FBI Acknowledges Major Breach Of Employee Data

The US Federal Bureau of Investigation confirmed it is “working around the clock” to investigate a “cyber incident” in which hackers apparently stole sensitive personal data on potentially tens of thousands of current and former FBI staff.

The group, known as ShinyHunters, first disclosed its hack last week, and on Friday bureau leaders declared to staff in an internal memo that it was treating the hack as a cybersecurity incident, while acknowledging that employees’ data had been stolen.

“We are operating under the premise that the threat actor is also exfiltrating PII of all FBI employees,” the memo said, using the abbreviation for personally identifiable information, according to multiple reports.

Data displayed on a screen. Hacking, hacker, security, data, developer, code.

Sensitive data

The hack has emerged as potentially one of the worst in breaches of sensitive government information, in that it could expose current and former FBI staff to physical danger.

The data appears to include home addresses, Social Security numbers, secretive job assignments, the names and telephone numbers of emergency contacts, including parents, siblings and children, employee identification numbers used in airline security checks, the names of units in which FBI personnel are employed and their job titles, and more, according to a sample of the data analysed by the .

ShinyHunters said it also stole medical data including psychiatric records and documents related to blood and urine tests.

The group, which is believed to be comprised of English-speaking people linked to damaging hacks on Marks & Spencer, Jaguar Land Rover, US casino chains, and other organisations, said it was not seeking a financial payoff.

Instead, it said it wanted the FBI to remove an advisory issues in the spring that warned the group was known to harass victims and family members with threats or coercion, which ShinyHunters said was inaccurate.

After threatening to publish the FBI data, in a Monday statement, the group said it did not plan to publish the information after all, and the hack had been a “marketing campaign” whose goals had been “widely… accomplished”.

The hack stole data from an Oracle PeopleSoft database used in the FBIJobs.gov portal, and affected people who used the portal to apply for a job with the FBI.

The portal has been the primary way for people to apply for a position with the bureau since 2017, according to ABC News.

Original source FBI Acknowledges Major Breach Of Employee Data

Back to home