FBI memo reportedly tells staff to assume hackers stole all employee data

According to an internal memo reviewed by the New York Times, the FBI is telling its own staff to assume their personal information was stolen by hackers. Gizmodo reports that the memo apparently says: "We are operating under the premise that the threat actor is also exfiltrating [personally identifiable information] of all F.B.I. employees."
The incident is the ShinyHunters hack of the FBI's jobs portal, FBIJobs.gov, originally reported on Tuesday of last week. The initial hack caused the portal to display a banner reading "This site has been seized by ShinyHunters." ShinyHunters told 404 Media, which broke the news of the attack, "We hacked the FBI. We hold data on all FBI employees and applicants." Judging by the Times' view of the internal communications, Gizmodo says, that claim does not appear to have been an exaggeration.
The memo outlines next steps, including what the Times calls "virtual briefings" still to come. It also urges employees to be on the lookout for suspicious text messages or calls from unknown numbers. Employees should, the memo apparently says, create new voice mail greetings with AI voices.
In a public statement on Monday, relayed by the Times, the FBI said the bureau is "working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted, including multiple bureau-wide communications within 24 hours of public reporting." It added: "The F.B.I. treats the security of its information and the safety of its work force as top priorities, and our investigation is ongoing."
Gizmodo's take is sardonic, calling the hack humiliating and poking fun at a bureau of investigation that was breached. The factual core is the memo's stated assumption, as relayed by the Times, that employee data was taken, not a confirmed inventory of what was stolen.
Key facts
- An internal FBI memo, reviewed by the New York Times, says the bureau is operating on the premise that the threat actor is also exfiltrating personally identifiable information of all FBI employees.
- The breach began with ShinyHunters defacing the FBIJobs.gov jobs portal with a banner reading "This site has been seized by ShinyHunters"; the hack was originally reported on Tuesday of last week.
- ShinyHunters told 404 Media: "We hold data on all FBI employees and applicants." Gizmodo says the Times' view of the memo suggests this was not an exaggeration.
- The memo tells staff to watch for suspicious texts or calls from unknown numbers and, apparently, to set new voice mail greetings using AI voices; "virtual briefings" are still to come.
- The FBI's public statement on Monday says the investigation is ongoing and cites multiple bureau-wide communications within 24 hours of public reporting.
Why it matters
A federal law enforcement agency is telling its own workforce to treat their personal data as compromised. The story starts with a jobs portal, but the memo's premise reaches every FBI employee, not only applicants who used the site. The breach is also a public embarrassment for the bureau, which is how Gizmodo frames it. The only AI angle is small: the memo apparently advises employees to record voice mail greetings with AI voices.
Who it affects
First, FBI employees, who are told to assume their personally identifiable information was taken. Second, applicants: ShinyHunters claimed to hold data on "all FBI employees and applicants." The FBI's statement says it is in regular communication with anyone who may be impacted. No count of affected employees or applicants is given.
How to use it
This is a news item, not a tool, but the memo's advice is concrete. Employees are urged to be on the lookout for suspicious text messages or calls from unknown numbers, and apparently to create new voice mail greetings with AI voices. The Times says further "virtual briefings" are still to come, with no date given.
How solid is it
The core claim rests on a memo that Gizmodo did not see itself; it relays the New York Times' review, and the memo quote is hedged with "apparently." The FBI's own quoted public statement does not confirm that all employee data was stolen; the assumption comes from the memo as relayed by the Times. ShinyHunters' claim to 404 Media is the hackers' own word, though Gizmodo reads the Times' account as consistent with it.
Risks and caveats
The types of personal data stolen are not specified beyond "personally identifiable information," and no method or vulnerability used in the breach is described. The article gives no exact calendar dates, only "Tuesday of last week" and "Monday." It does not say who wrote the memo or when it was dated. The premise that data was taken is a working assumption, not a finding.
“We are operating under the premise that the threat actor is also exfiltrating [personally identifiable information] of all F.B.I. employees”
— FBI internal memo, as quoted by the New York Times and relayed by Gizmodo