The Daily · 2026-09-30
Inside the Devastating Hack of the F.B.I.
This is Wakewire's analysis, based on the recording and the passages quoted here. Tone and candor labels are our read, not a finding about anyone's motive. Our standards
- Source
- The Daily · Episode page
- Released
- 2026-09-30
- We read it
- 2026-09-30
- Recording
- Recording has gaps
- Read confidence
- medium
- Review
- Passed automatic checks
What the episode covered
Dustin Volz said hackers stole sensitive FBI personnel data from a government jobs portal, exposing employees and family members. The register is mixed, with detailed reporting but a visible transcript break at a key verification moment. Watch whether officials confirm what was taken, how the data was validated, and whether the stolen records surface.
Our summary, written from the transcript. Not the speakers' words.
The episode, in order
01Breach scale and sensitivity
The issue is less only the number of people affected and more the detail of data tied to law enforcement work and families.
02Comparison to OPM
That comparison makes the story a test of whether post-OPM promises to protect government personnel data changed enough.
03Hackers and method
If confirmed, that would make the pathway through enterprise software and data management practices central to the fallout.
04Retaliation concern
The harms described extend beyond institutional embarrassment to personal and family safety.
Sponsors named in this episode
| Sponsor stated | Where, claim and disclosure |
|---|---|
| YouTube Premium |
|
| The New York Times app |
|
| Altra |
|
| Vanta |
|
No sponsor named doesn't mean no ads. Each row was taken from the ad break as it was read on air. The verbatim passage behind every row is checked against the transcript character for character. Short excerpts appear below.
Roles and stated affiliations
Stated affiliation. ShinyHunters: As described by Volz, the group said it wanted the FBI to correct a public service advisory and also operates an extortion model against organizations.
Wakewire's read of interests
- Michael Barbaro: He hosts the episode and frames the breach as a major public story for The Daily audience.
- Dustin Volz: He is introduced as a New York Times cybersecurity reporter explaining his reporting on the breach.
- The New York Times: The recording promotes Times journalism and the Times app after the interview.
- Advertisers named in the recording: YouTube Premium, Altra, and Vanta use the episode feed to promote paid products or services.
Recording limits
- The transcript appears to skip from “They sent you essentially a sample of the” to a YouTube Premium line and then to a later FBI discussion.
Claims that need more support
- Dustin Volz said the hackers found and used a zero-day against an Oracle PeopleSoft product, but the excerpt does not include confirmation from Oracle, the FBI, or a forensic source.
Claims made on air that the episode itself did not back up.
Questions the conversation didn't reach
- The episode raises but does not answer why the FBI-related jobs portal kept spouses, siblings, children, emergency contacts, and other intimate information in one repository for years.
Topics the episode did not address. This does not mean anyone avoided them.
Are you from this show? You can ask for a correction, reply, or ask us to stop coverage on the rights page.
The read
The strongest subtext is data stewardship, not only hacker audacity. The episode says the breach matters because a personnel repository appears to have gathered sensitive job, family, and contact information that current and former officials did not expect to exist in that form. A charitable read is that the segment is warning the public about safety risks before the stolen data spreads. A boring read is that enterprise HR systems and retention rules created a large target. A skeptical read is that the episode leans on unnamed officials and a broken transcript section where authentication of the sample data would matter most.
This read assumes: The officials described by Volz are accurately represented in the episode. The transcript excerpt is missing part of the interview at the ad insertion. The stolen-data descriptions in the available excerpt reflect what the reporters were able to review.
Every opinion labeled as one. This is Wakewire's analysis of the recording, not a finding about anyone's motive.
What was said
Breach scale and sensitivity
Volz said the breach may affect tens of thousands of current and former FBI employees and included unusually sensitive personal and job-related data.
Comparison to OPM
The episode revisited the 2015-era Office of Personnel Management breach and said officials view the new incident as potentially comparable or worse in some respects.
Hackers and method
Volz said ShinyHunters described using a zero-day flaw in an Oracle PeopleSoft product tied to HR and financial records.
Retaliation concern
Volz said former FBI officials worry that agents who worked violent crime, mafia, cybersecurity, or foreign intelligence matters could face exposure if the data becomes public.
Our paraphrase, not the speakers' words.
The passages we relied on
"why would there be a place where there's a repository of so much intimate information that seemingly is kept for years without being deleted, without being purged, that a hacker could access and take."
"If you like YouTube, you'll love YouTube Premium. Hi, Sean Evans from Hot Ones here. With"
"If you like YouTube, you'll love YouTube Premium. Hi, Sean Evans from Hot Ones here."
"You can read more from Dustin Volz and all of our reporters on The New York"
"If you like YouTube, you'll love YouTube Premium. It's destroying athlete, creator, and YouTube Master. YouTube"
"Hey, what's up, guys? It's Haley Bailey. Okay, I need to tell you about something. I"
"Why do most running brands force your toes into tight, pointy shoes? At Altra, we think"
"As AI adoption grows, so do your company's security risks and requirements. New frameworks, audits, and"
Short excerpts, credited to the show, at most 40 words each and 150 per episode. We do not publish transcripts. We link to the episode so you can hear it from the show itself.
What to watch for
- A public statement from the FBI, Oracle, or another named counterparty confirming the exploit path and affected system. (Days to weeks.)
- Evidence that the stolen records are published, sold, or used to contact FBI employees or relatives. (Days to months.)
- Congressional hearings, inspector general activity, or agency reviews focused on data retention and repository design. (Weeks to months.)
- More reporting that explains how the sample data sent to Volz was authenticated. (Days to weeks.)
Written by Wakewire's system under our editorial standards. Reading is open to everyone. A free account personalizes your brief.