Internal memo: FBI said it is "operating under the premise" that a threat actor stole PII of all employees; ShinyHunters set a Tuesday deadline tied to demands
First reported by NYT ·
Your personal data, if you are an FBI employee, has likely been exposed and may be used for future attacks.
Dutch police arrested Pepijn van der Stap, a 24-year-old convicted cybercriminal, on suspicion of aiding the hacker group ShinyHunters. Following his arrest around September 16th, ShinyHunters claimed responsibility for stealing personal information of FBI employees from the FBI's job application site, apply.fbijobs.gov. The stolen data, including Social Security numbers and sensitive medical files, affected over 5,000 officials. ShinyHunters exploited a zero-day vulnerability in Oracle's PeopleSoft software, a platform used for HR and hiring, which was later patched. The group also claimed a data breach of over 6.2 million Dutch citizens from Odido, the country's largest mobile provider. An internal FBI memo indicated the agency is operating under the premise that a threat actor stole PII of all employees. ShinyHunters has set a Tuesday deadline tied to demands, though the specific demands are not detailed. The group also taunted the Cl0p ransomware group and the FBI through social media posts, including memes depicting the 9/11 attacks.
The FBI's internal acknowledgment of a data breach affecting all employees, coupled with the specific targeting of PII and sensitive medical files, signifies a significant escalation in the capabilities and audacity of threat actors like ShinyHunters. This breach, originating from a vulnerability in widely-used Oracle PeopleSoft software, highlights the persistent risks associated with legacy HR systems and the sophisticated methods threat actors employ to bypass security measures, even those designed by major security firms like Mandiant. The group's subsequent threat and deadline underscore a direct engagement with and challenge to law enforcement and federal agencies, indicating a new phase of cybercrime where data exfiltration is directly tied to explicit demands and potential further exploitation against government entities.
The internal memo regarding the FBI breach and the simultaneous targeting of a major telecommunications provider suggests a pattern of high-impact, broad-reaching cyberattacks that prioritize sensitive personal information. The FBI's confirmation and the subsequent demands set a new precedent for the types of entities and data that are vulnerable, moving beyond typical corporate espionage or financial gain to direct attacks on government personnel. This incident, alongside the Odido breach, indicates a strategic focus on entities that hold vast amounts of sensitive, PII-rich data, potentially setting the stage for future attacks that leverage this stolen information for extortion, identity theft, or even national security risks.
AI-written summary. May contain errors.