Your Employer’s HR System Was Breached. Here’s What Happens Next.
Bottom line up front
If your employer, a former employer, or a company you once applied to says its HR or hiring system was breached, assume the stolen file holds things you cannot reset: your Social Security number, your date of birth, your home address, and the names of people in your household. Freeze your credit, get an identity protection PIN from the IRS, lock your Social Security number in E-Verify, and treat anyone who contacts you about the breach as unverified until you have reached them on a number you already had. That takes an evening, costs nothing, and covers the gaps that the free credit monitoring in a breach letter leaves open.
On Wednesday the FBI put out a statement about its own recruiting website that is worth reading slowly. A criminal group had claimed it broke into FBIJobs.gov and took data on agents and on people who had applied to work there. The bureau did not confirm that, and it did not deny it either. What it said was that it could not yet tell whether the breach had happened in its own systems or at one of the outside companies that support the site.
So two days in, the FBI did not yet know whose system had failed. If you have ever opened a breach letter from an employer, you have been in a version of that position yourself, usually with a lot less information and a lot more waiting.
The FBI is the headline this week, but the useful story is the ordinary one underneath it. Jobs portals, payroll processors, applicant tracking systems and benefits sites hold more about you than almost anything else in your life. They are often run by a vendor whose name is not on the letter, and if you applied somewhere years ago and never got the job, the company may not even have a current address to send you one.
Seven things to do this week
Roughly in order of how much ground each one covers. None of them costs anything.
- Freeze your credit at Equifax, Experian and TransUnion. All three, because a freeze at one bureau does nothing at the other two. While it is on, nobody can open new credit in your name, you included, so you lift it for a day when you need a loan or an apartment. It is free, it does not touch your credit score, and the FTC’s guidance says it matters most when your Social Security number has been exposed in a data breach.
- Get an identity protection PIN from the IRS. It is a six-digit number known only to you and the IRS, and an e-filed return under your Social Security number that is missing it gets rejected. Anyone with an SSN who can verify their identity can opt in through an IRS online account, and parents can request one for dependents. An HR file holds most of what a fraudulent tax return needs, which is why this sits so high on the list.
- Lock your Social Security number in E-Verify. Most people have never heard of this one. With a free myE-Verify account you can turn on Self Lock, and any E-Verify employer that tries to confirm a new hire using your number gets a mismatch instead. You lift the lock yourself when you start a job. It fits this situation unusually well, since the file that leaked is exactly the kind an employer uses to hire someone.
- If your children are on your workplace health plan, freeze their credit too. Enrolling dependents usually means handing HR their names and birth dates, and often their Social Security numbers. For a child under 16, a parent can request a free freeze that stays in place until you remove it. The process is different from an adult freeze and each bureau publishes its own instructions.
- Decide now how you will check anyone who mentions the breach. Find your HR department’s phone number on a pay stub, an old offer letter or the company intranet, and write it down where you will find it again. That is the number you call back on. Not one from an email that arrives this month, however official it looks.
- Know what an unemployment claim in your name looks like. The Labor Department says the first sign is usually paperwork: a state agency letter about a claim you never filed, a 1099-G tax form for benefits you never received, or your own employer asking about a claim. Report it to the state where the claim was filed, even if you have never lived or worked there.
- Tell the other people in the file. HR systems hold spouses as beneficiaries, children as dependents, and whoever you listed as an emergency contact. In the sample of the FBI data that one outlet reviewed this week, spouses’ details sat right alongside the agents’. None of those people chose to be in the file, and they may never get a letter of their own.
Definition
An HR system breach is unauthorized access to the software an employer uses to recruit, hire, pay and insure people: applicant tracking, onboarding, payroll and benefits enrollment. Because those systems hold Social Security numbers, birth dates, home addresses, bank details and family members’ information, the exposure outlasts any password reset.
What happened at the FBI, and what nobody knows yet
The group says it got in on Monday 21 September. On Tuesday the FBI’s recruiting site was defaced, The Record reported, and the careers page went up with a “System Unavailable” banner covering both apply.fbijobs.gov and the Special Agent Applicant Portal, according to CBS News. The same day, a group calling itself ShinyHunters posted a long message on its leak site, addressed to the bureau’s leadership. “We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,” it read.
