Credited from: LATIMES
The FBI is currently investigating a significant cyberattack on its jobs website, allegedly executed by the hacking group ShinyHunters. The group claimed to have stolen more than 2 terabytes of sensitive data, purportedly affecting "almost all FBI agents and individuals who applied for a job" with the bureau. The FBI has confirmed awareness of the unauthorized activity on its jobs portal, which has been taken offline as a precautionary measure, according to Indiatimes and LA Times.
According to ShinyHunters, the data leak comprises a wealth of personal information including names, addresses, email addresses, phone numbers, and sensitive details about the agents’ job roles and assignments, possibly linked to counterintelligence operations against various threats, including Chinese and Russian espionage, as stated in reports by Reuters and CBS News.
The hacking group also noted that it utilized a zero-day vulnerability in Oracle's PeopleSoft platform, a system used by the FBI for human resources management, to execute the data breach. They assert that this breach has exposed sensitive operational data and personal identification details of approximately 38,000 FBI personnel and applicants, a claim that remains under investigation, according to BBC and CBS News.
ShinyHunters claimed the breach was not financially motivated, but rather a response to an FBI advisory that categorized the group unfavorably. The group demands that the FBI retract this advisory within one week or face the consequences of full data exposure. This ultimatum emphasizes the group’s intent to challenge the FBI’s narrative regarding its operations, as highlighted by LA Times and Reuters.
The FBI has not independently verified the legitimacy of the stolen data as it explores whether the breach originated from its own servers or a third-party vendor. However, the agency is working closely with its partners to mitigate risks associated with the suspected breach, as reported by BBC and Indiatimes.