FBI rushes to investigate if ShinyHunters hack of thousands of employees is real
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav The FBI is now investigating claims from a hacker group that thousands of current and former employees’ personal data was stolen after the group exploited a previously unknown bug found on an agency jobs website. On Tuesday, 404 Media reported that ShinyHunters took down the agency site, FBIJobs. gov, then posted a banner on the homepage that said “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.” About two to three terabytes of data were taken, ShinyHunters told The New York Times. None of the data has been leaked yet, but it included “names of current and former agents as well as applicants and corresponding home addresses, phone numbers, names of spouses, certain medical information, and other data.” According to Bloomberg, the data could be used to potentially retaliate against agents, with one sample appearing to include “potentially sensitive professional information on the FBI employees’ work focus such as counter-intelligence work on China, Russia and Iran, as well as work against street gangs.” The group’s motive was not to extort the FBI or seek a ransom, it claimed. That “never” happens, ShinyHunters said. To get the advisory changed, ShinyHunters told FBI director Kash Patel and the assistant director of the FBI Cyber Division, Brett Leatherman, that they had one week to comply with demands or presumably risk a breach of sensitive employee data. FBI warns employees to be safe Not many details have been released on how ShinyHunters got access to the data. ShinyHunters would only tell NYT that “it had weaponized a zero-day, or previously undiscovered, computer bug within the Oracle PeopleSoft software, an application that companies use for human resources and financial management.” So far, Oracle is silent on that bug, reports said, while ShinyHunters said it plans to continue using the zero-day for its “businesses’ normal operations.” The FBI has not confirmed that the hack occurred, but it has begun probing the claims. Ashley Belanger Senior Policy Reporter Ashley Belanger Senior Policy Reporter Forum view Prev story Next story 1. Owners mourn spoiled food after firmware update bricks Samsung smart fridges 2. Aftermarket driver assist under federal probe following fatal crashes 3. Woman's brain worm infection confirmed after eggs grow tails in lab test 4. A new report from Europe raises serious alarms about orbital collisions 5.
Original story by Ars Technica • View original source
Anonymous Discussion
Real voices. Real opinions. No censorship. Resets in 15 hours.
About NewsBin
Freedom of speech first. Anonymous discussion on today's news. All content resets every 24 hours.
No accounts. No tracking. No censorship. Just honest conversation.
Loading comments...