Hacked FBI Data Exposes Sensitive Details on Employees

FBI

A trove of data allegedly stolen from the FBI includes detailed information about employees working on sensitive intelligence, counterespionage and security operations, Reuters reported Wednesday (Sept. 23).

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    The data, obtained by the hacking group ShinyHunters, includes a 5,000-line spreadsheet containing names, addresses, telephone numbers, dates of birth, Social Security numbers and emergency contact information for what the hackers said were thousands of current and former FBI employees, the report said. The spreadsheet also identified assignments to specific FBI field offices and, in some cases, sensitive units.

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    Reuters said in the report that it was unable to authenticate the entire spreadsheet but individually verified information for more than 22 people by cross-checking the data against credit records and previous data leaks compiled by the dark web intelligence platform District 4 Labs.

    Among the information were assignments involving China, Russia, Iran and Hezbollah, as well as cyber, surveillance and human intelligence operations, according to the report. The spreadsheet identified 14 employees working on China-related matters and nine in Russia-related roles, including positions associated with the FBI’s Russia Operations Section and work involving infrastructure and technology threats.

    The FBI said it was aware of a cybercriminal group claiming to have compromised the FBIJobs.gov portal and obtain employees’ personally identifiable information, per the report. The bureau said the cause of the alleged breach remained undetermined and that it is investigating the matter.

    ShinyHunters claimed Tuesday that it had breached the FBI and obtained data on many employees, according to the report. The group said it is holding the information hostage while seeking the withdrawal of a statement the FBI issued about the group in May. On Wednesday, the hackers said they were attempting to prevent the personnel information from spreading more broadly.

    The potential exposure extends beyond the employees themselves. Former FBI counterintelligence operative Eric O’Neill said information identifying personnel working against foreign intelligence services could be valuable to hostile governments, per the report. Another cybersecurity executive cited by Reuters expressed particular concern about the inclusion of emergency contacts, who may include family members with less experience handling sensitive information.

    The alleged breach underscores the potential consequences of compromises involving personnel systems. A system containing employee information can expose not only personally identifiable information but also details about how sensitive organizations are structured and staffed.