A known hacking group has claimed to have stolen more than two terabytes of data containing personal and sensitive information of thousands of employees and job applicants at the Federal Bureau of Investigation (FBI).
According to ITNA, a hacking group called ShinyHunters, which had previously breached several institutions and companies, announced on Tuesday in a message on its dark web site that it gained access to very sensitive data related to nearly all FBI agents and people who have applied for jobs at the agency.
An FBI spokesperson said in a statement that the agency is aware of the claims regarding unauthorized activity on the FBIjobs.gov recruitment site and is investigating the matter.
Unprecedented theft
Cybersecurity experts have said that although cybercriminals and state-sponsored hackers have been infiltrating U.S. IT systems for years, stealing precise and sensitive information about FBI employees is an unprecedented and audacious act.
The main concern is that such information is usually traded on the dark web and ends up in the hands of the highest bidder.
Details of the incident
According to Axios, ShinyHunters told the site in an email that the stolen data includes names, employment status of agents, email, phone number, home address and in some cases even spouses' information including their Social Security numbers.
The group also claimed to have infiltrated criminal justice, human resources and other internal FBI systems.
According to the hacking group, they exploited a zero-day vulnerability in Oracle's PeopleSoft platform to seize and deface the FBI's recruitment page; a site that remained unavailable as of Tuesday afternoon.
Although the authenticity or recency of the stolen data has not yet been independently verified, cybersecurity researchers have confirmed the credibility of the attack.
404 Media also obtained a sample of the leaked data that apparently contains information on about five thousand purported FBI agents.
Reactions and expert views
Cynthia Kaiser, a former official in the FBI's cyber division, said the agency is expected to mobilize more resources to identify the perpetrators more quickly after such an attack.
Alan Liska, threat intelligence analyst at Recorded Future, believes that while the attack will draw greater short-term attention from law enforcement to ShinyHunters, its long-term harm falls on FBI employees and their families whose information has been exposed.
Andrew Brandt, head of threat intelligence at Hunters, also warned of the possibility that these data could be sold to other criminal groups or state-sponsored hackers, saying that disclosure of such information could expose employees and their families to threats or harm.
Background
ShinyHunters claims the attack was not financially motivated, but aimed at forcing the FBI to retract statements it had previously made about the group's methods.
In a warning published in Ordibehesht this year, the FBI accused these hackers of using harassment tactics, including sending threatening messages to victims and their families and in some cases engaging in swatting (false police reports). ShinyHunters denied these claims, saying the accusations were attributed to them due to other less-skilled attackers abusing the group's name.