The hacking group behind a massive FBI data breach says it will not publish the information it obtained, but cannot guarantee what will happen with the data it already shared.
ShinyHunters claimed responsibility for stealing a massive trove of data from the FBI last Tuesday — including officials’ job assignments, addresses and social security numbers — and gave the law enforcement agency one week to rescind an unflattering statement about the group.
With the deadline approaching, a ShinyHunters representative sent CBC News a statement Monday saying they were never planning to release the sensitive data, adding that the media and the public have “made many false assumptions and wild speculations.”
The group has been linked to dozens of cyberattacks targeting large companies and institutions. ShinyHunters typically demand ransom payments in exchange for not releasing sensitive data, but they have been adamant that was not their intention in this case.
Campaign to ‘combat disinformation’
ShinyHunters denied asking the FBI for a ransom, but acknowledged “past operations” could leave them open to misinterpretation.
“The reason why we have stated multiple times that this is not extortion is because since the very beginning we had made our decision that we would never publish this data. We have never intended to nor have we ever planned to,” the statement said in part.
The group told CBC News that their actions against the FBI were part of a campaign to “combat disinformation” about their tactics.
“If we made this statement normally then this much attention to our words and intentions would’ve never been this widespread. We’d have been ignored and disregarded. However, now everyone knows what the issue is and what we are doing.”
ShinyHunters took issue with an FBI report from May that said, among other things, the group is known to threaten family members of its targets and threaten to release embarrassing or compromising images of its victims.
ShinyHunters denied ever using those tactics and released a statement following last Tuesday’s data breach giving the FBI one week to remove or “correct” the report.
The group shared a 5,000-line spreadsheet of breached FBI data with some journalists, which it said represented only a small piece of its claimed two- to three-terabyte trove.
The sample included names, addresses, telephone numbers, dates of birth, social security numbers and emergency contact details for what it claimed were thousands of FBI employees.
When CBC News asked ShinyHunters on Monday whether they have taken any steps to ensure the shared data isn’t leaked by other sources, the representative said they “cannot guarantee” what will happen to those samples, “because that is out of our control and certain journalists violated our trust.”
‘Can’t trust them,’ researcher says
Ian Lin, an ethical hacker and head of research and development at Toronto-based cybersecurity company Packetlabs, says that’s concerning.
He says he’s seen “a number of researchers” claiming online to have obtained the data, in addition to journalists.
“There’s going to be people that are willing to pay a high price for this data,” Lin told CBC News.
The hack, which one former FBI operative called a “foreign intelligence service goldmine,” has raised concerns about the safety of the agency’s employees.
The New York Times reported Monday that the FBI sent out a staff memo acknowledging employees had personal information stolen in a cybersecurity incident, and instructing them to remain vigilant at home and at work and report any unsolicited contacts or threats.
Lin says he does not have high hopes ShinyHunters will keep their word, saying it’s common for criminal hacking groups to renege on their promises or to use the same set of data as leverage multiple times.
“Why they did this, I think was for attention. But you still can’t trust them to keep safe your data. Because now this is leverage over the law enforcement and FBI. And at any moment they could choose to use this data for their own additional purposes,” he said.
“The FBI and law enforcement should all still remain vigilant. There should be massive lessons learned from the FBI side.”
Click Here For The Original Source.
