incident-responsetrade-pressNewsThe Broadside1 min read

ShinyHunters claims FBI HR breach, demands warning retraction

The demand letter is a publicity tactic dressed as a negotiation, the group isn't asking for a ransom payment, it's asking the Bureau to rewrite its threat advisory.


TL;DR

The ShinyHunters cybercriminal group claims it breached FBI systems and stole sensitive data on agents and job applicants, threatening to release the material unless the Bureau retracts a May 15 public service announcement that described the group's harassment and swatting tactics. 404 Media reported receiving a file appearing to contain information on roughly 5,000 FBI employees. The FBI has not commented on the claims, and the account of the intrusion has not been independently verified.

ShinyHunters addressed its demand to FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman, giving the bureau one week to correct or remove the May 15 warning. The group claims the intrusion was not financially motivated.

The PSA at issue warned that ShinyHunters uses harassment to pressure victims, including threatening communications to victims and family members and, in some cases, swatting. The alert also noted that attackers may exaggerate their access to personal information or falsely claim to possess compromising material. ShinyHunters denied those practices in its statement.

The group says it accessed several FBI services, including human resources systems and something identified as Medlink. A representative told 404 Media the entry point was a previously unknown vulnerability in Oracle's PeopleSoft software, and that the group moved into servers in AWS GovCloud. The same representative claimed the group took between two and three terabytes of data.

An FBI jobs page displayed a "Scheduled Maintenance Underway" notice Tuesday, and an earlier version of the page appeared to show a seizure notice posted by the group. Whether the outage is connected to the claimed intrusion is unknown.

The claims arrive during a year when the Bureau has already been managing the fallout from a suspected Chinese breach of its surveillance systems, reported in March. The FBI has not said whether the two incidents are related.

Nextgov/FCW has reached out to the FBI, the FBI Agents Association, Oracle, and AWS for comment. None had responded at publication time.


Published ·Deep Fathom