FBI Hacked, Sensitive Info on "Almost All FBI Agents" Stolen
The notorious hacker group ShinyHunters claim they breached the FBI's systems on Monday night, reportedly accessing the personal data of "almost all FBI agents/employees."
The data ShinyHunters claims to have infiltrated includes home address, phone number, dates of birth, spousal information, education data, former US government employment information, sensitive medical and drug info, and more.
The group claims to have found a new zero-day vulnerability in Oracle's PeopleSoft enterprise software, which allowed for the breach.
ShinyHunters say the hack was due to false allegations by the FBI in a PSA they released titled ShinyHunters: Cyber Criminal Group Attacks Learning Management System published on May 15th. The PSA refers to the infamous hack of the online learning platform Canvas, used by a large number of educational institutions.
ShinyHunters' issues with the public notice are threefold:
- it exaggerates the access of personal information to prompt payment from victims
- it claims they used harassment of victims including threatening of victims and their families with text messages, phone calls, and swatting
- it falsely claims that they have sensitive or compromising information on the victims including embarrassing photos and videos
They stated Tuesday to the FBI:
We wish to state unequivocally we have NEVER conducted swatting attacks against corporate victims personnel nor have we ever texted victims personnel family members any threats
They claim that they did not claim to have sensitive or compromising information and they "ARE NOT SEXTORTIONISTS." They also say they're not involved with "The Com," a decentralized network of cybercriminals where hackers brag about their hacks and promote violence against victims.
They further state that "The Com" is "a propaganda started by the InfoSec Industry, which has brainwashed past FBI and DOJ officials into formalising this nonsense.”
Attacks on public institutions are nothing new. Just weeks ago, 6.3GB of confidential internal information was accessed by hacker group Qilin and published online.
Public utilities such as water filtration facilities face attacks aimed at contaminating the water supply for millions of people.
It's clear the current state of cybersecurity is woefully underprepared for the adversaries we face. When you think about the countless pieces of software that companies use internally, an exploit in any number of them could be a disaster for the whole company or organization.
Community Discussion