Skip to content

Cart

Your cart is empty

Article: Hackers Claim FBI Data Breach

Illustrative file photo. FBI cyber agents work at computer systems. The cybercrime group ShinyHunters claimed Sept. 22 that it breached FBI systems and stole personal information belonging to thousands of bureau employees and applicants. The FBI had not

Hackers Claim FBI Data Breach

PHOTO CAPTION: Illustrative file photo. FBI cyber agents work at computer systems. The cybercrime group ShinyHunters claimed Sept. 22 that it breached FBI systems and stole personal information belonging to thousands of bureau employees and applicants. The FBI had not confirmed the claimed breach as of Tuesday afternoon. (Federal Bureau of Investigation photo)

A notorious cybercrime group says it breached FBI systems and stole a massive collection of personal information belonging to current and former bureau employees and people who applied for jobs with the agency.

The group, known as ShinyHunters, publicly claimed responsibility Tuesday and provided journalists with a sample that it says came from the FBI.

The FBI had not confirmed the claimed breach or responded to repeated requests for comment as of Tuesday afternoon.

The claim first emerged through 404 Media, which reported receiving a sample containing information on roughly 5,000 alleged FBI employees.

The sample included names, home addresses, telephone numbers, dates of birth and, in some cases, information about employees’ spouses.

404 Media checked some of the telephone numbers against outside databases and found that they corresponded to people with the same names listed in the sample. Some numbers were also associated with Department of Justice personnel.

Reuters conducted its own checks on some of the material.

The news agency compared names, address information and Social Security numbers in the sample against credit bureau information and previously leaked records maintained by cybersecurity researchers.

In at least nine cases, Reuters found information that appeared to match.

But Reuters could not determine where ShinyHunters obtained the information or verify that the records were actually stolen from FBI systems.

That distinction is critical.

ShinyHunters claims it obtained information on almost all FBI agents, as well as people who applied for employment with the bureau.

That sweeping claim has not been independently verified.

What journalists have been able to establish so far is that at least portions of the sample appear to contain accurate information connected to real people.

The source and full scope of the data remain unknown.

The hackers also claim they obtained between two and three terabytes of data.

According to ShinyHunters, the intrusion began through an Oracle PeopleSoft system. The group claims it then gained access to government cloud infrastructure hosted by Amazon and downloaded additional information.

Those technical details currently come from the hackers themselves and have not been confirmed by the FBI, Oracle or Amazon.

PeopleSoft is widely used for human resources and employment functions, which could potentially explain why the claimed data includes information on both employees and job applicants.

TechCrunch reported that ShinyHunters said it accessed the PeopleSoft system before moving into an Amazon hosted government cloud environment.

There was another visible development Tuesday.

404 Media reported that ShinyHunters defaced an FBI jobs website with a message claiming the site had been seized by the hackers.

The publication reported that the FBI jobs site later displayed a notice saying its application system and Special Agent Applicant Portal were unavailable.

Reuters could not authenticate the hackers’ screenshot of the alleged defacement, but independently observed that the FBI job system had experienced disruption Tuesday.

The outage by itself does not prove that ShinyHunters penetrated the FBI’s internal network.

The main FBI Jobs website was accessible again when checked later Tuesday, although the earlier disruption remains part of the circumstances surrounding the hackers’ claim.

ShinyHunters is not an unknown group.

It has been associated with major data theft and extortion campaigns involving private companies, schools and software platforms.

The FBI itself published a cybersecurity warning last year describing activity in which victims of data theft later received extortion demands attributed to ShinyHunters.

The hackers say this attack was retaliation.

ShinyHunters told Reuters it targeted the bureau because of an FBI announcement issued in May that described the group’s methods and advised victims not to pay extortion demands.

The group told 404 Media that its current demand is not primarily financial. Instead, it wants the FBI to remove the report about the group.

The hackers characterized their demand as coercion rather than extortion.

If the larger claims are eventually confirmed, the potential consequences would extend far beyond ordinary identity theft.

Home addresses, telephone numbers, family information and other personal details connected to federal law enforcement personnel could potentially be useful to criminals seeking to intimidate investigators or to foreign intelligence services attempting to identify and target FBI personnel.

TechCrunch noted that information of that kind could create counterintelligence risks involving agents and their families.

But the scale of that potential exposure remains uncertain.

There is currently evidence that some information in the sample corresponds to real people.

There is also evidence that FBI recruiting systems experienced disruption Tuesday.

Neither fact independently proves the hackers’ much larger assertion that they compromised data belonging to almost every FBI agent and applicant.

As of Tuesday afternoon, the central question remained unanswered: Did ShinyHunters actually penetrate FBI systems on the scale it claims, or did the group obtain some of the information through another source?

Until the FBI responds or independent investigators establish where the data originated, the alleged breach remains exactly that: a claim supported by some apparently authentic personal information, but not yet confirmed in its full scope.

(Source: OAF Nation)

MORE FROM THE

OAF NATION NEWSROOM

Illustrative file photo. Fixed blade and folding knives are shown together in a military field kit. Knife Rights, the Association of New Jersey Rifle & Pistol Clubs and four residents filed a federal lawsuit Sept. 21 challenging New Jersey restrictions

NJ Sued Over Knife Carry Laws

Gun Rights Groups Sue New Jersey Over Carrying Knives and Other Objects for Self Defense

Read more