Nearly Every FBI Agent Just Got Doxxed. The Purge Started Long Before the Hack.
Inside the breach that handed 2 to 3 terabytes of agent data to extortionists, and the staffing decisions that made it easy.
The Jack Hopkins Now Newsletter #1,046: Monday, October 5th, 2026
I want to tell you about the greatest counterintelligence giveaway in American history. And no, you don’t need a coupon.
Sometime in September, a gang of extortionists who call themselves ShinyHunters walked through the FBI’s own job application website and strolled out with the names, home addresses, cell phone numbers, email addresses and employee ID numbers of nearly every single person who works at the Federal Bureau of Investigation.
Plus the Social Security numbers of their emergency contacts. Plus…records on more than 8,000 state and local cops who sat on FBI task forces.
Read that again. The agency that catches hackers for a living got cleaned out by a crew whose previous greatest hit was holding Canvas, the homework website, for ransom.
Six current and former FBI officials described the scope to MS NOW. Officials and outside experts are now calling it one of the worst counterintelligence disasters in modern history. One of the bureau’s own cybersecurity agents used a shorter word: incompetence.
Now here’s the part nobody in Washington wants to say out loud, so I’ll say it for them.
This didn’t happen to the FBI. It happened after somebody spent eighteen months firing, forcing out and reassigning the people whose job was to stop it. Pull up a chair. This is a story about how to build the perfect victim, one pink slip at a time.
First, the burglary. It was embarrassingly easy.
The front door was FBIJobs.gov, the portal where bright-eyed applicants upload their dreams of a badge.
Behind it sat Oracle PeopleSoft, a human-resources program, reportedly running on Amazon’s GovCloud.
PeopleSoft had a hole in it. Not a secret hole, mind you. Google’s threat intelligence team warned the whole world about it back in June. The FBI…to its credit…patched it. To its discredit…it missed one avenue. ShinyHunters found the avenue.
That’s it. That’s the heist. No Ocean’s Eleven. No laser grid.
A known bug…a half-finished patch…and a pile of personnel data that…according to that same FBI cyber agent…never should have been sitting on an internet-facing system in the first place.
The bureau later obtained chat logs of the hackers marveling at how easy it was. I’d like you to picture that scene. Career criminals, sitting there, sincerely astonished that the FBI left the keys in the ignition.
ShinyHunters claims it hauled off two to three terabytes. It handed reporters a sample of 5,000 records as proof…and…a former agent confirmed the sample was real.
The group says it won’t publish the rest. How reassuring. A ransom gang’s pinky promise is now the load-bearing wall of American counterintelligence.
And why did they do it? Not for money, they say. For spite.
In May the FBI put out a public alert about ShinyHunters…telling victims not to pay. The gang took it personally…and spent four months planning a revenge job on the one agency that should have been expecting it.
The FBI’s official position is that this was “a failure of a platform managed by a third-party vendor.” Which…is technically true…in the way that “the ship had a steering problem” is technically true of the Titanic.
Now, the setup. Eighteen months of clearing the room.
Let me take you back to Inauguration Day 2025…
…when the White House and its hand-picked FBI director, Kash Patel, began what Senator Mark Warner later described on the Senate floor as a political purge that, by his count, forced out thousands of experienced agents and senior leaders.
Who got the boot? Let’s check the guest list.
The head of the Counterterrorism Division. The head of the Intelligence Division. The head of the Critical Incident Response Group. And, I’d like you to underline this one, Michael Nordwall, the executive assistant director whose branch oversaw the Cyber Division…the man at the top of the bureau’s fight against ransomware and sophisticated intrusions.
You know. Intrusions. Like the one that just happened.
The purge didn’t stop at headquarters. Patel fired agents tied to the Mar-a-Lago documents search in waves through the winter of 2026…roughly a dozen at a time…more than once in the same week an unflattering story about Patel’s jet or his girlfriend’s security detail hit the papers.
The bureau’s internal misconduct office recommended suspensions for some of them. Patel overrode it…and fired them anyway.
In late February he dismissed a dozen agents and staff from CI-12, a counterintelligence unit watching Iran, days before U.S. strikes on Iran.
The FBI Agents Association…which represents more than 90 percent of active agents…said the director had “disregarded the law and launched a campaign of erratic and arbitrary retribution.” Fired agents sued. The co-deputy director quit in September after barely a year.
And…for the agents who weren’t fired? According to Warner, the bureau reassigned 25 to 45 percent of those working cyber, counterterrorism, espionage and child-exploitation cases to immigration enforcement.
So let’s tally the scoreboard.
The executive over the cyber division is gone. A quarter to nearly half of the cyber bench is chasing visa overstays.
The survivors have watched colleagues get fired…for the crime of having once opened a file with the wrong name on it. Morale…per a New York Times report quoting dozens of current and former employees…is somewhere below the basement.
Meanwhile, over at CISA, the agency Congress built specifically to defend government systems…more than a third of the staff has been pushed out too.
If you were designing an agency to lose a database…friend…you could not have drawn it up better.
How the two stories are really one story
Here is the thing about patching a known vulnerability.
It is not glamorous. Nobody gets a medal. It is the kind of work that gets done by a mid-level person…who has been there eleven years…knows which three systems nobody remembers exist…and is not currently updating her résumé.
The FBI patched PeopleSoft and missed one avenue. Ask yourself who, in a normal year…would have caught that avenue.
The executive over cyber, maybe. Fired. The senior people across the bureau who’d have asked why applicant data was sitting on a public-facing box.
Forced out in Washington, Miami, New Orleans, Las Vegas, Seattle. The rank-and-file cyber agents…who’d have been running the follow-up scans. A quarter to half of them reassigned to immigration raids.
And…the ones still at their desks? Picture the incentive. You have just watched a dozen colleagues get fired for work they did four years ago under a different director. You have watched the misconduct office say “suspension” and the director say “gone.”
Are you, this week, going to walk into the front office and say, “Sir, I think our vendor’s patch is incomplete and we moved sensitive data where it shouldn’t be”? Or are you going to keep your head down and hope the vendor handles it?
That’s not a cybersecurity failure. That’s a management failure…wearing a cybersecurity costume.
Now layer on the timing. ShinyHunters says it started planning in May, right after the FBI’s alert.
Google published the PeopleSoft warning in June. Between June and September the bureau’s biggest priorities, judging by the headlines, were defending the director’s travel habits…fending off lawsuits from the people he’d fired…and finding new people to fire.
Somewhere in there…one avenue went unpatched for roughly three months.
Senator Warner stood on the Senate floor in November 2025 and said the purges had sharply reduced the bureau’s ability to respond to cyber intrusions.
He practically read the ShinyHunters playbook into the Congressional Record ten months early. Nobody listened…which…in fairness…is what the Senate floor is for.
So…when the FBI says this was a third-party vendor problem…here is my question. Who was supposed to be watching the third-party vendor? And where are they now?
The pitch, and the fine print
So here’s my offer, and I’ll keep it simple.
For the low, low price of one politicized purge…you too can receive: the home address of every FBI employee in America…delivered free of charge to a group whose entire business model is selling stolen data.
Act now…and we’ll throw in 8,000 local police officers at no extra cost. Experts are already comparing it to the 2015 OPM breach…when Chinese intelligence took the files of nearly every federal worker…and they expect Beijing and Moscow to be hunting for a copy of this one as we speak.
The FBI’s response? Briefings.
Staff will receive sessions on “public disclosures and mitigation strategies.” A PowerPoint. For the people whose home addresses are now in a terabyte folder on a server they’ll never see. Wonderful.
Now, in fairness, because I’m a fair man, here’s what the other side would say.
They’d say the hole was in Oracle’s software, not the FBI’s. True.
They’d say the bureau did patch it and simply missed a path, which happens to Fortune 500 companies every week. Also true.
They’d say nobody has produced a document showing a fired agent would have caught the gap…and that pinning a zero-day exploit on personnel decisions is correlation dressed up as causation.
And…the bureau would say the hackers never touched investigative or classified systems, which is correct…and…also…when the stolen data is where the agents sleep at night, not much comfort.
Fine. Grant every word of it. Then…explain why an agency that pushed out the executive over its cyber division…shed, by a senator’s count, thousands of veterans…and diverted up to half of its remaining cyber agents to immigration work…should be surprised…when the one thing it was built to prevent walked in through the help-wanted page.
You can’t fire your way to competence. Turns out you can fire your way…to this.
After the Breach: 10 Questions the FBI Would Rather You Didn’t Ask
Who exactly is exposed?
