Officials cite ‘incompetence’ for massive FBI cyber hacking attack | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


The hack of FBI computer systems exposed sensitive personal information about nearly every FBI employee, as well as thousands of local law-enforcement officials who worked on FBI task forces, six current and former FBI officials told MS NOW.

FBI officials and outside experts are calling the breach one of the worst counterintelligence disasters in modern history. They say it raises questions about whether negligence was a factor in allowing it to happen.

One FBI agent who works on cybersecurity matters chalked the breach up to “incompetence.”

“This was a vulnerability that supposedly they thought they patched, but managed to miss one of the ways to patch it,” the agent said in a text message, adding that the cause was “definitely incompetence.”

The sensitive employee information that was stolen “should never have been tied to the Internet, either. It belonged on our internal system and some dumbass moved it all” to an internet-facing system, the agent said.

The agent added that the FBI obtained chats in which the hackers expressed disbelief that such sensitive information was available to them so easily.

Google’s threat intelligence experts issued a public warning in June about the vulnerability the hackers exploited, and the FBI took steps to shore up its systems, two cyber security experts told MS NOW, speaking on the condition of anonymity to discuss a sensitive matter.

But the hackers found a way around the FBI patch, they said. 

“It’s the fault of whoever in the FBI is responsible for our cyber security,” said the FBI cyber security agent who blamed the breach on “incompetence.” The agent added, “But also whoever pushed that information from our internal system to the Internet.”

An FBI official told MS NOW that the hack was the result of a vulnerability in software maintained by a third-party vendor. The official didn’t respond to questions about the allegations of FBI incompetence.

Cybersecurity experts say the hacking group, which calls itself ShinyHunters — a reference to a game pursuing rare and valuable Pokémon characters — got in through the FBIJobs.gov portal by exploiting a previously unknown vulnerability in Oracle PeopleSoft, the human resources software. The hackers did not penetrate the FBI’s core investigative network or any classified systems, the current and former officials said.

Nonetheless, the information they stole could be extremely damaging.



Source link

...........