Criminal hacking group ShinyHunters has claimed to have stolen more than 2 terabytes of FBI employee data and has demanded the government agency retract a May advisory about the group.

The group said on its website that it holds private data on all current FBI staff, as well as anyone who has applied for a job with the bureau, totalling around 38,000 people. This allegedly includes agent’s names, badge numbers, roles and personal information including home address, phone numbers and spousal information.

The alleged hack took place on Monday night, and the group contacted news organisations including the BBC on Tuesday sharing samples and screenshots of the stolen data. The UK news organisation said that the portion it had seen appears to be genuine.

Reuters reported that some of the data includes sensitive information about agent assignments, including work against Chinese spies, Russian intelligence and drug cartels.

The FBI issued a statement on social media platform X yesterday saying that while the point of breach is still undetermined, it is “actively and aggressively” investigating the matter.

The FBI’s jobs website is currently offline, displaying a Cloudflare error page saying there is an “unknown error” with the web server.

In a message on the dark web, the group said that it did not perform the hack for financial gain but rather with the goal of forcing the agency to retract an advisory it issued about ShinyHunters in May.

Speaking to technology news site The Register, a spokesperson for the group said it was “NOT financially motivated”, adding that it wants the FBI to “correct or retract their statements they made, which included substantial false allegations.”

The statements referred to were made in a 15 May bulletin in which the FBI said that ShinyHunters used “harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.”

The alert also said that the extortionists “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”

ShinyHunters’s spokesperson claimed to The Register that none of this is true. “I have been doing my very best to combat these allegations,” they said, “and this is the best way to do it.”

The spokesperson told the site that it exploited an Oracle PeopleSoft zero-day vulnerability on the FBI’s jobs webpage, allowing for remote code execution on the servers.

ShinyHunters also claimed to The Register that it moved laterally from the compromised site to the FBI’s managed servers on AWS GovCloud, where it downloaded between two and three terabytes of data.

This is the latest in a series of major data hacks claimed by the group this year. In June, it claimed to have stolen more than 300 gigabytes of sensitive employee and government data from the Council of Europe, and earlier this month it released data affecting around 6.4 million people after medical supplier McKesson apparently did not pay its requested $55.2 million ransom.


Share.
Exit mobile version