Signal

Internal memo: the FBI says it is "operating under the premise" that a threat actor stole PII of all staff; ShinyHunters set a Tuesday deadline tied to demands

First reported by NYT ·

The signal ●●●○ Compiled by AI from NYT, Techmeme, 404 Media, Krebs on Security, Silicon UK and 4 more
Why you might care

The FBI's systems are compromised, and all staff PII, including sensitive medical and psychiatric files, may be in the hands of threat actors.

What happened

Dutch police arrested Pepijn van der Stap, a 24-year-old convicted cybercriminal, on suspicion of aiding the hacker group ShinyHunters. Following his arrest, ShinyHunters allegedly stole sensitive data from the FBI's job application website, affecting over 5,000 staff members including personal information and medical files. The group claims to have exploited a zero-day vulnerability in Oracle's PeopleSoft platform, a widely used HR software. ShinyHunters set a Tuesday deadline tied to their demands, and the FBI is operating under the premise that all staff PII was compromised. Additionally, ShinyHunters claimed responsibility for extorting the Russian ransomware group Cl0p. Investigations suggest a shift in ShinyHunters' operations potentially influenced by a new leader from Jordan, who may be attempting to frame the arrested Dutch hacker.

What it means

The FBI's confirmation of a data breach, coupled with an internal memo stating they "operate under the premise" that all staff PII is compromised, signifies a significant security failure with broad implications for federal employees. The exploitation of a PeopleSoft vulnerability by ShinyHunters highlights a persistent threat vector targeting widely used enterprise software, suggesting that even patched systems may remain vulnerable through sophisticated evasion techniques.

This incident underscores the evolving tactics of cybercriminal groups like ShinyHunters, who are escalating from data theft to more aggressive extortion and potentially framing operations. The alleged takeover by a Jordanian cybercriminal associated with Scattered Spider and LAPSUS$ indicates a consolidation of threat actors and a potential increase in the sophistication and boldness of their attacks, warranting heightened vigilance across organizations relying on similar software.

AI-written summary. May contain errors.