The FBI’s first response was a single sentence to reporters. On Wednesday it published a longer one:
“The FBI is aware of a cybercriminal enterprise group claiming a compromise of the fbijobs.gov portal and alleged impact to FBI employee personally identifiable information (PII). While the point of breach is still undetermined — whether a third-party or the FBI’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support fbijobs.gov to mitigate any and all risk.”
Sort what is known by who is saying it, because some of the numbers going around belong to the group and to nobody else. What the FBI has confirmed is narrow: an investigation into a claimed compromise of the jobs portal with alleged impact to employee data, an undetermined point of breach, and work with the site’s third-party providers.
What reporters have checked is a little wider. 404 Media, which broke the story, says it saw a sample covering about 5,000 alleged agents, with names, addresses, phone numbers and details about spouses, and TechCrunch reports that the publication verified a portion of it against public records. According to CBS, Reuters and 404 Media each found records matching real FBI or Justice Department staff, though neither could establish that the records came from FBI systems. Reuters, which also received the sample, reported that it included dates of birth, Social Security numbers and emergency contact details, and that it had individually verified details for more than 22 people, according to ASIS’s Security Management. CBS also reports that FBI documents confirm the bureau’s recruiting side uses Oracle PeopleSoft, a common human-resources platform, and Amazon’s government cloud.
Everything else is the group talking. The data on nearly all agents and a large share of applicants, the two to three terabytes, the route in through a PeopleSoft flaw: none of it is confirmed, and Cybersecurity Dive notes it is not even clear whether that flaw was new or one Oracle disclosed in June. How many applicants are in the file, and how far back it goes, nobody outside the investigation knows.
The motive is the strangest part. ShinyHunters says it is not after money; it wants the FBI to “correct or remove” statements in a public service announcement from May about how the group pressures victims, including “threatening text messages and phone calls to victims and their family members, and in some cases, swatting.” It gave the bureau a week, and it has threatened to leak data on every agent and every applicant if the notice stays up. As of Friday nothing had been published, Deseret News reported, though several experts told The Record they expect a leak, because they do not expect the FBI to withdraw its warning. Our post on the Canvas attack that prompted that advisory has the background on the group.
The advisory is worth reading for a reason the group would not enjoy. It closes with a short list for anyone contacted by someone claiming to hold their personal data: verify requests through another channel, don’t pay, be wary of anyone claiming to be the organization or law enforcement, don’t click. It works for any HR breach, this one included.
Why the jobs portal was the soft target
A hiring system has an awkward job. It faces the open internet, because applicants arrive from anywhere and have no account yet, and it spends all day accepting documents from strangers. It also keeps records on people who never became employees, since hiring leaves a paper trail whether or not anyone is hired. My read is that this combination, public-facing and long-lived, is what makes hiring systems such good targets.
The other problem is ownership. Most employers rent their HR systems. Applicant tracking comes from one vendor and payroll from another, with benefits enrollment often run through a broker’s platform and the whole arrangement stitched together with single sign-on and file transfers. When a breach letter arrives from your employer, the system that actually failed may belong to a company you have never heard of, and your employer may be waiting on that company before it can tell you much.
ShinyHunters has worked this particular seam before. Google’s threat intelligence team documented the group exploiting a different PeopleSoft flaw against the education sector between 25 May and 9 June this year, according to CBS.
What an HR file holds, and who else is in it
“Personal information” undersells it. Follow a single person through a single employer and the file fills up quickly, and it fills up with other people too.
Categories drawn from typical hiring, payroll and benefits records. Retention rule: IRS, Employment tax recordkeeping. Red marks what cannot be changed after a breach.
Two rows in that picture tend to surprise people. The first is the applicants: if you applied and were never hired, you can still be in the system, sometimes with a date of birth and Social Security number if the role involved a background check. The FBI case is explicitly about applicants as well as agents.
The second is the family row. Nobody in your household applied for anything, but a spouse named as a beneficiary, or a child enrolled on your health plan, sits in the same system with the same exposure and possibly no letter of their own.
