes job titles such as Special Agent, Threat Intake Examiner, and Major Cyber Crimes Unit. Reuters reported that some titles relate to investigations of China or Russia. The exposure of ROU members is particularly sensitive, as the unit's composition and operations have largely remained secret. According to a 2020 Office of the Inspector General report, the ROU was instrumental in developing the NIT deployed on a dark web child abuse site that the FBI operated for two weeks, and its focus has since shifted to national security investigations. Much of that report remains redacted.