Chaos and Fear at F.B.I. after Massive Data Hack Revealed | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker

NEW YORK – A criminal group known as ShinyHunters recently “revealed it had pilfered intimate details about bureau personnel from the agency’s jobs portal and threatened to leak them online,” The New York Times – which has analyzed some of the records – reports.
On September 28, the F.B.I. issued a statement saying it was “working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted… The F.B.I. treats the security of its information and the safety of its work force as top priorities, and our investigation is ongoing.”
The article, with the headline ‘Embarrassing Breach at F.B.I. Fuels Fears of Harm to Its Employees’, further notes that “the theft by a criminal hacking group of reams of sensitive personal data involving potentially tens of thousands of former and current F.B.I. employees is emerging as one of the worst breaches of sensitive government information, leaving the bureau rushing to protect its personnel as an uncertain deadline loomed.”
A sample of records were shared by the hackers with The Times and other news organizations.
On September 25, the F.B.I. issued an internal memo: “We are operating under the premise that the threat actor is also exfiltrating PII of all F.B.I. employees… Bureau leadership remains committed to supporting the safety of you and your family.”
The Times writes that “the memo said the agency would offer virtual briefings in the weeks ahead and instructed employees to remain vigilant at home and at work, report any unsolicited contacts or threats, avoid answering calls from unknown numbers and set up voice mail accounts with A.I.-generated voices.”
The article adds: “Still, many past and present personnel remain in the dark about whether their data has been purloined,” and “some have anxiously asked Times reporters whether their names are contained in the hacked data, wondering whether they needed to take steps to protect themselves or their families.”
ShinyHunters, according to The Times, is “believed to be a loose collective of young hackers operating across the globe. It said it had targeted the F.B.I. as retribution for a public advisory the bureau had issued in the spring, warning that the group was known to harass victims and family members with threatening or coercive maneuvers. In their note, the hackers demanded that the F.B.I. “correct or simply REMOVE” the advisory or risk further consequences.”
In an email to The Times on Sept. 25, “ShinyHunters said that the bureau had until the end of Tuesday to fulfill its request, even as the hackers themselves appeared to acknowledge that the bureau was unlikely to acquiesce.”
The Times write that the “note left open the possibility that the hackers would not dump the data online, even as the group reiterated its deadline. But on Monday [Sept. 28], in a new statement, the group claimed it never intended to do so.
“We have never intended to nor have we ever planned to.” It added that the hack and threat to the F.B.I. was a “marketing campaign to protect our business” and said that “we are not taking any further actions” with the data, including revealing more about what is contained in the files.
“We seek no escalation as our goals have widely been accomplished,” it said.
(Material from The New York Times was used in this report)


