Post

We Hacked the FBI Hackers Claim to Have Data on All FBI Employees

We Hacked the FBI Hackers Claim to Have Data on All FBI Employees

We Hacked the FBI: Hackers Claim to Have Data on All FBI Employees

A high-profile hacking group claims it has breached multiple FBI-related services and stolen data on all FBI employees and applicants. A representative of the group, called ShinyHunters, told 404 Media that the data includes FBI agents’ names, home addresses, phone numbers, and information on their spouses. The representative stated, “We hacked the FBI. We hold data on all FBI employees and applicants.” They provided 404 Media with a sample appearing to contain the personal data of 5,000 FBI employees, including alleged addresses, phone numbers, dates of birth, and in some cases, details on their spouses.

404 Media put some of the sample phone numbers into the open-source intelligence tool OSINT Industries and found they corresponded to people with the same names as listed in the sample file. Additionally, these records revealed that some of the phone numbers are associated with U.S. Department of Justice personnel. ShinyHunters also defaced the FBI jobs website on Tuesday, displaying the message, “This site has been seized by ShinyHunters.” The defacement further claimed, “All FBI data was compromised including PII/PHI (personally identifiable information and protected health information) on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.” At the time of writing, the FBI jobs website stated, “Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable.” After publication, an FBI spokesperson told 404 Media, “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.”

The representative said ShinyHunters used a zero-day exploit in an Oracle product called PeopleSoft. From there, the group managed to access AWS GovCloud servers and downloaded data. The representative stated that the exfiltrated data totaled between two and three terabytes. When asked if ShinyHunters was going to attempt to extort the FBI, the representative said, “What we plan to do is not something I’d call extortion, maybe coercion,” adding, “This is not financially motivated.” In a post on its leak website, ShinyHunters said the FBI made “false allegations” in a previously published report. ShinyHunters stated it is “allowing you [the FBI] a time of 1 week to correct” or remove the report.

The data breach could be massively significant and may have all sorts of national security and counterintelligence implications. Criminals from the same ecosystem as ShinyHunters have previously used hacked data like phone records to track, intimidate, and harass the FBI agents investigating them. The highly sensitive data could also be a boon to foreign intelligence agencies who want to better understand how one of the most important law enforcement and intelligence agencies in the U.S. operates. If the data fell into the hands of more criminals, FBI agents and their spouses could face serious threats to their safety.

Read full article\n

This post is licensed under CC BY 4.0 by the author.