ShinyHunters Claims FBI Data Breach As Agency Investigates Cyber Incident

ShinyHunters Claims FBI Data Breach As Agency Investigates Cyber Incident

Cyber extortion group ShinyHunters has claimed that it compromised FBI systems and obtained sensitive information related to employees and job applicants, while FBI has confirmed that it is investigating claims of unauthorized activity affecting its online jobs portal. The group published a message on its data leak site claiming access to personal information associated with FBI personnel and applicants, stating that the alleged breach was linked to several internal services. FBI said it was aware of the claims regarding unauthorized activity affecting FBIjobs.gov and was reviewing the matter. At this stage, the full extent of the alleged incident and whether any sensitive information was accessed or exposed remains under investigation.

According to ShinyHunters, the group allegedly obtained personal information belonging to FBI agents and individuals who submitted job applications to the agency. The group claimed that the compromised information included names, home addresses, phone numbers and details related to family members. ShinyHunters also alleged that affected services included Criminal Justice, Human Resources and Medlink systems. The group claimed that it exploited a zero day vulnerability in Oracle PeopleSoft software and later moved into FBI’s Amazon Web Services GovCloud environment, where it allegedly accessed more than two terabytes of data. These claims have not been fully verified, although some media reports stated that a sample of allegedly stolen records reviewed by researchers appeared to contain legitimate information.

The alleged incident follows a public dispute between ShinyHunters and FBI regarding previous statements about the group’s cyber activities. ShinyHunters claimed that its actions were a response to what it described as inaccurate information shared by FBI regarding its methods and operations. The group demanded that FBI update or remove a previous security alert related to its activities, stating that stolen data would be deleted if the request was addressed within a specified timeframe. Cybersecurity experts and law enforcement organizations have repeatedly warned that promises from cyber extortion groups to delete stolen information cannot usually be verified and may not be honored. Security researchers have also noted that public claims made by cybercriminal groups are often intended to create pressure, attract attention or influence negotiations.

The first public indication of the reported incident appeared when FBI’s online jobs portal was allegedly defaced with ShinyHunters messaging and cyber extortion content. FBI later took the affected website offline, with visitors receiving a system unavailable message. The group has previously been associated with large scale data theft campaigns targeting organizations across different sectors. In recent months, ShinyHunters has claimed attacks involving universities, healthcare organizations and government related entities, including organizations using Oracle PeopleSoft platforms. The group has also attempted to distance itself from broader cybercrime communities such as The Com, rejecting claims of association with groups involved in harassment, swatting or other harmful activities.

Cybersecurity experts have described targeting a law enforcement organization as a significant development in the activities of cyber extortion groups. However, analysts have also suggested that public claims against high profile targets can serve as reputation building efforts within cybercrime networks. Meanwhile, ShinyHunters has continued making additional claims involving other organizations, including Fresenius Medical Care, which confirmed it was investigating unauthorized access affecting a limited number of internal systems. The healthcare company stated that medical devices, patient care, manufacturing operations and business continuity were not impacted. Investigations by affected organizations and security authorities remain ongoing as officials work to determine the authenticity of the claims, the scope of any potential exposure and the appropriate response measures.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment