Cybercrime group ShinyHunters claims it has hacked into the U.S. Federal Bureau of Investigation and stolen personal data for thousands of FBI staff.
The assertion came Tuesday in a statement on the group’s dark-web site and in an online chat with Reuters. The FBI did not immediately respond to requests for comment.
The attack was in response to a warning issued in May by the FBI that branded the group a cybercrime threat and recommended that potential victims refuse to pay ransom, according to ShinyHunters. The hackers also released what they said was proof of their hacking.
Reuters was able to partially check some of the information presented by ShinyHunters. In 9 instances or more, names and postal addresses were identical to the data in credit databases and data that had been exposed. But the checks were not able to confirm that the information had originated directly from FBI systems.
The agency’s jobs website was also disrupted. The FBI jobs website and a Special Agent Applicant Portal were not accessible, according to a message posted on the site, but Reuters could not independently verify that the outage was due to ShinyHunters.
The new allegations follow months after the FBI publicly issued a warning over ShinyHunters after an attack on an online learning-management platform.
The FBI’s Internet Crime Complaint Center (IC3) called it a cybercriminal organization in May that was engaged in large-scale data theft and extortion.
ShinyHunters had earlier taken responsibility for the hacking of Instructure’s Canvas platform, which is used by thousands of educational institutions.
A huge volume of student and staff data was stolen, according to Reuters, and the FBI reported that there was a cyber incident in the education sector at the time.
The FBI also noted in its May advisory that stolen information may be used in very targeted phishing attacks. Legitimate personal and organizational information can be used to make fraudulent messages seem more convincing.
Because of the nature of the information allegedly involved, the reported FBI incident is therefore significant. Information about law-enforcement personnel could pose further risk if the information is accurate and subsequently used for harassment, impersonation or targeted attacks.
Much uncertainty remains about the latest claim. ShinyHunters has made data-theft and extortion claims in the past, and the FBI has yet to make any public statement that its internal systems were hacked.
Reuters has limited information to verify, but some of the information seems to match real people, but not how the data was collected.
The incident also coincides with a surge in ShinyHunters’ activity. The group has been the target of cybersecurity researchers and government agencies due to its frequent attacks on companies with massive amounts of personal data.
At this time, the focus is not on whether ShinyHunters did indeed gain access to FBI systems, but on how much information they were able to obtain.
A statement from the FBI or additional independent confirmation of the alleged records would shed light on the incident.
