Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data

Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data

ShinyHunters, a prolific cybercriminal group known for large-scale data theft and extortion, says it has breached the FBI and stolen data on thousands of agents and applicants. The hackers made the claim on their dark web leak site, which TechCrunch reviewed, saying they had stolen “sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job.” 404 Media first reported on the breach after receiving a sample of the stolen names, home addresses, and phone numbers of FBI agents and their spouses, and verifying a portion of the stolen data against public records. The hackers say their hack is “not financially motivated,” and are demanding that the FBI remove a report that they say contains false allegations about the group. The independent publication said the hackers breached an Oracle PeopleSoft server, often used by human resources and recruiters to store job applicants’ personal information, then pivoted to breach an Amazon-hosted government cloud storing the agents and applicants’ data. ShinyHunters told the publication that they took terabytes of data but did not say what they would do with the information if the FBI does not take down its published report. The stolen data could present a major counterintelligence threat, in which hackers and overseas spies use the information to coerce or extort FBI agents and their families into cooperating with a foreign government. The hackers reportedly defaced the FBI’s jobs site, which showed at the time of publication that the portal was “currently down for maintenance.” The site also said that the FBI’s special agent applicant portal was also down. The FBI did not respond to a request for comment about the incident on Tuesday, and neither did the ShinyHunters hackers. This is the second known breach of an FBI system this year after unidentified hackers broke into one of the agency’s systems for managing real-time wiretaps and foreign intelligence-gathering warrants, which could have identified targets of the agency’s surveillance. Separately, FBI director Kash Patel also had his personal email account hacked and leaked by an Iran-backed hacking group called Handala in retaliation for U.S.-led strikes against Iran. When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence. Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security. He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com. View Bio

Original Source

Read the full article at Techcrunch →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.