Headlines

‘Almost all agents’ data stolen? Hackers claim they breached FBI jobs site, stole 2TB of data

‘Almost all agents’ data stolen? Hackers claim they breached FBI jobs site, stole 2TB of data


'Almost all agents' data stolen? Hackers claim they breached FBI jobs site, stole 2TB of data
File photo: An FBI agent walks inside the front entrance of ex-Trump national security adviser John Bolton’s Washington office (AP Photo)

The FBI is investigating an apparent cyberattack on its job application website after the hacking group ShinyHunters claimed it stole more than 2 terabytes of data containing sensitive personal information about thousands of FBI employees and job applicants.The bureau confirmed that it was investigating unauthorised activity affecting FBIjobs.gov, while the website’s Special Agent applicant portal was unavailable on Tuesday.ShinyHunters claimed on its dark-web site that it had obtained “very sensitive data” on almost all FBI agents and people who had applied for jobs with the bureau. The group also claimed it had accessed the FBI’s criminal justice, human resources and other systems.However, Axios said it could not independently verify whether the stolen data was legitimate or current. Cybersecurity researchers told the publication that the attack itself appeared legitimate, while 404 Media obtained a sample of the alleged stolen data that appeared to contain information on about 5,000 people identified as FBI agents.

What hackers claim they stole

According to Axios, ShinyHunters said the data included names, agent status, email addresses, phone numbers, home addresses and, in some cases, information about spouses, including Social Security numbers.The group also claimed it used a zero-day vulnerability in Oracle’s PeopleSoft platform to access and deface the FBI’s jobs website. The site remained offline on Tuesday afternoon.Cybersecurity experts told Axios that the potential exposure could pose a long-term risk to FBI employees and their families if the information is circulated among other criminal groups or sold on the dark web.Allan Liska, a threat intelligence analyst at Recorded Future, told Axios that the data was likely to be repeatedly downloaded and shared with other threat actors if it had been obtained as claimed.Andrew Brandt, principal threat intelligence incident commander at Huntress, said the biggest concern was whether ShinyHunters would sell the information to criminal or state-sponsored hackers.

Why did ShinyHunters target the FBI?

The group claimed the attack was not financially motivated. Instead, it demanded that the FBI retract or revise statements the bureau made about its activities.In a May advisory, the FBI warned that ShinyHunters commonly uses harassment tactics against victims and their families, including threatening calls and messages and, in some cases, swatting.ShinyHunters disputed the FBI’s description, telling Axios that other “low-skilled threat actors” had been carrying out attacks while using the group’s name.The FBI did not say whether it had confirmed the identity of the attackers or the extent of any data compromise.The incident comes as US law enforcement agencies face repeated cyberattacks. CNN reported that the FBI investigated a separate suspected breach in March involving a sensitive network used to manage wiretaps and intelligence surveillance warrants.Last month, hackers also leaked files they allegedly stole from the Justice Department’s Bureau of Alcohol, Tobacco, Firearms and Explosives. CNN reported that the material appeared to contain sensitive information from past investigations.The FBI has also faced cyber incidents in the past, including a 2023 breach of a computer system used by its New York field office for child sexual exploitation investigations.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *