FBI looking into reported security issues after claims of a hacking group’s breach

FBI looking into reported security issues after claims of a hacking group's breach

FBI Investigates Alleged Security Breach

The FBI is currently looking into a potential security breach involving its public recruitment portal, FBIjobs.gov. This investigation was prompted after a hacking group called ShinyHunters claimed they accessed and exfiltrated confidential personnel and applicant data.

Following these claims, the portal and its associated application system went offline, with notices indicating that services were suspended. However, the full scope of the breach, including how it occurred and the complete amount of data that may have been compromised, has yet to be confirmed by federal officials.

In messages posted on dark-web forums and shared with cybersecurity reporters, ShinyHunters asserted that they stole between two to three terabytes of data, which they say includes records of both current and former FBI personnel as well as job applicants.

The group further stated that this information encompasses personally identifiable details, such as names, home addresses, phone numbers, and email addresses, in addition to data about family members.

ShinyHunters claims they initially accessed these systems by exploiting a supposed zero-day vulnerability in Oracle’s PeopleSoft platform, subsequently gaining entry into an Amazon AWS GovCloud environment connected to FBI operations.

While FBI documents confirm that their recruitment process utilizes Oracle PeopleSoft and AWS GovCloud, the FBI has not verified whether these systems were indeed compromised or if the alleged vulnerability was indeed the method of entry.

So far, ShinyHunters has provided several media outlets with a sample consisting of around 5,000 records, which they claim belong to FBI personnel.

According to reports from Recorded Future News, some organizations examined this sample and observed that the information seemed to match actual FBI and Justice Department personnel. Additionally, Reuters noted that the alleged stolen data corresponds to employees within these agencies.

However, these evaluations do not independently confirm that the records were taken from FBI systems or that ShinyHunters has the larger data volume they claim.

The group’s demands seem aimed at persuading the FBI to retract or modify previous statements made about ShinyHunters and their actions. In their communications, they dispute the FBI’s characterization of their tactics and assert that other criminal entities have misrepresented their name.

They have purportedly given the FBI a deadline to adjust its statements.

“We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to ‘disrupt’ our operations, an effort that ultimately proved unsuccessful,” they stated.

ShinyHunters hasn’t formally described this event solely as a financial ransom demand, though their intentions regarding the data remain somewhat ambiguous. Reports indicate that the group might release additional sensitive information should their conditions not be met.

On their end, the FBI acknowledged the claims made by the cybercriminal group, confirming that FBIjobs.gov may have been compromised and that there could be a risk to the personally identifiable information of FBI employees.

“The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII),” the FBI remarked in a statement. “While the point of breach is still undetermined — whether a third-party or the FBI’s enterprise — we are actively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.”

Cynthia Kaiser, a former deputy cyber director of the FBI and a current senior vice president at Halcyon, expressed concern over the potential risks, stating, “This type of information could be used by criminals to target or physically harm FBI agents, personnel and their families.”

The inquiry remains ongoing, with several serious claims — such as the alleged massive data theft and the methods of access — still unverified and classified as assertions by ShinyHunters rather than confirmed findings from the FBI.

Facebook
Twitter
LinkedIn
Reddit
Telegram
WhatsApp

Related News