Press "Enter" to skip to content

FBI investigates claims of breach at jobs website

Key takeaways:

  • The FBI says it has not determined whether any breach involved its own systems or a third-party provider.
  • A ShinyHunters representative claimed the group stole between 2 and 3 terabytes of files, but NBC News could not verify the claim.
  • ShinyHunters said it would publish purportedly stolen data in a week unless the FBI retracts a May public service announcement about the group.

The FBI is investigating claims that hackers breached its jobs website and stole sensitive information about agents and job applicants. The site was offline Wednesday, and the bureau said it had not determined where any breach occurred.

“The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII),” the bureau said in a statement reported by NBC News. “While the point of breach is still undetermined — whether a third-party or the FBI’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.”

FBIJobs.gov is the main portal where prospective employees learn about the bureau and begin applying for jobs, The Guardian reported. An FBI spokesperson said the agency was investigating claims of unauthorized activity affecting the site.

The hacking group ShinyHunters claimed responsibility. In a message described by The Guardian, the group said it had “compromised very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job”. A representative of ShinyHunters told NBC News the group entered the jobs portal Monday, then accessed other agency programs and stole between 2 and 3 terabytes of files.

The group’s claims about the data it obtained could not be verified. The FBI has not confirmed that agents’ or applicants’ information was stolen.

ShinyHunters said the alleged attack was a response to an FBI public service announcement issued in May. The announcement described the group as a “cyber criminal group specializing in large-scale data breaches and extortion”, according to The Guardian. It said the group often uses real or exaggerated claims of access to sensitive information to seek payments from victims and may falsely claim to possess compromising material.

In a post on its website viewed by NBC News, ShinyHunters objected to the announcement: “We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to ‘disrupt’ our operations, an effort that ultimately proved unsuccessful.” The group said it would publish purportedly stolen data in a week unless the FBI retracted the announcement. Its representative told NBC News the operation had been planned since May.

Cynthia Kaiser, a former deputy cyber director of the FBI who is now a senior vice president at cybersecurity company Halcyon, told NBC News that disclosure of agents’ addresses or family details could put them at risk. “This type of information could be used by criminals to target or physically harm FBI agents, personnel and their families,” she said. Kaiser also cautioned that cybercriminal extortionists often mix accurate claims with exaggeration.

In March, the FBI disclosed an investigation into suspicious activity on an internal system containing sensitive information about surveillance operations and investigations, The Guardian reported. The same month, a pro-Iranian hacking group claimed it had accessed an account belonging to FBI Director Kash Patel and posted what appeared to be older photographs and personal documents.

Sources

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Share via
Copy link
Powered by Social Snap