Nearly every FBI employee, per six current and former officials: names, home addresses, cell numbers, bureau email addresses and employee ID numbers.
Emergency contacts lost Social Security numbers and personal emails. Add more than 8,000 state and local officers who served on FBI task forces, and an unknown number of job applicants whose files sat in the same recruiting system.
What’s the single most dangerous piece of that data?
Home addresses tied to confirmed FBI employment. Everything else is annoying; that one is physical.
An agent working cartels, domestic extremists or foreign intelligence targets now has a current address in a file that ShinyHunters says it won’t publish but that adversaries are presumably trying to obtain.
Can the data reveal what agents actually work on?
ShinyHunters claims the records include details that could link some personnel to sensitive assignments, and early reporting pointed the same way. The FBI hasn’t confirmed it.
Even without a job title, an email address plus a field office plus task force membership is enough for a foreign service to infer who covers counterintelligence in Houston or cyber in San Francisco.
Why do experts keep invoking the 2015 OPM breach?
Because this is the same category of damage: a complete roster that a hostile intelligence service can use to identify, track, pressure and recruit. China got OPM’s files on nearly every federal worker and used them for years. The FBI set is smaller but far higher value per record.
What does the recruitment risk look like in practice?
Blackmail and inducement work best with a target list. Adversaries can cross-reference this roster against financial records, divorce filings, social media and prior breaches to find the agents with debts, grievances or secrets.
The CSIS researchers quoted in the coverage called it a longer-term national security threat for exactly this reason.
Are undercover or sensitive-assignment personnel at risk?
Potentially. Anyone whose cover depends on their FBI employment not being public now has that fact sitting in a stolen database. The FBI hasn’t said how many such people are in the set…and that silence is itself informative.
What about the 8,000 task force officers?
They’re arguably more exposed than agents. Local officers typically lack federal protective resources, and their task force membership, especially on violent gang or drug task forces, is often not known in their communities. Their home addresses now are.
How does this enable phishing and impersonation?
Attackers now have verified FBI email formats, real names, real employee IDs and real phone numbers.
That lets them impersonate agents to the public, impersonate the bureau to its own staff, and craft spear-phishing that passes every “does this look legit” test. Applicants are a soft target too: a text saying “re-enter your info due to the portal incident” will land.
Is the FBI’s investigative or classified network compromised?
Officials say no. The hackers entered through FBIJobs.gov and PeopleSoft…not case systems.
But the “one avenue” that was missed in the June patch raises the obvious question of what else is running on internet-facing vendor platforms with incomplete fixes. The March 2026 incident on a surveillance-related system suggests this isn’t a one-off.
What’s the long-tail risk nobody is talking about?
Trust inside the bureau. Employees now know their employer moved their personal data to a public-facing system, half-patched it, and is responding with briefings.
Combine that…with eighteen months of purges and reassignments…and you get an agency where experienced people leave…the ones who stay don’t speak up…and the next gap goes unreported. That’s the vulnerability that outlasts the data.
The 11th Question: Who Benefits From Scared Agents?
Every answer above assumes the danger comes from outside.
China, Russia, cartels, ransomware crews. But a stolen roster…does something else that nobody at the podium will say out loud: it changes how the people on the roster behave.
Consider what an FBI agent now knows about their own position.
In early 2025, acting Deputy Attorney General Emil Bove demanded the names of thousands of agents who worked January 6 cases.
Leadership keeps lists. Since then, Director Patel has fired agents for case work done years earlier under a different director…overriding his own misconduct office when it recommended suspensions instead.
Leadership acts on lists. And…as of September…every one of those agents’ home addresses…cell numbers and emergency contacts…sits in a criminal database…with the bureau’s response amounting to a mitigation briefing. Leadership can’t protect them.
Now…put yourself in the chair of an agent weighing whether to pursue a case that touches the president’s allies…cooperate with an inspector general…or answer a congressional subpoena honestly.
Nobody has to threaten that agent. The ledger already reads: I am exposed, my employer compiles names, my employer fires from those names, and my family’s address is loose in the world.
The rational move is to keep your head down. Multiply that across roughly 38,000 employees…and you have an agency that has lost its independence without a single order being given.
This is why counterintelligence professionals treat doxxing as a force multiplier rather than a privacy problem. The data doesn’t have to be used. It only has to be known to exist.
