Data stolen in a major hacking group’s alleged intrusion into FBI systems is believed to contain personal information on hundreds of FBI intelligence analysts and other employees involved in clandestine intelligence-gathering and surveillance, according to two people familiar with the matter.
The analysts focus on myriad subject areas like Russia, China, Hezbollah, and cartel-related intelligence, said the people, who spoke on the condition of anonymity because the exposures are sensitive. The employees’ roles only offer a small picture of their duties, but may still help outsiders identify people working in sensitive parts of the bureau.
ShinyHunters claimed responsibility for the breach Monday, threatening to release what it described as two to three terabytes of FBI employee data unless the bureau retracted a public warning about its tactics within a week.
On Tuesday, the group sent Nextgov/FCW and other news outlets an apparent sample of that data containing roughly 5,000 entries listing employees’ names, home addresses, phone numbers and information about their spouses and siblings.
Multiple individuals also work on human intelligence-gathering, as well as roles involving electronic surveillance activities that make use of telecom interception techniques and other covert access mechanisms. Some employees work in the FBI’s Remote Operations Unit, which builds specialized tools to target computers and networks.
One person works in the bureau’s FISA Management Unit, which handles the processing of applications and renewals under the Foreign Intelligence Surveillance Act that governs surveillance and search standards used to collect foreign intelligence.
The FBI said it was aware of “a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information” and added that it is investigating the matter.
The agency said the cause of the breach was still undetermined. ShinyHunters previously said it exploited vulnerabilities in Amazon and Oracle services to access the bureau data. Neither company has returned a request for comment.
Reuters and 404 Media previously reported details regarding the intelligence roles and the ROU staff.
The language ShinyHunters wants removed appears in a May 15 FBI public service announcement that describes practices the hacking group contests. The group has built a global reputation for various hacking achievements. In May, it claimed responsibility for accessing Canvas, the popular education tech platform used by thousands of U.S. institutions.
The direct claim of an FBI breach is “an unusually provocative move” and should be taken seriously, said Etay Maor, the vice president of threat intelligence at Cato Networks.
Exposure of sensitive bureau staffing data could pose profound counterintelligence risks. For employees who do not publicly identify themselves as working for the FBI, the exposure could reveal both their jobs and how to reach them outside secure work environments. Linking that information to home addresses and relatives’ details could make it easier for nation-state groups and cyber criminals to target employees and their families with harassment, scams or threats.
The breach would be “troubling news” for both FBI employees and applicants, said Doc McConnell, a former cyber policy official at the White House and the Cybersecurity and Infrastructure Security Agency.
McConnell, who now heads policy and compliance at Finite State, compared the incident to the OPM hack a decade ago.
“The breach of OPM’s personnel records in 2015 resulted in a decade of credit monitoring for millions of affected individuals, and the full counterintelligence impact will likely never be known. This breach appears to contain similar data, creating potential security concerns for the victims if it is made publicly available,” he said.
The bureau will likely work more assertively to crack down on ShinyHunters. When any group directly targets the agency, “they should expect that the FBI is going to marshal additional resources to bring them more quickly to justice,” said Cynthia Kaiser, the SVP of Halcyon’s Ransomware Research Center and former deputy director of the FBI’s Cyber Division.
The incident follows other cyberattacks involving the bureau and its leadership this year. In March, pro-Iran hacking group Handala published material from FBI Director Kash Patel’s personal email account, which the bureau said contained historical information unrelated to government business. Separately, a suspected China-linked intrusion into an FBI system exposed surveillance targets’ phone numbers.
