
Click the link below the picture
.
The theft by a criminal hacking group of reams of sensitive personal data involving potentially tens of thousands of former and current F.B.I. employees is emerging as one of the worst breaches of sensitive government information, leaving the bureau rushing to protect its personnel as an uncertain deadline loomed.
Nearly a week after the group, known as ShinyHunters, revealed it had pilfered intimate details about bureau personnel from the agency’s jobs portal and threatened to leak them online, F.B.I. investigators are still piecing together how the breach took place and the total damage.
The hack appears to have swept up home addresses, Social Security numbers, secretive job assignments and much more, according to a New York Times analysis of some of the records. Some are already comparing it to China’s breach of more than 20 million records from the Office of Personnel Management over a decade ago, considered so catastrophic that officials and lawmakers vowed to never let something like it happen again.
Many F.B.I. employees first learned about the hack when news reports about it surfaced on Tuesday, according to current and former officials. The next day, F.B.I. staff received an email reminding them that October is cybersecurity awareness month, which struck some as tone deaf in light of the breach, one of those people said.
On Friday, bureau leaders, in an internal memo to its rank and file, declared the hack a cybersecurity incident and acknowledged its employees had personal information stolen.
“We are operating under the premise that the threat actor is also exfiltrating PII of all F.B.I. employees,” according to the memo, which was described by someone who had seen it, using the abbreviation for personally identifiable information.
The memo said the agency would offer virtual briefings in the weeks ahead and instructed employees to remain vigilant at home and at work, report any unsolicited contacts or threats, avoid answering calls from unknown numbers and set up voice mail accounts with A.I.-generated voices. “Bureau leadership remains committed to supporting the safety of you and your family,” it said.
Still, many past and present personnel remain in the dark about whether their data has been purloined. In recent days, some have anxiously asked Times reporters whether their names are contained in the hacked data, wondering whether they needed to take steps to protect themselves or their families.
In a statement on Monday, the agency said it was “working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted — including multiple bureau-wide communications within 24 hours of public reporting.”
It added, “The F.B.I. treats the security of its information and the safety of its work force as top priorities, and our investigation is ongoing.”
In announcing its hack, ShinyHunters, believed to be a loose collective of young hackers operating across the globe, said it had targeted the F.B.I. as retribution for a public advisory the bureau had issued in the spring, warning that the group was known to harass victims and family members with threatening or coercive maneuvers. In their note, the hackers demanded that the F.B.I. “correct or simply REMOVE” the advisory or risk further consequences.
In an email to The Times on Friday, ShinyHunters said that the bureau had until the end of Tuesday to fulfill its request, even as the hackers themselves appeared to acknowledge that the bureau was unlikely to acquiesce.
That note left open the possibility that the hackers would not dump the data online, even as the group reiterated its deadline. But on Monday, in a new statement, the group claimed it never intended to do so.
“Since the very beginning we had made our decision that we would never publish this data,” the group said. “We have never intended to nor have we ever planned to.” It added that the hack and threat to the F.B.I. was a “marketing campaign to protect our business” and said that “we are not taking any further actions” with the data, including revealing more about what is contained in the files.
“We seek no escalation as our goals have widely been accomplished,” it said.
It remains to be seen what ShinyHunters will do, and security researchers warned that even if they did not publish it online they could still sell it to other criminals or foreign governments.
It is also unclear just how much sensitive information the hackers stole. The group claimed publicly to have stolen records on everyone who has applied for a job at the F.B.I., and told The Times that the people with compromised information numbered in the tens of thousands.
Ciaran Martin, the former head of Britain’s cyberdefense agency, said the F.B.I. hack likely had “huge impact on the operational capability” of the bureau and could rank as one of the most consequential data breaches in history — graver even than the Office of Personnel Management burglary.
“Losing the data on 20 million federal employees to the Chinese was bad,” Mr. Martin said. “But you knew the Chinese weren’t going to sell or publish it.”
A sample of records that the hackers have shared with The Times and other news organizations includes newer hires as well as retired ones, with birth dates ranging from the early 1940s to the mid 2000s. The most recent date references in the spreadsheet were from late April, suggesting the stolen files are at most only months old.
Current and former U.S. officials said that at least portions of the sample, and potentially all of it, appeared to be authentic.
A Times review of the sample found that it contained a range of private personal data, including:
The names, home addresses, phone numbers, work emails, Social Security numbers and birth dates and hire dates of current and former F.B.I. personnel.
Names and numbers for spouses and other emergency contacts, including in some cases parents, siblings and even children.
Employee identification numbers that are used for the Transportation Security Administration’s PreCheck program, which could aid spies in tracking travel itineraries of agents, including those that work undercover.
Names of the units in which F.B.I. personnel are employed and their job titles, as well as the names of supervisors. While some list mundane departments, others reveal extraordinarily sensitive assignments including counterintelligence, narcotics and various desks focused on Russian, Chinese and Iranian national security threats. F.B.I. agents in those roles are generally expected to zealously protect their work in such fields to avoid putting a target on their back.
Additionally, ShinyHunters said that it had stolen medical data about employees, including psychiatric records and documents related to blood and urine tests. It also said that it had additional background check files on employees.
Former bureau officials and security experts said the hacked data prompted no end of worries. The data could also make it far easier for violent criminals to seek revenge against F.B.I. agents who sent them to prison. When they submit paperwork against criminal suspects, F.B.I. agents sign their names to the records but are typically trained to not let delicate personal information easily emerge online.
“It doesn’t take much imagination to picture scenarios where employees or their families could be threatened or harmed by this kind of information being released,” said Andrew Brandt, a threat intelligence researcher at the cybersecurity company Huntress. “The bigger worry is ShinyHunters selling the data to other criminal or nation-state groups who could put it to more damaging use, rather than dumping it themselves.”
.
A criminal hacking group known as ShinyHunters said it had targeted the F.B.I. as retribution for its public warning in the spring that the group was known to harass its victims and their family members. Credit…Tierney L. Cross/The New York Times
.
.
Click the link below for the complete article:
.
__________________________________________
Leave a comment