The FBI said it is investigating a possible breach into its online jobs portal, after a prolific cybercrime group publicly claimed to have stolen personal information of FBI personnel.
“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” the FBI National Press Office said in a statement.
Confirmation of an ongoing investigation came hours after a cybercriminal group known as ShinyHunters posted a message online claiming it had stolen “very sensitive” data on “almost all” FBI agents, as well as those who had applied for jobs at the bureau.
The group provided a sample of stolen data affecting 5,000 supposed FBI agents to 404 Media, which first reported on the alleged hack. The sample data set included agent names, home addresses, phone numbers and information on agents’ spouses, the outlet said.
Two people with knowledge of the breach said investigators believe the group’s claims are credible, and amount to a significant counterintelligence failure. Identifying information on even a handful of agency personnel could be used to threaten or harass active FBI agents or their families, and would be of interest to foreign intelligence services and violent criminal gangs.
“It’s really bad,” said the first of the two individuals, who was granted anonymity due to the sensitivity of the situation.
The FBI’s job website also appeared to have been affected by the breach, with the site on Tuesday afternoon featuring a “system unavailable” banner.
The suspected hack follows another major breach of a sensitive FBI system this year. In April, hackers linked to China broke into an FBI wiretap system, in one of the most serious intrusions inside agency systems in years, POLITICO reported at the time.
In the post, ShinyHunters did not specify what systems or databases it claimed to have breached, how much data it stole, or what time period the data covered.
The first individual with knowledge of the breach said they appeared to have used a vulnerability in Oracle PeopleSoft, an application commonly used in human resources departments. A representative for the group claimed to 404 Media that they hacked into PeopleSoft using a previously unknown software vulnerability — or zero-day — though the first person with knowledge of the breach said investigators had not yet determined if that was the case.
In June, ShinyHunters used a then-unknown zero-day bug in a campaign of attacks targeting organizations running PeopleSoft. But Oracle later fixed the bug, so it is possible the group reused the same exploit on a system the FBI failed to patch or ShinyHunters found a different way altogether into the system.
Investigators are still trying to determine that, the first person said.
ShinyHunters is a prolific cybercriminal group, and has been increasingly active this year. The FBI in May put out a public service announcement outlining the hacking group and its tactics, which was released after ShinyHunters attacked the Canvas learning system, leaving thousands of schools and universities temporarily offline.
The statement from ShinyHunters took issue with the PSA, and claimed that the breach was carried out to force the FBI to “correct or simply remove” the alert, strongly denying any claims that ShinyHunters carried out sextortion schemes against victims.
Spokespeople for the Justice Department did not respond to a request for comment on the breach. A spokesperson for the Cybersecurity and Infrastructure Security Agency — the nation’s cyber defense agency — declined to comment and referred POLITICO to the FBI.
The group also published stolen data of Madison Square Garden customers online for anyone to download earlier this year, and was blamed for a breach of the European Commission’s cloud infrastructure earlier this year. Anthropic this month published evidence of ShinyHunters carrying out data theft operations against unnamed victims.
Cynthia Kaiser, former deputy assistant director of the FBI’s Cyber Division, told POLITICO on Tuesday that the “retribution” style attack on the FBI was “very atypical behavior for ransomware gangs, but goes to show you the unpredictability and immaturity of the group.”
On the targeting of her former agency, Kaiser noted that “unfortunately, cybercriminals have consistently targeted law enforcement to learn more about their investigations and target the people behind them.”