The FBI grapples with the aftermath of a massive data breach
A week after a group of cybercriminals claimed to have stolen sensitive personal data from thousands of current and former FBI employees, the bureau is still assessing the extent of the damage while facing internal criticism over the agency’s handling of the incident.
It is one of the most serious agency data breaches in years, but some FBI employees feel left in the dark about whether they are affected and disappointed by the security resources offered to victims, according to current and former officials.
“The direction is lost,” a former FBI agent in contact with his former colleagues told CNN. “They don’t provide any clear guidance to officers.”
The problem began a week ago, when hackers broke into an online portal hosting information on FBI applicants. Social Security numbers, emergency contact details and home addresses were included in the stolen data.
The hackers demanded that the FBI change a previous advisory posted about the group, saying they were “offended” by how the agency described its alleged extortion tactics from victim organizations.
Many people at the FBI and in the cybersecurity industry viewed the request as an unspoken threat that hackers would release the stolen data. (The cybercrime group now says it never planned to publish any of the stolen data, but it has a history of doing so with other victims).
The hackers responsible, known as ShinyHunters, have previously targeted “large companies in the technology, financial and retail industries, often stealing millions of customer records at a time,” according to the FBI’s advisory on the group.
In this case, the stolen data includes information about FBI personnel working in sensitive units focused on China and Russia, among other topics, according to sources who have viewed the data.
An FBI spokesperson said the bureau communicated with employees throughout the incident response process.
“Potentially affected FBI employees have received communications and notifications multiple times over the past week, as recently as Saturday,” the spokesperson said.
After discovering the hack, the FBI “immediately responded with a multi-divisional effort, all aimed at prioritizing incident response, pursuing suspected actors and data, engaging employees and partners, and more.” “, said the spokesperson. “The teams worked 24/7 on all of this. »
The breach was alarming news for FBI agents who rely on relative anonymity to work on the front lines of counterintelligence, terrorism and cybercrime. Some agents fear their home addresses will be made public, which could pose a security issue for their families while they travel, according to people familiar with the matter.
The scale of the breach also raised serious counterintelligence concerns. Officials fear that detailed personal data stolen by the hackers could be used along with other information compromised in previous breaches to identify officers in sensitive positions, according to several people briefed on the investigation.
Adversaries of foreign governments or drug cartels could use this information – if they were to acquire it – to try to identify agents who are working undercover or assigned specific roles of interest to them. The FBI will have to try to mitigate security risks for these employees, according to the sources.
Adversaries have used FBI data as a weapon before. A Mexican drug cartel hired a hacker to monitor the movements of a top FBI official in Mexico City around 2018, collecting information from the city’s camera system that allowed the cartel to kill potential FBI informants, according to a Justice Department inspector general report made public last year.
The FBI sent an email to staff about the incident on Friday, emphasizing the bureau’s commitment to the safety of employees and their families, according to people familiar with the message. He encouraged employees to report any safety or security concerns to FBI security personnel. The bureau assumes that the hackers stole data on all FBI employees, the message said. (The New York Times first reported on the email.)
It’s a blow to one of the nation’s leading cybercrime organizations, which is often called upon to help clean up hacks of Fortune 500 companies.
The FBI’s cybersecurity, security and victim services divisions are all involved in responding to the hack, according to people familiar with the matter. The goal is to give each employee the resources they need to face possible threats from hackers.
But, at least initially, some members of the workforce did not believe they would have access to these resources. FBI agents have turned to agency rumors to try to find answers about the breach that executives have not provided, a source said.
This story has been updated with a response from the FBI.
Gn headline