ShinyHunters claims hacking FBI data: All you need to know about the cybercriminal group and its other victims | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Cybercriminal group ShinyHunters has claimed that it breached the Federal Bureau of Investigation (FBI) and stole sensitive data on thousands of agents and job applicants. In a statement on a dark web leak site, the group said that it had gained access to information related to “almost all FBI agents”. The FBI said it is aware of claims about unauthorized access on its jobs site and is investigating the alleged breach.

ShinyHunters was able to breach FBI data by hacking into an Oracle PeopleSoft server used to manage human resources and recruitment, TechCrunch reported. The group said it stole terabytes of information from an Amazon-hosted government cloud, where FBI data on agents and applicants are stored. ShinyHunters has said there is no financial motive behind the attack, demanding the FBI to take down a report which the group said includes inaccurate allegations against it.

What is ShinyHunters?

According to the FBI, ShinyHunters is a cybercriminal group “specializing in large-scale data breaches and extortion.” The group is known for attacking major companies across domains including technology, finance, and retail, often stealing millions of records in one go.

When did ShinyHunters originate?

ShinyHunters first came into the limelight in 2020 and claims to have successfully attacked dozens of victims so far. The group is mainly after money, but has also been causing reputational damage to its victims. Researchers believe the group may have originated either in 2019 or 2020.

Who have been victims of ShinyHunters?

In the past, ShinyHunters has targeted companies through vulnerabilities within cloud applications and website databases. By targeting customer management providers such as Salesforce, cybercriminal groups such as ShinyHunters can gain access to rich data sets from several clients in a single attack. Some of the biggest companies that have been affected in attacks by ShinyHunters are Ticketmaster, Wattpad, Tokopedia, BigBasket, and AT&T.

Who are members of ShinyHunters?

According to a report by The Conversation, there might be a significant overlap of membership between ShinyHunters and other cybercriminal groups such as Scattered Spider and Lapsus$. All these groups are international, and their members operate on the dark web from various parts of the world. Experts believe that ShinyHunters operates as a loose network of cybercriminals rather than a tightly-organised gang.

Add ET Logo as a Reliable and Trusted News Source



Click Here For The Original Source.

——————————————————–

..........

.

.