Hacker Group Claims Massive FBI Data Breach, FBI Probes Zero-Day Attack on Jobs Portal
The cybercrime group ShinyHunters claims to have stolen more than 2 terabytes of sensitive data on thousands of FBI employees and job applicants by exploiting a zero-day vulnerability in Oracle’s PeopleSoft software. The FBI is investigating but has not confirmed the breach, while its jobs website remains offline.
The FBI is investigating an apparent cyberattack on its job application website after the hacking group ShinyHunters claimed it stole more than 2 terabytes of data containing sensitive personal information about thousands of FBI employees and job applicants, according to multiple reports.
The bureau confirmed that it was investigating unauthorised activity affecting FBIjobs.gov, and the site’s Special Agent applicant portal remained unavailable as of Wednesday, according to sources inside the FBI told Bloomberg.
ShinyHunters claimed on its dark-web site that it had obtained “very sensitive data” on almost all FBI agents and people who had applied for jobs with the bureau. The group also claimed it had accessed the FBI’s criminal justice, human resources and other systems, according to Axios.
The group said it used a zero-day vulnerability in Oracle’s PeopleSoft platform, an application used for human resources and financial management. Oracle has not commented on the bug, reports said. ShinyHunters told the New York Times that it “had weaponized a zero-day, or previously undiscovered, computer bug within the Oracle PeopleSoft software,” and said it plans to continue using the vulnerability for its “businesses’ normal operations.”
The FBI has not confirmed that the hack occurred, but it has begun probing the claims. On Wednesday, the FBI said in an X post that “the point of breach is still undetermined—whether a third-party or the FBI’s enterprise.” It added that it is “actively and aggressively investigating this matter and working closely” with third-party providers supporting the jobs site “to mitigate any and all risk.”
According to Axios, ShinyHunters said the stolen data includes names, agent status, email addresses, phone numbers, home addresses and, in some cases, information about spouses, including Social Security numbers. Cybersecurity researchers told Axios that the attack itself appeared legitimate, and 404 Media obtained a sample of the alleged stolen data that appeared to contain information on about 5,000 people identified as FBI agents.
The group demanded that the FBI retract or revise statements the bureau made about its activities, according to Axios. In a May advisory, the FBI warned that ShinyHunters commonly uses harassment tactics against victims and their families, including threatening calls and messages and, in some cases, swatting. ShinyHunters disputed the FBI’s description, telling Axios that other “low-skilled threat actors” had been carrying out attacks while using the group’s name.
ShinyHunters told FBI Director Kash Patel and the assistant director of the FBI Cyber Division, Brett Leatherman, that they had one week to comply with demands, according to Ars Technica. The group refused to specify what will happen if the deadline is missed. “We cannot comment on what we will do if the FBI does not comply with our request,” ShinyHunters said in an email to the New York Times. “We reiterate we are not extorting the FBI and this is NOT financially motivated.”
The group also stated to the Times: “Our intention, goal, and motive is solely to set the record straight.”
Cybersecurity experts told Axios that the potential exposure could pose a long-term risk to FBI employees and their families if the information is circulated among other criminal groups or sold on the dark web. Allan Liska, a threat intelligence analyst at Recorded Future, told Axios that the data was likely to be repeatedly downloaded and shared with other threat actors if it had been obtained as claimed. Andrew Brandt, principal threat intelligence incident commander at Huntress, said the biggest concern was whether ShinyHunters would sell the information to criminal or state-sponsored hackers.
The incident comes as US law enforcement agencies face repeated cyberattacks. CNN reported that the FBI investigated a separate suspected breach in March involving a sensitive network used to manage wiretaps and intelligence surveillance warrants. Last month, hackers also leaked files they allegedly stole from the Justice Department’s Bureau of Alcohol, Tobacco, Firearms and Explosives. The FBI also faced a 2023 breach of a computer system used by its New York field office for child sexual exploitation investigations, according to CNN.
Artículos relacionados
También te puede interesar




