The hacking collective known as ShinyHunters has alleged that it stole between 2 and 3 terabytes of sensitive information belonging to employees and job applicants of the US Federal Bureau of Investigation. According to reports from Reuters and 404 Media, the group utilized a zero-day vulnerability in Oracle’s PeopleSoft software to breach Amazon Web Services’ GovCloud servers.
A spokesperson for ShinyHunters told 404 Media, “We hacked the FBI. We hold data on all FBI employees and applicants.” The sample data reviewed by journalists reportedly contained personal identifiable information for approximately 5,000 individuals, including names, addresses, phone numbers, dates of birth, social security numbers, and emergency contacts. The hackers also claim access to details regarding specific work assignments for agents and information about FBI units involved in intelligence, security, and counter-espionage operations targeting China and Russia.
This incident follows an earlier claim by the group that it had taken over the FBI’s website. In response, the FBI confirmed it is aware of the cyber-criminal enterprise’s allegations regarding a compromise of the FBIJobs.gov portal and stated it is “actively and aggressively investigating the matter.”
While ShinyHunters has historically targeted corporations such as Ticketmaster and Rockstar Games for financial extortion, the group asserts this attack was not money-driven. Instead, they claim the objective is to coerce the government into retracting or amending a May report in which the FBI accused the hackers of exaggerating their access to sensitive data to solicit payments from victims.
I’m glad the FBI is investigating aggressively. We need transparency on what exactly was accessed and who is responsible for the breach.
This is exactly why we need better government cyber hygiene. A zero-day in Oracle shouldn’t compromise national security data.
Wait, so they did hack it but only exaggerated the extent? That’s a pretty bold claim if true. What’s the actual proof here?
Five thousand people with exposed SSNs is a nightmare. I can’t believe the FBI left their GovCloud this vulnerable.