The FBI is investigating a cyberattack on its jobs portal after the cybercrime group ShinyHunters said it hacked the system and stole a vast trove of sensitive data from the bureau.
“The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII),” the bureau said in a statement on Wednesday. “While the point of breach is still undetermined—whether a third-party or the FBI’s enterprise—we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.”
In a statement posted to its dark-web leaks site, ShinyHunters said it had stolen “very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job.” It listed several “FBI services” that it claimed to have hacked: “Criminal Justice (CJ), HR, Medlink, and more.”
ShinyHunters told 404 Media that it hacked into the jobs portal using a zero-day vulnerability in Oracle’s PeopleSoft human-resources platform, a tactic it has used before. The potentially wide-ranging breach highlights the supply chain risks facing organizations of all sizes and levels of sophistication. ShinyHunters specializes in supply chain attacks, and its intrusions have illuminated weaknesses in the security protocols at widely used software and infrastructure providers.
404 Media confirmed that a sample of stolen data provided by ShinyHunters included agents’ sensitive personal information. People familiar with the breach described it to Politico as a major counterintelligence failure that could lead to the harassment or stalking of FBI agents. Foreign governments could also use FBI employees’ personal data to monitor them and undermine their investigations and operations.
The FBI’s jobs portal is currently offline and displays a banner explaining that the site is unavailable.
It is unclear whether the PeopleSoft vulnerability that ShinyHunters allegedly exploited is a zero-day or a previously disclosed flaw, such as the one Oracle disclosed in June after ShinyHunters exploited it. Oracle did not respond to a request for comment.
ShinyHunters claimed that it conducted the attack in retaliation for the FBI’s descriptions of the group’s activities in a May bulletin. That advisory “made substantial false allegations,” the group wrote. “We have been severely offended.” ShinyHunters demanded that the FBI “correct or simply remove” the offending lines from its bulletin.