Critics have gone a step further and asked whether anyone inside the Justice Department, which since April has had acting Attorney General Todd Blanche, Trump’s former criminal defense lawyer…at its head…could use the breach as leverage:
A quiet reminder to an inconvenient agent that information “might be in the wrong hands.”
Let’s be precise about that. There is no reporting that anyone has done this…and doing it would be a federal crime: extortion, obstruction, and likely a civil rights violation.
It would also be unnecessary. Leadership already holds every employee’s personnel file legally. The hack adds nothing an insider couldn’t already see. The only thing it adds is deniability…and a bad actor doesn’t need to make the threat…when the fear arrives on its own.
So…the honest question isn’t whether leadership is exploiting the breach. It’s whether leadership built the conditions in which agents reasonably believe it could.
That one is answerable from the public record: the name lists, the serial purges, the half-patched vendor system, the briefings instead of protection.
If an agent hesitates on a politically sensitive case this fall…and cites fear for their family…no one will be able to call that paranoia. It will be pattern recognition.
That is the vulnerability that does not show up in any forensic report. The hackers took the data. The institution…had already taken the nerve.
#HoldFast
Back soon.
-Jack
Jack Hopkins
Remember, Jack’s got your back.
P.S. ShinyHunters deleted its message to the FBI from its leak site. The FBI…pushed out the man over its cyber division. Only one of those can be restored from backup.
Sources
The breach
MS NOW: ‘Incompetence’: Massive FBI hack hit most employees and extends to local officials
PBS NewsHour: FBI investigates hackers’ claim to have stolen employee data
CNBC: ShinyHunters hackers say they breached FBI, stole data on bureau employees
NBC News: FBI investigating hacking group’s claim of massive breach of agent info
Cybersecurity News: ShinyHunters allegedly claims breach of FBI jobs site
Fox News: FBI hack claim raises fears over sensitive personal data
WSB-TV: Hackers behind Georgia schools cyberattack now claim they breached FBI systems
TechCrunch: FBI investigating hack on its wiretap and surveillance systems (March 2026)
The purge
Bloomberg Law: Patel pushes out more FBI leaders and agents in renewed purge
Washington Post: Kash Patel purges more FBI agents tied to Mar-a-Lago investigation
MS NOW: FBI fires agents who scrutinized Patel in Trump documents case
MS NOW: Patel ousts senior FBI agents linked to Trump probes
MS NOW: When Kash Patel is under fire, FBI agents and staff get fired
CNN: Patel gutted FBI counterintelligence team tracking Iranian threats days before U.S. strikes
Washington Post: Mass firings leave national security ranks thinned as war raises threats
Forbes: Kash Patel’s FBI co-deputy director quits after barely a year




I think that in essence what you are saying that "organized incompetence" is actually a open invitation to "stochastic terrorism". (Not necessarily violent terrorism - in this case, a form of cyber-terrorism.) With some indecipherable and ever changing complex combination of malicious motivation to promote incompetence intertwined with true incompetence, that has no self-awareness, replicating itself.
If I'm correct my interpretation - I totally agree and IMO, this can be even more dangerous than an actual planned conspiracy to effect terrorism, since stochastic processes, by definition, are unpredictable - making prevention and creation of safe guards much more difficult to construct.
When and where the stochastic terrorism borne of "organized incompetence" will next strike is unpredictable and does NOT arise from an overall organized conspiracy that can be investigated and hopefully disbanded. In fact, there are likely doors open all over the place that are ripe for the picking, and no way to know who next will attack which door, for what reason.
I’ve been expecting an incident….. since the 2.0 inauguration. You cannot decimate security and then play dumb or blame others when catastrophe walks through the open door.
There are so many failures at so many levels that it’s hard to NOT say it’s a pattern, pay attention. On top of all that, Larry Ellison effectively controls Oracle. I’m NOT alleging a conspiracy and the whole f**k up is very damning. Accountability has to start at the top…. T, then Patel and on down.
This is horrific…. Not only does an agent worry now about not offending anyone, they must worry about the safety of their safety net (family). I hope a LOT of people see this and begin to understand the implications of ALL of it then vote accordingly.
Thank you, Jack for laying this out so clearly. Going to do my part to raise the alarm on this one….