INTELLIGENCEORIGINAL.COM — FRONTPAGE
Intelligenceoriginal.com · Cyber & Security · September 29, 2026
C y b e r & S e c u r i t y
The Breach of the Breachers
Within a single week, hackers penetrated the Pentagon’s personnel database, the FBI’s recruitment portal, and multiple Israeli security networks. The Pentagon lost the Social Security numbers of nearly three million people — and did not notice for nine months. The FBI lost the medical records of its own agents. Israel lost the private phone data of hundreds of operatives. The pattern is not coincidence. It is the collapse of the assumption that the agencies entrusted with secrecy can keep it.
By the Intelligence Original Editorial Desk · September 29, 2026 · 19 min read
On July 16, 2026, a vulnerability was patched on a server belonging to the Pentagon’s Defense Manpower Data Center. The patch was routine. The discovery of the vulnerability was not. For approximately nine months — from October 2025 to July 2026 — unauthorized users had access to the personal records of nearly three million people.[citation:12]
The breach affected 2.76 million living individuals and another 294,000 deceased people. The compromised files contained unencrypted personally identifiable information: names, Social Security numbers, dates of birth, contact details. For some, the records also included sex, race, and military occupational specialties.[citation:12]
The Defense Manpower Data Center is not a peripheral system. It is one of the Department of Defense’s central repositories for personnel and identity information, maintaining records on over 60 million people: active-duty service members, reservists, civilian employees, contractors, retirees, veterans, and family members.[citation:1][citation:12]
The Pentagon has said it found no evidence that the exposed information has been misused. It has offered affected individuals one year of free credit monitoring and identity-restoration services. Notifications began with breach letters dated September 18.[citation:12]
What the Pentagon has not explained is how unauthorized users maintained access for nine months without detection. It has not identified the individuals behind the intrusion. It has not disclosed their motive. It has not established how much information was viewed or collected.[citation:12]
I. The FBI: The Breach That Was a Message
ShinyHunters, the PeopleSoft Zero-Day, and the Medical Records of Special Agents
On the night of September 21, 2026, a hacking group called ShinyHunters claims it compromised FBI systems through a previously unknown vulnerability in Oracle PeopleSoft. The next day, the FBI’s recruitment portal — apply.fbijobs.gov — was defaced with the group’s signature “seized” banner before being taken down and later restored.[citation:11]
The group says it exfiltrated between 2 and 3 terabytes of data relating to current and former FBI employees and job applicants. It claims access to systems it identified as Human Resources, Criminal Justice, and Medlink — the latter containing the medical records of FBI agents.[citation:11]
BBC has seen samples of the stolen medical records, which include blood and urine test results, and doctors’ notes mentioning conditions such as “shellfish and banana allergies,” “blood in urine,” and “high cholesterol.” The files contain full names and addresses of agents.[citation:13]
Reuters was able to partially verify the authenticity of the sample data by running details, including Social Security numbers, against credit bureau records and previously breached data preserved by the dark-web intelligence firm District 4 Labs. In at least 10 instances — including in the case of FBI Director Kash Patel — the details appeared to match.[citation:15]
The FBI has confirmed it is investigating “unauthorized activity affecting FBIJobs.gov” but has not confirmed the broader breach claims, the alleged PeopleSoft zero-day, or the volume of data stolen. The agency said it is working with external vendors who support the recruitment portal “to mitigate any risk.”[citation:5][citation:15]
“This is NOT extortion, it is NOT about ransom and it is NOT about money. It was a marketing campaign aimed at protecting our interests and actively combating disinformation.”
