The data breach is in retaliation for alleged disinformation published by the FBI about ShinyHunters’ cybercrime methods, according to the group.
Cybercriminal group ShinyHunters said it breached the US Federal Bureau of Investigation (FBI) yesterday (22 September) and stole the personal information of a number of current and former FBI employees.
A screenshot shared by the group with a number of outlets reportedly showed information ShinyHunters had obtained on 5,000 FBI agents, including names, addresses, phone numbers and details on the employees’ spouses.
Reuters said it could not verify whether the screenshot was real, but was able to partially verify the authenticity of some of the information displayed – the outlet was able to match details from the leak to FBI employees in at least 10 instances, one of which was FBI director Kash Patel.
However, the publication said it could not establish where the data came from, or whether it had been stolen from the FBI’s internal systems as claimed by ShinyHunters.
According to 404 Media, which cited an FBI spokesperson, ShinyHunters was able to instigate the breach through a zero-day exploit in an Oracle product called PeopleSoft, after which the group managed to access AWS GovCloud servers and download data. The total exfiltrated data amounts to between 2TB and 3TB, according to the publication.
In a statement first posted to the group’s website on the dark web, ShinyHunters said it had targeted the FBI due to a report the agency published about the group earlier this year, which detailed the group’s methods and advised people not to pay if targeted for ransom.
ShinyHunters said the FBI made false allegations about the group and its cybercrime methods in the report – including alleged usage of threatening phone calls and false claims of compromising information – and has given the FBI one week to “correct or simply remove” the report.
It’s unclear what the group plans to do with the data if the one-week deadline passes. When asked by BleepingComputer if it would release the stolen data if the FBI failed to correct or remove the report, ShinyHunters said: “No comment.”
Commenting on the FBI breach, Closed Door Security CEO William Wright told SiliconRepublic.com: “Hell hath no fury like a ShinyHunter scorned.
“This is a retaliation attack, which not only demonstrates that no organisation is safe from the group, but also the fact that they will go to any length to protect their image.
“The group clearly wants to control the narrative around their activities, ensuring nothing is said that could dent their reputation. Just like any organisation, reputation is everything, even in the dark and unruly world of cybercrime.”
Wright also said Oracle needs to act fast to mitigate the zero-day vulnerability that allegedly allowed this breach to occur.
“It is essential Oracle takes steps to understand the [exploited] CVE [Common Vulnerabilities and Exposures] and whether it is already known to them. If not, an emergency update is essential,” he said.
“Any gaps between this announcement and a patch being released will only leave organisations vulnerable. Other threats actors will use the gap to exploit the CVE and launch further attacks.”
ShinyHunters has been linked to a number of high-profile breaches in recent months.
In March, the prolific group claimed responsibility for a breach of the European Commission’s Europa.eu platform, in which a reported 350GB of data, across multiple databases, was accessed and stolen.
In May, ShinyHunters claimed responsibility for hacking education management platform Canvas and issued a ransom to Canvas parent company Instructure. Some days later, Instructure reached an agreement with the group.
Recently, ShinyHunters targeted rival cybercrime group Clop by hacking and defacing its ransomware leak site in an escalation of a dispute between the two groups.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.










You must be logged in to post a comment Login