The FBI has told its agents and support staff that their personal information was taken in a cyberattack on the bureau's job application portal, according to an internal notification. The notification declared a cyber security incident and said employees' names, addresses, job titles and Social Security numbers were exposed. It is the bureau's first acknowledgement that personal data belonging to FBI agents was stolen in the breach.

The FBI had not publicly confirmed a breach beyond a statement last week, in which it said it was aware a hacking group had claimed a cyberattack but that the theft of data was still undetermined. MS NOW reporter Ken Dilanian reported the internal notification over the weekend. Several media outlets have since confirmed that some of the stolen data included medical information, such as records relating to blood and urine samples, as well as psychiatric reports.

The hacking group called ShinyHunters previously told TechCrunch it holds data on mostly all of the FBI, along with a substantial amount of information on applicants who applied through the FBIJobs.gov portal. The hackers broke in by exploiting a vulnerability in an Oracle PeopleSoft server, which hosts large amounts of human resources information on agents and now-employees who applied through the portal. The hackers said they are not seeking a financial ransom but are demanding the correction of an earlier FBI-issued report that they say misrepresents their activities.

Justin Sherman, a national security expert, described the data breach as a counterintelligence disaster for the U.S. government in a blog post for Lawfare. He warned that the theft would expose thousands of FBI personnel to profiling, phishing, foreign intelligence approaches and more.

It is less clear whether the FBI has disclosed the incident to lawmakers in Congress who oversee the bureau. Under federal law, alerting Congress is required when an intrusion meets the bar of a major incident, such as a data breach involving the theft of personally identifiable information likely to result in demonstrable harm to U.S. national security. If a disclosure is required, it would be the FBI's second known notification to lawmakers this year about a data breach, after hackers suspected to be Chinese broke into a surveillance system that exposed targets of FBI surveillance and investigations earlier this year.

A spokesperson for the FBI did not respond to TechCrunch's request for comment on Monday, and a White House spokesperson also did not respond to an email asking whether the bureau had declared a major incident. Representatives for several lawmakers whose jurisdictions cover oversight of the FBI did not have immediate answers. ABC News reports that the FBI's job site has been the primary way to apply for a job with the bureau since 2017, and the portal remains down.

More cybersecurity news from TechManNews.