Current and former FBI agents have expressed concern following a hack that has reportedly exposed the private and personal information of the agency's entire workforce. A former FBI agent stated, "This is really bad for our undercover agents," highlighting fears for the safety of colleagues. Agents are worried that their personal information could be made available online to criminals and hostile nation-state hackers, potentially leading to targeted attacks or phishing scams.
The hacking group ShinyHunters has threatened to publish the stolen databases and documents within four days unless its demands are met. Some agents are also concerned about the risk of physical attacks from cyber criminals they have previously investigated. A former agent noted discussions in a group chat about potential "violence-as-a-service" attacks from young online gangs, who could use the information to harass FBI agents involved in their cases.
ShinyHunters, believed to be an English-speaking gang, claims to have breached FBI systems on Monday and posted details of the attack on its darknet site. The FBI has not yet responded to requests for comment but acknowledged the breach on Wednesday, stating it is "aggressively investigating" how it occurred.
Michael McPherson, a former FBI agent and current senior vice president of security operations at cyber firm ReliaQuest, described the hack as a significant security threat that could impact agent safety and their families. He noted that the incident reportedly includes personal data such as home addresses and contact information, which could expose family members to threats.
ShinyHunters shared samples of the alleged stolen data with reporters, which appear to include names, addresses, phone numbers, badge numbers, job titles, and information about spouses. The records reportedly relate to thousands of agents, including senior officials such as deputy directors. The criminals also appear to possess sensitive medical information related to special agents, including details from "fitness-for-work" medical examinations.
Cynthia Kaiser, a former Deputy Director of Cyber at the FBI, stated that ShinyHunters may have already lost control of some of the data circulating in various online groups, which could lead to harm even before the main tranche is published. She noted that the repercussions of such breaches can persist for years on the dark web.
Concerns have also been raised about the breach's national security implications, as staff may become targets for recruitment by foreign intelligence services. Many agents expressed anger at the FBI for allowing the data to be stolen, with one former cyber agent describing the security failures that enabled the breach as "sloppy and lazy."
There is uncertainty about how to manage the fallout if the data is published next week, as the FBI is unlikely to comply with the hackers' demands. The hackers are not demanding money but want the FBI to retract an advisory published in May, which they claim "offended" them.
Former agents have reported widespread shock that such a breach could occur at a major law enforcement agency, emphasizing that this information should not be exposed on the internet. There is also embarrassment that a group of young cyber criminals has repeatedly managed to evade law enforcement while executing high-profile hacks. ShinyHunters has been linked to various extortion attacks, including those on Rockstar Games and the education platform Canvas.
McPherson stated that the FBI is taking the incident seriously and expects the agency to leverage its resources to address the attack. Kaiser warned the hackers to expect a significant effort by the FBI to bring them to justice.