FBI says leader of hacking group that stole personal data from federal jobs site arrested in the Netherlands | #cybercrime | #infosec


The group reportedly stole personal data on thousands of FBI agents, along with that of anybody who has used the jobs site to apply for the bureau.

WASHINGTON — FBI Director Kash Patel announced Tuesday that alleged hackers accused of stealing personal data from the agency’s jobs website were arrested in the Netherlands, days after news of the hack temporarily shut down the site.

“This morning (the FBI) and our partners the Dutch National Police are announcing the arrest of one of the alleged leaders of ShinyHunters – a global cybercrime and threat actor group linked to cyberattacks in the United States, the Netherlands, and around the world,” Patel said in a post on X.

On Sept. 24, the FBI said that it was investigating a criminal hacking group’s claims that it had stolen “very sensitive data” belonging to thousands of agents and applicants and that it had compromised the bureau’s jobs website.

The group, believed to go by the moniker “ShinyHunters,” claimed responsibility for the attack on the FBI jobs website, the main portal for prospective employees to learn about the FBI and initiate the application process. 

The group reportedly stole personal data on thousands of FBI agents, along with that of anybody who has used the jobs site to apply for the bureau. 

“We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,” said the ShinyHunters message, which was directed to Patel and Brett Leatherman, the assistant director in charge of the bureau’s cyber division.

The alleged leader of the group arrested in the Netherlands was not publicly identified in Patel’s message, but he said the investigation was ongoing and more arrests could come soon. 

“In coordination with FBI investigators the Dutch High-Tech Crime Unit arrested the suspect under Dutch law,” Patel said. “As we speak FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest.”

The hackers sought retribution over an FBI advisory

Miriam Wugmeister, a lawyer specializing in data, privacy and cybercrime who tracks hacking outfits like ShinyHunters, said that based on the group’s past practices, there was reason to believe the hackers’ claims, “so I think it’s likely that they were able to compromise this website and they got some data.”

Wugmeister said that though the data that appeared to be compromised was the type of personal information that is routinely accessed during a breach, the hack nonetheless had alarming national security implications given that it could expose agents and their families to extortion, swatting and other harassment and because the identities of spouses were also said to have been obtained.

“Even if the agents and the analysts and the employees are sophisticated, you worry about their families, too,” Wugmeister said.

In its message, ShinyHunters said it would give the bureau one week to correct or remove what it said were false allegations contained in an FBI public advisory from May that described the organization as a “cyber criminal group specializing in large-scale data breaches and extortion.”

That advisory characterized ShinyHunters as “threat actors” who often “use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims,” commonly harass or threaten victims and “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”

ShinyHunters said in its message to the FBI that it was “offended” by those characterizations and demanded that the FBI remove those claims. It did not say what would happen if the FBI did not do so within a week.

“This is not a ransom, coercion, or extortion. Your federal policies do not apply here. This PSA is NOT financially motivated,” the hacking group’s message said.

ShinyHunters has a reputation for “causing trouble and being disruptive,” Wugmeister said, as evidenced by the group’s involvement in a hack last spring of Canvas, an online system used by thousands of schools and universities. The breach created chaos as students tried to study for finals and prompted the FBI’s advisory that ShinyHunters is now objecting to.

The Associated Press contributed to this story. 



Click Here For The Original Source.

——————————————————–

..........

.

.