— ShinyHunters statement, cited by ABC News
The group says the operation was retaliation, not extortion. It gave the FBI one week to retract or correct a May 2026 advisory that described ShinyHunters as a threat actor known to threaten family members of targets and to use “real or exaggerated claims of access to sensitive or personal information to cause victims to pay.”[citation:5] ShinyHunters denies those tactics and says the breach was a response to being mischaracterized.[citation:2][citation:11]
The group has since said it will not publish the full dataset. But it has also acknowledged it “cannot guarantee” what happens to the samples it already shared with journalists — data it says is now “out of our control.”[citation:2]
Cybersecurity researcher Ian Lin, head of R&D at Packetlabs, is not reassured. “You still can’t trust them to keep safe your data,” he told CBC News. “Because now this is leverage over the law enforcement and FBI. And at any moment they could choose to use this data for their own additional purposes.”[citation:2]
The FBI has advised employees to “remain vigilant and not respond to suspicious calls,” to avoid speaking with media, and to report any attempts at doorstepping by journalists to 911.[citation:1]
II. Israel: The Handala Campaign
700 Operatives, a Cyber Tool Called Na’em, and the Phone of Israel’s Former Military Chief
While Washington was processing the Pentagon and FBI breaches, a parallel campaign was unfolding against Israeli security infrastructure. A hacking group calling itself Handala claims to have used a cyber tool called Na’em to infiltrate the mobile phones of hundreds of individuals connected to Israeli security agencies, publishing images of approximately 700 people.[citation:3]
The group says its operations extend beyond cyberattacks and frame its activities as part of a broader “popular front” discourse. It has warned that “cyber security in Washington and Tel Aviv is not as reliable as advertised” and described its recent operations as only a small sample of its capabilities.[citation:3]
Handala has previously claimed to have hacked information on Israeli Brigade 89 forces and subsequently released images and information on those individuals as promised. The group says it operates without publicly announcing targets or activities in advance, publishing only portions of obtained data after operations are complete.[citation:3]
In a separate but related incident, the Israeli Hebrew channel Kan reported that Handala hackers had penetrated the mobile phone of Herzi Halevi, former Chief of Staff of the Israeli military, accessing a large volume of personal images and documents related to him and his family members — documents previously banned from publication for security reasons.[citation:19]
The scale of the cyber pressure on Israel is documented. The head of Israel’s internal cyber agency told the German newspaper Die Welt that in June 2025, during the 12-day war, authorities recorded approximately 1,600 cyber incidents. By June 2026, that figure had risen to 4,800 attacks per month — targeting critical infrastructure, central organizations, small and medium businesses, and the general public.[citation:3]
A separate Algerian hacking group calling itself Anonymous Algeria claims to have breached the websites of “several Israeli entities,” including the Ministry of War, extracting 10 gigabytes of data on officers, armies, and military plans. The group claims the data includes ID cards, phone numbers, addresses, parents’ names, health insurance details, scholarship information, and criminal records.[citation:9]
An actor operating under the name “autone” has released a dataset allegedly obtained from a publicly accessible API endpoint operated by Israel’s Ministry of Defense. The dataset reportedly contains more than 37,000 records with Israeli national identification numbers and full names. The actor says the endpoint did not require authentication when the information was collected — suggesting an exposed-data incident rather than a breach of internal systems.[citation:16]
III. The Mossad Question
What Was Breached, What Was Not, and Why the Distinction Matters
Claims of a Mossad database breach have circulated widely on social media. They require careful handling.