The last row is the one employers talk about least. Records do not leave when you do. The IRS tells employers to keep employment tax records, which include employees’ names, addresses and Social Security numbers, for at least four years after filing the fourth quarter for the year. Plenty of companies keep far more than the minimum for far longer, so a breach at a job you left in 2019 can still include you.
The part of this you cannot reset
A leaked password costs you an afternoon, and a leaked card number costs you a week and a new card in the mail. An HR file is a different kind of problem, because almost nothing in it can be changed. Your Social Security number stays, and so do your date of birth, the addresses you have lived at, and the names of the people you live with.
Cynthia Kaiser, a former senior official in the FBI’s cyber division who is now a senior vice president at the security firm Halcyon, made the point with an example from the bureau’s own history. Speaking to Cybersecurity Dive, she pointed to a 2016 breach that led to the theft of personal information on tens of thousands of FBI employees. “You still occasionally see that list circulated on the dark web today,” she said.
She was also blunt about what worried her most in the current case: “the short term potential for physical harm if criminals use this information to target the people who put them behind bars.” Most readers are not in that position. But a home address changes the feel of every scam that follows, because it lets a stranger sound like someone who already knows you.
Your employee ID, your start date and the last four digits of your Social Security number used to be how a lot of HR and benefits lines confirmed it was you. After a breach like this they prove nothing about the person reciting them. Hold on to the FTC’s rule instead: your employer, your bank and the IRS do need your Social Security number, but they won’t call, email or text you to ask for it. If they do, it is a scammer.
If your work makes you someone people might want to find — law enforcement, the courts, or anyone who has left a dangerous relationship — raise it with your employer’s security team this week instead of waiting for the letter. The fixes for an exposed home address are slower and more personal than a credit freeze, and they are worth starting early.
What tends to follow, and the move that beats each
None of these is new. What changes after an HR breach is how informed they sound.
The recruiter who knows your application
Applicant data is raw material for fake job offers. A message that names the job you actually applied for reads very differently from the usual “remote data entry, great pay” spam. The FTC’s description of the pattern fits closely: an official-looking offer before you have even interviewed, paperwork that wants your driver’s license, Social Security or bank account number, and a recruiter who pushes for those details before answering any questions about the job. Real employers, the FTC says, won’t ask for that kind of information before they have interviewed and hired you.
The move: go back through the careers page where you originally applied, or call the company’s main number, and ask whether the offer exists. We have a longer walk-through on verifying a recruiter if you want the full routine.
HR, payroll or benefits on the line
This is the one that costs money fastest. A call or email from “HR” or “benefits” asks you to confirm some details or update your direct deposit, often through a link to a sign-in page. For a lot of employers this is also open enrollment season, which gives a benefits message a reason to exist. The FBI’s May advisory warned that data stolen from education platforms could be reused to impersonate IT support or financial aid offices; HR and payroll are the workplace version. We wrote up the payroll half of this, from the employer’s side, in our piece on payroll diversion.
The move: never change bank details from a message or during a call someone else started. Log in to the payroll or benefits portal the way you normally do, or ring HR on the number you wrote down in step five.
The tax return filed before yours
Your name, Social Security number, address and employer add up to most of a tax return. The IRS identity protection PIN from step two is the lock here, and it covers a gap the paid services leave open: the FTC says credit monitoring won’t alert you when someone uses your Social Security number to file a return and collect your refund. If you have already handed your number to someone you now doubt, our guide for an SSN given to a scammer walks through the rest.
A job, or an unemployment claim, in your name
The FTC lists getting a job among the things a thief can do with your details, and E-Verify warns that when someone works under your number, their wages can be reported in your name to the IRS and the Social Security Administration. The fraud rings behind fake remote hires lean on stolen identities to get through hiring checks; we covered that from the employer’s side in our post on deepfake job candidates. Self Lock blocks the version that runs through an E-Verify employer. For unemployment, the tell is paperwork you never asked for; the Labor Department says to report it to the state that sent it and to file your taxes with only the income you actually received.
The follow-up that sounds official
Expect breach-themed messages: a “notification” with a link to check your exposure, a caller who says they are with the investigation, a text offering free monitoring with a sign-up link. After a breach that involves the FBI, expect some of them to claim to be the FBI, a trick the bureau itself warned about in July when it described criminals impersonating its complaint center. Nobody legitimate charges a fee to remove you from a leak or to hold your place in a settlement. If a message about the breach lands in your inbox, paste it into our free email scam checker before you touch anything in it.
