FBI
We read the privacy notices published across central government, councils, tax and benefits offices, health bodies and policing. These are the patterns that repeat. A public body is not a company and you are not its customer: it holds your record because a law lets it, which changes what you can ask for and what you can expect back.
Reported incidents
Hackers claim agents' and job applicants' data taken through the jobs portal
2026-09-22Affected FBIJobs.gov (Oracle PeopleSoft recruitment server)
On 22 September 2026 the ShinyHunters group said it had breached the FBI and taken data on nearly all agents and on people who applied for FBI jobs. An FBI spokesperson said the bureau was "aware of claims regarding unauthorized activity affecting FBIJobs.gov" and was investigating. 404 Media checked names, home addresses and phone numbers of agents and spouses against public records. Later reports said the FBI told staff of a "cyber security incident" on the application portal. The group said the way in was an Oracle PeopleSoft server used for recruitment. The FBI has not published a count.
People affected typically ask FBI to confirm whether their information was included, and which categories.
The verified route
DÆTRAX is a personal data accountability ledger: a dated record of which companies hold your personal data, what you asked them to do about it, and what they claimed in reply.