According to the Greek fact-checking organization Greece Fact Check, the alleged hacking does not concern Mossad databases. As the group that claimed the operation itself states, what was breached were the personal emails of individuals working at the INSS (Institute for National Security Studies) — some of whom had previously worked at Mossad. There is no evidence at this time of a direct breach of Mossad’s internal databases.[citation:4]
A separate incident does involve Mossad directly, but in a different capacity. The French magazine Challenges reported that Mossad hacked the phone of Dora Cattuti, the North Africa and Middle East advisor in the diplomatic office of the French Presidency. The breach was discovered during a security check. Cattuti had reportedly responded to a phishing email she believed came from the Palestinian Authority.[citation:10]
The French Presidency’s diplomatic office said it “does not confirm this information, which contains errors.” The French Foreign Ministry has not commented.[citation:10]
In a separate development, a leak of a secret visit by Israeli Prime Minister Benjamin Netanyahu to the UAE triggered a serious security assessment from Mossad. The agency concluded that the leak posed a serious security threat to the prime minister and his delegation and requested that publication of the news be classified as a serious incident endangering Israeli state security.[citation:7]
IV. South Africa: The Mossad, CIA, and MI6 Leak
A Third Continent, a Different Vector
The pattern extends beyond Washington and Tel Aviv. In South Africa, State Security Minister David Mahlobo announced a full investigation into the leaking of classified security documents by broadcaster Al Jazeera. The leaked intelligence reports belonged to international intelligence organizations including Israel’s Mossad, the CIA, and Britain’s MI6.[citation:20]
Mahlobo said the disclosure of such information was illegal under the country’s classification protocols and undermined national security. He noted with concern media reports about the contents of classified intelligence reports and said the leaking of documents detailing operational details of the State Security Agency (SSA) was “condemned in the strongest possible terms.” The government would also look into social media reports alleging espionage linked to some politicians.[citation:20]
V. The Pattern
What the Convergence of These Breaches Reveals About Institutional Security
The breaches do not share a common actor. ShinyHunters is a financially motivated cybercrime group that has pivoted to reputational warfare. Handala appears to be an ideologically driven actor aligned with Iranian interests. Anonymous Algeria operates on a separate track. The South African leak appears to be a media-driven disclosure rather than an external hack.[citation:2][citation:3][citation:9]
But they share a common structural vulnerability: the assumption that large institutions with security mandates can protect the data they collect.
The Pentagon’s nine-month exposure window is not a failure of encryption. It is a failure of monitoring. A system that stores records on 60 million people was accessed by unauthorized users for three-quarters of a year before detection.[citation:12]
The FBI’s breach is not a failure of perimeter defense. It is a failure of vendor risk management. The compromised system was a third-party recruitment portal. The medical records of agents were stored in a system the FBI did not fully control.[citation:11][citation:15]
Israel’s breaches are not a failure of technical capability. They are a failure of scale. A small nation with world-class cyber defenses cannot protect every endpoint, every phone, every API in a conflict zone where adversaries are actively probing for weaknesses.[citation:3][citation:16]
“The FBI and law enforcement should all still remain vigilant. There should be massive lessons learned from the FBI side.”
— Ian Lin, Packetlabs, to CBC News
The breach of the breachers is not a metaphor. It is the operating reality of a period in which the volume of sensitive data held by security institutions has grown exponentially, while the attack surface has expanded faster than any institution’s capacity to monitor it.
Sources: ABC News via PAP (September 29, 2026); CBC News (September 29, 2026); BBC via MIA (September 26, 2026); Reuters via Security Affairs (September 23, 2026); Times Now (September 29, 2026); BelTA/TAСС (September 29, 2026); Greece Fact Check (September 14, 2026); L’Espresso (September 14, 2026); Republika (September 29, 2026); AKŞAM (September 18, 2026); Mizan Online (September 18, 2026); SOCRadar (September 24, 2026); Dark Web Informer via X (September 26, 2026); Sanj Samachar (September 19, 2026); Legalbrief (September 18, 2026); Daily Naya Diganta (September 17, 2026); AlAhed News (September 1, 2026); Anonymous Algeria Telegram via AlAhed News.
Related Intelligence
- The Algorithm That Decides Who Is a Terrorist — AI targeting in modern warfare (September 23, 2026)
- The Mines Beneath the Strait — German MCM and the Hormuz question (September 28, 2026)
- The Fixer — Hakluyt, Black Cube, and the private intelligence industry (September 26, 2026)
BERND PULCH — NO MORE FAIRY TALES
For over 30 years, Bernd Pulch has been digging where others refuse to look. He publishes uncensored primary-source intelligence, original scanned documents, forensic analysis, and raw data that mainstream outlets either ignore or actively suppress. Stasi archives, offshore financial trails, lawfare operations, geopolitical ruptures, and the hidden networks that actually move power — this is the vault.
JOIN THE INTELLIGENCE DESK: PATREON.COM/BERNDPULCH
INTELLIGENCEORIGINAL.COM · CYBER & SECURITY · SEPTEMBER 29, 2026
© 2026 INTELLIGENCEORIGINAL.COM — ALL RIGHTS RESERVED
“`



Leave a Reply