What the free monitoring covers, and what it doesn’t
Breach letters often come with a year or two of free credit or identity monitoring. Take it, since it costs nothing, but be clear about what it is: something that tells you about damage afterwards. The FTC is unusually direct about where it goes blind. If you enroll, use the code from the official letter, on the provider’s site typed in by hand.
By the FTC’s own list, credit monitoring won’t alert you when someone withdraws money from your bank account or files a tax return with your Social Security number. Most identity monitoring won’t alert you when your details are used to claim unemployment, Social Security, Medicare or Medicaid benefits. Identity theft insurance generally won’t reimburse money a scammer actually took. The free locks at the top of this page close several of those gaps before anything happens.
Monitoring gaps: FTC, “What To Know About Identity Theft.” Locks: FTC (credit freeze), IRS (IP PIN), E-Verify (Self Lock), Department of Labor (unemployment claims). Amber marks the attacker’s move, red a silent gap, blue your move.
The other limit is time. The 2015 breaches at the Office of Personnel Management exposed data on some 22.1 million current, former and prospective federal employees, contractors and others, including background-investigation records on about 21.5 million people. Congress required at least ten years of free identity protection for them, and that coverage is scheduled to end on 30 September 2026. A bill introduced in August would make it lifelong. As far as we could find, it had not passed when this was written.
Senator Mark Warner put the underlying problem plainly when he introduced that bill: “once that information is in the hands of a bad actor, you don’t get it back.” His announcement also noted that much of the OPM data has never publicly resurfaced, which is its own kind of warning.
In the meantime there is a free version of monitoring that never expires: your own credit reports. You can pull one every week from each of the three bureaus at AnnualCreditReport.com, and accounts you don’t recognize are the first thing to look for.
If you only ever applied
This is the group most likely to be missed. If you applied for a job, even years ago, you may still be in the company’s applicant system, and the company may have nothing better than an old email address to reach you with. You might never get a letter.
You can look anyway. Watch the company’s own newsroom or security page, reached by typing its address rather than following a link someone sends you. If you live in California, the attorney general posts a sample of every breach notice sent to more than 500 Californians, in a list you can search by company name; check whether your own state’s attorney general does something similar. If the data is ever dumped publicly, services such as Have I Been Pwned may add it; go to one you already trust, because fake “breach checkers” asking for your date of birth or Social Security number turn up after almost every big leak. Our Exact Sciences guide explains how the legitimate lookups work.
For the FBI case specifically, the bureau has not said whether or how it will notify applicants. Treat anyone who contacts you first, claiming to be handling it, as unverified.
Talking about it at home
The person in your house most likely to take the fake recruiter’s call is not always you. A teenager applying for a first job this autumn may already have given a Social Security number to an employer, and fake job offers are one of the scams that reach young people most directly. We keep a short page on the four scams most likely to land in a teenager’s messages, with a sheet you can print, and the fake job is on it.
For everyone else, one household rule does most of the work. Anything about pay, benefits, taxes or a job gets checked through a number we already had, and nobody reads out a Social Security number to someone who called them. It only works if everyone in the house has actually heard it, so say it out loud at dinner rather than forwarding this article and hoping.
What to do now
If you have had a letter, or you know you are in a breached HR or applicant system, work through the seven steps at the top this week, starting with the credit freeze and the IRS PIN. If you are not sure whether you are affected, those two are still worth an evening. They are insurance against the next breach as much as this one.
If something has already gone wrong — an account you did not open, a tax return rejected because one was already filed, an unemployment letter — report it at IdentityTheft.gov, which builds a recovery plan for you, and use our first-hour checklist for the order to do things in. If someone contacts you claiming to hold your data and demanding anything, the FBI’s advice is not to pay, and to report it at IC3.gov.
And if the HR system in question is yours, because you run the business, the other side of this is covered in our incident response guide for small businesses.
The first fake job offer your family sees should be ours
ScamDrill sends your household realistic practice scams by email, fake job offers among them, and turns every click into a short lesson on the spot. Nobody is graded and nobody gets told off.
See how it works