news.mlab.sh
Back to the feed
threat-intel

FBI investigating alleged ShinyHunters breach of its jobs site

High
Summary

The FBI is investigating a suspected breach of its jobs website by the ShinyHunters cybercriminal group. The group defaced the site, claimed to have stolen data on current and former FBI employees and applicants, and threatened to leak the information unless the FBI removed a public service announcement. The FBI is concerned about the potential misuse of the stolen data, particularly by other criminal or nation-state actors, given the sensitive nature of the information involved and the roles of those affected.

The Federal Bureau of Investigation is currently investigating a suspected breach of its job applications platform, FBIjobs.gov, following claims made by the cybercriminal group ShinyHunters. On Tuesday, the group replaced agency images on the website with a photo of a Pokemon, a mascot for the group, and subsequently posted a lengthy statement criticizing the FBI for a public service announcement released earlier in the year, asserting that the group’s claims regarding stolen data were exaggerated. The group threatened to leak information on every FBI agent and applicant if the alert was not removed.

As of Wednesday morning, the FBIjobs.gov site still displays a banner indicating that the special agent application portal is currently unavailable. ShinyHunters provided samples of 5,000 stolen FBI agent records to 404media and several other news outlets, which have verified their legitimacy. The group has been in the crosshairs of the FBI for nearly a year, following a series of high-profile attacks on companies like Ticketmaster and AT&T, as well as educational publisher McGraw Hill, Carnival Cruise Line, and 7-Eleven.

During a recent roundtable, Brett Leatherman, assistant director of the FBI’s Cyber Division, emphasized the FBI’s focus on ShinyHunters due to their expertise in data exfiltration and extortion attacks. Experts believe the group is likely to leak the stolen data, potentially selling it to other criminal or nation-state actors for more damaging use. This is particularly concerning given the sensitive nature of the information – including records of FBI personnel – and the potential for misuse, such as financial fraud, threats against staff and their families, or future targeted attacks.

Read the full article at The Record