Skip to content

Product1 publisher3 min readPublished

ShinyHunters' no-leak promise leaves 2-3TB of stolen FBI data in its hands

ShinyHunters says it will never publish the 2-3TB of FBI data it took, allegedly through the agency's online jobs board. The agents whose records were taken still have to plan as if the files are loose, because the pledge covers only publication.

The Product Desk · Product desk

Photograph accompanying ShinyHunters' no-leak promise leaves 2-3TB of stolen FBI data in its hands
Photo: pcmag.com

What happened

  • The group had given the FBI a week to correct or remove a May alert about its tactics; the alert is still up, and ShinyHunters has deleted its original threats.
  • In what it called a final statement, ShinyHunters described the whole episode as a marketing campaign to protect its business.
  • The FBI has publicly said only that it is investigating, though an internal memo acknowledged employees' information was stolen, according to The New York Times.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Protective steps for affected agents have to be sized to the theft itself, since a plan that relaxes on the group's word would have to tighten again whenever the group changes its story.
  • precedent ShinyHunters credits the stunt with new business, so its next victims have reason to expect the same threaten-then-retract pressure and to discount any no-leak assurance.
  • constraint With a public hiring tool as the reported route in, security teams cannot rank systems by the department that owns them; access to personal records has to set the priority.

An FBI employee now has two documents about the same theft. One is an internal memo acknowledging that staff information was stolen, according to The New York Times [9]. The other is the attackers' own statement: "we had made our decision that we would never publish this data," ShinyHunters wrote [6].

The group took 2-3TB of data out of the agency [2]. A sample of it holds addresses, phone numbers, Social Security numbers and emergency contacts for real agents, according to a source familiar with the matter cited by PCMag [3]. A promise not to post those records leaves them with the group. The statement, as PCMag reported it, did not mention deleting the data. PCMag's bigger worry is a quiet sale to other hackers or state-sponsored groups, with undercover work among the FBI operations it says could be endangered [10].

The group has been plain about why it made the promise. "This was all a marketing campaign to protect our business and actively combat disinformation," it said [7]. It also claimed "a recent influx of success in our operations" since the episode [8]. The same group was behind the breach at educational IT provider Canvas, and it routinely names new victims publicly to pressure them into paying [11]. The pledge comes from the group that made the threats it replaced. The FBI's May alert, the one ShinyHunters demanded be corrected or removed [5], warned that the group uses "real or exaggerated claims" to pressure victims [4].

Then there is the way in. PCMag reports the theft was allegedly carried out by exploiting the FBI's online jobs board [2]. A jobs board is built to take input from strangers. If a system that strangers can reach can also reach personnel records, I think it needs the same review as the personnel system itself, whichever department pays for it.

That gives an operator two tests to run on their own setup. The first is a 2x2. One axis asks whether the public can reach the system. The other asks whether the system can reach personal records. Anything that scores yes on both gets reviewed like the HR database, even when HR bought it from a vendor and marketing edits the pages. The cost is slower vendor changes and a security sign-off on careers-site updates, and the team that owns the jobs board will feel that delay first.

The second test is for the incident plan: would any step in it change if the attacker reversed its latest statement? For the agents in the sample, the addresses and emergency contacts are out of their hands [3], and ShinyHunters' pledge covers publishing and nothing more [6].

What to watch

  • Whether the FBI says publicly how its jobs board reached agents' personal records, and what it tells affected staff beyond the internal memo.
  • Any sign of the FBI data being offered for sale or turning up with other groups, the risk PCMag says a no-publish pledge leaves open.
  • Whether ShinyHunters' pressure campaigns against other victims, such as Canvas, start citing the FBI episode as proof of reach.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories