
During the past year, the cybercrime group ShinyHunters has been extorting companies and, last week, took over a rival gang’s leak site. Now, it has gone after the agency that warned the public about it.
The FBI stated on Tuesday that it is investigating a possible breach of its online jobs portal after the cybercrime group said it had stolen data on FBI agents and those who had applied for positions at the bureau.
“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” the bureau said in a statement.
The breach was first reported by 404 Media, which received a sample covering 5,000 purported agents, including names, home addresses, phone numbers, and details of their spouses.
Two people with knowledge of the breach told that investigators consider the claims credible and view the incident as a significant counterintelligence failure.
“It’s really bad,” one said.
It is still unclear how the group gained access. According to the same source, the attackers seem to have exploited a vulnerability in Oracle PeopleSoft, a human resources software platform.
ShinyHunters told 404 Media that it had used a previously unknown flaw, but the source added that investigators have not verified this.
Politico noted that the group used a PeopleSoft zero-day against other organizations in June, a vulnerability that Oracle later patched, so it is possible that they reused that exploit on a system that had not been patched.
Unusually for a criminal group, ShinyHunters says it wants a correction rather than money.
In May, the FBI published an alert describing the group’s methods, after an attack on the Canvas learning platform knocked thousands of schools and universities offline.
The hack, the group said, was meant to force the bureau to “correct or simply remove” it.
Cynthia Kaiser, a former deputy assistant director of the FBI’s Cyber Division, told the attack was
“[…]very atypical behavior for ransomware gangs, but goes to show you the unpredictability and immaturity of the group.”
This is the second major breach of FBI systems this year, following a breach in which China-associated hackers gained access to a wiretapping system in April.
The group wished for the FBI to cease referring to it, and for the moment has given the bureau a great deal more to say.