ShinyHunters Hacks FBI Job Site, Threatens to Leak Agent Records

The FBI is investigating a breach of FBIjobs.gov after ShinyHunters defaced the site and claimed to have stolen records on agents and applicants.

ShinyHunters Hacks FBI Job Site, Threatens to Leak Agent Records

FBI Investigates Breach of Agent Hiring Platform by ShinyHunters

The Federal Bureau of Investigation is looking into a breach of its job applications website after the cybercriminal group ShinyHunters defaced the page and claimed to have stolen data on current and former employees and applicants, therecord.media reported Tuesday.

The group replaced official images on FBIjobs.gov with a photo of a Pokémon that has become ShinyHunters' de facto mascot. The hackers then posted a lengthy statement on their leak site threatening to release records on every FBI agent and job applicant unless the bureau removed a public service announcement it had issued earlier this year — one the group says falsely characterizes their conduct.

"The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," an FBI spokesperson told Recorded Future News on Tuesday evening. The agency did not respond to several other questions about the group's claims.

As of Wednesday morning, a banner on the FBI jobs site stated that the special agent application portal remained unavailable.

ShinyHunters provided samples of 5,000 allegedly stolen FBI agent records to 404 Media and several other news outlets, which confirmed their legitimacy.

Group Disputes FBI's Characterization

In its public statement, ShinyHunters pushed back against FBI assertions that the group had exaggerated the scope of stolen data and had extorted employees at companies it hacked.

"We wish to state unequivocally we have never conducted swatting attacks against corporate victims personnel nor have we ever texted victims personnel family members any threats," the group wrote. "We are not sextortionists."

The group also denied any affiliation with The Com, a broader network of young English-speaking hackers accused of various crimes targeting children online.

The FBI issued the public notice in May following ShinyHunters' attack on Instructure, the educational software company behind the Canvas platform used by thousands of universities and K-12 schools across the country. The attack disrupted operations at those institutions and ultimately forced Instructure to pay a ransom to restore services.

FBI "Focused" on ShinyHunters

The group has been under FBI scrutiny for nearly a year after a string of high-profile breaches at Ticketmaster, AT&T, educational publisher McGraw Hill, Carnival Cruise Line, 7-Eleven, and other major companies.

Brett Leatherman, assistant director of the FBI's Cyber Division, addressed the threat posed by ShinyHunters two weeks ago at a media roundtable. After securing arrests tied to a related cybercriminal group, Leatherman said the bureau is now "focused" on ShinyHunters "because right now it's a big problem when it comes to data exfiltration and extortion attacks."

Experts Warn of Broader Risks

Several cybersecurity experts said ShinyHunters is likely to publish the stolen data given that the FBI shows no indication of removing its alert.

"The bigger worry is ShinyHunters selling the data to other criminal or nation-state groups who could put it to more damaging use, rather than dumping it themselves," said Andrew Brandt, incident responder at cybersecurity firm Huntress.

Brandt cautioned that the exposed records involve law enforcement personnel who work with serious and dangerous criminals, sometimes requiring infiltration into criminal networks. "It could be abused in a multitude of ways, from financial fraud to serious threats of harm against staff and their immediate families, to future targeted attacks in cyberspace or the physical world," he said.

Source: NYT US News