The US Federal Bureau of Investigation has opened an investigation into a possible cyberattack on its recruitment portal after a hacking group calling itself ShinyHunters said it had seized personal data belonging to thousands of bureau employees and job applicants, potentially creating security and intelligence risks if its claims prove accurate.
The group announced the breach on Tuesday, saying the data it obtained included the names of former clients and job applicants, along with home addresses, telephone numbers, spouses’ names and some medical information. The hackers addressed a message to bureau director Kash Patel and its cyber-security official, claiming to possess data on ‘approximately’ all employees and job applicants.
Bureau opens investigation into recruitment portal breach
The bureau acknowledged the breach claims and said it had begun investigating them. The possible point of entry has not yet been determined, nor whether it was at an external provider or within the FBI’s own systems. The jobs portal remained offline on Wednesday after a message appeared on it the previous day saying the group had ‘seized’ the site.
ShinyHunters provided media outlets with a sample of the allegedly stolen data containing identifying information on about 5,000 employees. Some elements of the sample could be verified by comparing them with publicly available information and data that had appeared in previous leaks, strengthening the possibility that part of it was genuine without establishing the scale of the breach or the source of the data.
Leaked sample reveals data on about 5,000 employees
Bureau officials sent staff a memo on Tuesday warning them about the group’s claims and urging them to take steps to protect their personal information. The FBI has about 37,000 employees, potentially widening the risks if it is confirmed that the hackers obtained data covering a large proportion of employees and applicants.
ShinyHunters linked the attack to a warning issued by the FBI last May describing it as a criminal group specialising in stealing large amounts of data and extortion. The group said it was offended by that description and demanded that the bureau correct or remove the warning within a week.
The hackers denied that obtaining money was the aim of the attack, but did not specify what step they might take if the bureau rejected their demands. FBI officials, meanwhile, confirmed that the possible breach was under investigation, without determining whether the claims about the scope of the data or how it was transferred were accurate.
Risks of targeting agents and their families grow
The concerns arising from the possible leak go beyond the disclosure of personal information. Officials and experts warned that access to home addresses, telephone numbers and family links by foreign intelligence services or criminal groups could enable them to target agents or pressure them, posing a risk to public security and counter-intelligence operations.
Cynthia Kaiser, a former FBI official, said the greatest concern was that the data could be used to physically target agents and their family members by criminals who held grudges against them. Experts said the leaked information could also provide a map for those seeking to spy on or retaliate against bureau employees.
Previous breaches target systems linked to the bureau
The alleged breach follows previous incidents targeting cyber infrastructure linked to the bureau. Authorities earlier discovered Chinese hackers inside a database connected to domestic surveillance orders, in the aftermath of breaches that affected US telecommunications networks.
Personal emails belonging to bureau director Kash Patel were also hacked and leaked last March in an attack attributed to an Iran-aligned activist group. The new claims concerning the recruitment portal add to those incidents as the bureau continues to determine the possible source of the breach and the authenticity of the data presented by ShinyHunters.