Group demands FBI retract May advisory, not money
ShinyHunters said it breached FBI systems on Monday and later posted details of the attack on its darknet site, according to BBC News. The group shared samples of what it said was stolen data with reporters along with an extortion demand.
BBC News reviewed the samples and reported they appear genuine and contain names, addresses, phone numbers, badge numbers, job titles and information about spouses. BBC News also saw samples of stolen “fitness-for-work” medical examinations, which contain information such as blood and urine test results and doctors’ notes mentioning conditions including a “shellfish and banana allergy.” The records include agents’ full names and addresses along with references to medical concerns including “blood in the urine” and “high cholesterol.”
The records appear to relate to thousands of agents, including senior officials such as deputy directors, according to BBC News.
Unusually, ShinyHunters is not demanding payment, according to BBC News. The group wants the FBI to retract an advisory published in May that the hackers claim “offended” them, BBC News reported. The hackers, who communicate with reporters in English via the messaging service Telegram, said they will publish the full dataset in five days unless the FBI meets their demands.
Etay Maor, vice-president of threat intelligence at Cato Networks, said: “The list maps thousands of agents against their medical and fitness records. Passwords can be reset if stolen, but medical records cannot, so once this data is out, it stays compromised for good. That permanence, applied across an entire workforce, is what makes this leak so serious.”
Professor Ciaran Martin, the former head of the UK’s National Cyber Security Centre, described the hack, if confirmed, as “as serious as it gets when it comes to data breaches.”
Jamie Akhtar, chief executive and co-founder of CyberSmart, said the hackers’ claims should be treated with caution but that the breach appeared to be extremely concerning. “Such data could be used for highly convincing phishing, impersonation, identity fraud, blackmail or even operations targeting law-enforcement personnel, making the potential implications particularly serious,” Akhtar said.
The FBI has not responded to requests for comment. On Wednesday, the bureau acknowledged the breach and said it was “aggressively investigating” how it happened. In a statement posted on X, the FBI said it was still trying to determine whether the hackers had breached its systems directly or compromised a third-party provider. “We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk,” the statement said.
According to BBC News, the hackers’ claims about the scope of the breach have grown since they first surfaced. It was initially thought the breach affected the FBI’s 38,000 current employees, but the hackers now say they hold sensitive information on around 60,000 current and former FBI staff. The group says it underestimated the scale of the data theft, according to BBC News.
ShinyHunters claims it exploited a vulnerability in an Oracle cloud storage system used by the FBI, gaining access to multiple platforms including FBIJobs, FBI BEAST (which handles background checks on employees and applicants), FBI MedLink (which stores medical records) and FBI BICS (which contains investigative information).
Reuters reports that some of the data includes information on agents involved in investigations relating to Russia, China and drug cartels. Reporting by 404 Media suggests details of a previously little-known FBI hacking unit may also have been exposed.
ShinyHunters is an international hacking collective that has been active since 2019 and has been linked to incidents affecting Rockstar Games and the education platform Canvas, according to BBC News. The article was reported by Joe Tidy, BBC World Service cyber correspondent.