- Messages
- 3,996
- Likes
- 1,873
- Points
- 2,130
According to media reports, the FBI has launched an investigation into the incident following a claim by the hacker group ShinyHunters that the agency's HR system had been breached and the personal data of agents and job seekers had been stolen.
"We are actively and vigorously investigating this incident and are working closely with third-party service providers supporting FBIJobs.gov to minimize any risks," the FBI told the media.
The agency's press service added that agency specialists are aware of the hackers' reports of the alleged breach, but they have not yet identified the point of entry into the IT systems. The FBI believes that a third-party system supporting FBIJobs.gov was likely compromised. The agency also suspects a network attack directly targeting the agency's IT infrastructure.
As part of the investigation, all FBI employees were also sent a memo with recommendations on how to protect their personal data.
Previously, the hacker group ShinyHunters reportedly hacked the FBI's website and human resources cloud IT system and stole user data, including information about active agents. The hackers explained that their actions "are not for financial gain" and demanded that the FBI delete a report they claim contains false accusations against the group.
The data reportedly includes the names of FBI employees, their home addresses, phone numbers, information about their spouses and family members, and information about job applicants.
ShinyHunters explained that access to such sensitive data was made possible by a zero-day vulnerability in the Oracle PeopleSoft server platform, which is used by human resources departments and recruiters to store applicants' personal information. The hackers then moved on to hacking the FBI's cloud resources hosted on Amazon, where the data of agents and job applicants for the agency is stored.
After reporting the data breach, the hackers modified the FBI's job posting page. A message was displayed there for a while, similar to the one the agency posts on attacker websites after they are blocked
"We are actively and vigorously investigating this incident and are working closely with third-party service providers supporting FBIJobs.gov to minimize any risks," the FBI told the media.
The agency's press service added that agency specialists are aware of the hackers' reports of the alleged breach, but they have not yet identified the point of entry into the IT systems. The FBI believes that a third-party system supporting FBIJobs.gov was likely compromised. The agency also suspects a network attack directly targeting the agency's IT infrastructure.
As part of the investigation, all FBI employees were also sent a memo with recommendations on how to protect their personal data.
Previously, the hacker group ShinyHunters reportedly hacked the FBI's website and human resources cloud IT system and stole user data, including information about active agents. The hackers explained that their actions "are not for financial gain" and demanded that the FBI delete a report they claim contains false accusations against the group.
The data reportedly includes the names of FBI employees, their home addresses, phone numbers, information about their spouses and family members, and information about job applicants.
ShinyHunters explained that access to such sensitive data was made possible by a zero-day vulnerability in the Oracle PeopleSoft server platform, which is used by human resources departments and recruiters to store applicants' personal information. The hackers then moved on to hacking the FBI's cloud resources hosted on Amazon, where the data of agents and job applicants for the agency is stored.
After reporting the data breach, the hackers modified the FBI's job posting page. A message was displayed there for a while, similar to the one the agency posts on attacker websites after they are blocked