
FBI Warns ShinyHunters Crime Group for Hacking Agents’ Data After Arrest
Dutch authorities and the FBI announced Tuesday that Dutch law enforcement had arrested an executive of ShinyHunters, the international cybercrime group that last week claimed to have hacked an FBI website and stolen sensitive personal information about agents.
The bureau does not explicitly link Dutch’s arrest to the FBI hack, which appears to have occurred after the man’s arrest, but it uses it to warn other members of the ShinyHunters criminal network.
In a video statement posted on the FBI’s website, Cyber Division Deputy Director Brett Leatherman spoke directly to the hackers and urged them to confess to law enforcement.
“To other members of ShinyHunters: you have heard about your colleague’s arrest,” Leatherman said.
“Other groups thought anonymity or their friends would protect them and they were wrong. Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who stays,” he said. “I suggest you contact us first while the choice is still yours.”
Leatherman did not directly address the FBI hack in his message to ShinyHunters.
Earlier Tuesday, the Dutch National Police announced that they had arrested a 24-year-old man suspected of being a ShinyHunters hacker on September 15. She said she was under separate investigation on suspicion of ordering two killings abroad.
ShinyHunters is a prolific cyber extortion group with members from all over the world. It regularly hacks companies to steal sensitive data, then threatens to leak it to the dark web unless paid.
Last week, ShinyHunters announced on its website that it had hacked the FBI job portal and stolen important personal information about agents. The group asked the FBI to remove a public service announcement about the group posted in May. He gave until September 29 to do so, without explicitly specifying that he would publish the stolen data.
ShinyHunters breached the FBI on September 21, placing the hack after the Dutchman’s arrest. The group did not respond when asked about the arrest and Leatherman’s message.
Although the extent of what ShinyHunters stole from the FBI is unclear, a ShinyHunters spokesperson sent NBC News a sample document containing sensitive personal information about a former agent, which confirmed it was authentic.
According to a Justice Department notification to lawmakers obtained by NBC News, the FBI declared the matter a cybersecurity incident on September 22. He said the affected system held sensitive personal information, including Social Security numbers, dates of birth, phone numbers, addresses and emergency contact information, and that investigators were still working to determine how many people might have been affected.
ShinyHunters also claimed to have used its access to the FBI job portal to pivot and steal a cache of other information from several other agency programs, but did not provide proof of these claims.
The FBI sent a message to employees Friday saying they were working under the assumption that personally identifiable employee information may have been obtained, according to a person familiar with the matter, and that they should be vigilant and report any unsolicited contact. The person said some FBI employees were frustrated after hearing about the data breach through the media as well as what they saw as a slow response from the bureau.
“The FBI is working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be affected – including multiple Bureau-wide communications within 24 hours of the public report. The FBI considers the security of its information and that of its personnel to be top priorities, and our investigation is ongoing,” an agency spokesperson said in a statement.
On Monday afternoon, before the FBI’s announcement, ShinyHunters’ spokesperson told NBC News that the company was now committed not to release any of the data stolen from the agency. The spokesperson added a lengthy statement saying he was backing down from demanding the removal of the PSA.
“This was a marketing campaign to protect our business and actively combat misinformation,” the statement said.
“It wasn’t a threat. It may have been framed as a threat, but ultimately the public took this story out of context and made their own wild assumptions and speculations,” he said. “We are right.”
Gn headline