The FBI is investigating a declare by a cyber-crime group that it has stolen delicate data on all bureau workers – round 38,000 individuals.
The hackers, Shiny Hunters, says it has each agent’s identify, position, badge quantity and private particulars together with dwelling tackle, cellphone numbers and partner data.
Professor Ciaran Martin, the previous head of the UK’s Nationwide Cyber Safety Centre, mentioned – if confirmed – it was “as severe because it will get on the subject of knowledge breaches.”
In an announcement posted on X, the FBI mentioned it was conscious of the declare and the company was “actively and aggressively investigating the matter”.
The criminals declare to have breached the FBI’s servers on Monday night time and started contacting reporters on Tuesday sharing samples and screenshots of the stolen knowledge.
The BBC has seen a small portion of the info, which seems to be real.
In response to Reuters, among the knowledge accommodates particulars about officers’ job assignments, together with delicate work in opposition to Chinese language spies, Russian intelligence and drug cartels.
ShinyHunters is a world collective of hackers, believed to have initially began in France. It has been behind plenty of high-profile breaches together with on Rockstar Video games in April and a extremely disruptive hack on schooling platform Canvas in Could.
The group claims to have discovered a vulnerability within the Oracle cloud storage system utilized by the FBI to breach a number of programs together with FBIJOBS, FBI BEAST, which does background checks on workers and candidates, FBI MedLink, which holds agent’s medical data and FBI BICS, which holds investigation data.
In its message on the darkish net, the group mentioned it didn’t hack the FBI system for cash.
As a substitute, the cyber-criminals are asking the company to retract an advisory that it issued in Could concerning the gang, saying it was “offended” by its characterisation.
That FBI’s public service announcement, exterior described ShinyHunters as “risk actors” who typically “use their actual or exaggerated claims of entry to delicate or private data to immediate cost from victims”.
“They aim main firms throughout tech, finance, and retail, typically stealing thousands and thousands of buyer data without delay,” the advisory mentioned.
ShinyHunters mentioned it could give the bureau one week to appropriate or take away what it says are false allegations or they’d publish the complete databases.
The FBI didn’t reply to a number of requests for remark from the BBC.
In its assertion on X, the company mentioned it was attempting to find out whether or not or not the hackers had breached its programs or a 3rd get together.
“We’re actively and aggressively investigating this matter and dealing carefully with these third-party suppliers that help FBIJobs.gov to mitigate any and all threat,” the put up mentioned.
In an announcement to the BBC, a cyber-security knowledgeable mentioned it was a “retaliation assault”, which demonstrated that “no organisation is protected from the group”.
“The group clearly needs to regulate the narrative round their actions, guaranteeing nothing is alleged that might dent their popularity,” mentioned William Wright of Closed Door Safety.
In the meantime Andrew Brandt of cyber-security agency Huntress mentioned it could provoke the FBI to trace down and prosecute members of the hacking group.
“ShinyHunters should really feel fairly assured they will not get caught to threaten a authorities company like this,” he mentioned.



