Skip to content

Security1 publisher2 min readPublished

Researchers say leaked FBI assignment data puts agents at risk of direct targeting

ShinyHunters claims data on almost every FBI agent, and samples reviewed by researchers show contact information, family details and duty assignments. The FBI has not confirmed what was taken or who took it, and says it is investigating.

The Watch · Security desk

Photograph accompanying Researchers say leaked FBI assignment data puts agents at risk of direct targeting
Photo: pbs.org

What happened

  • ShinyHunters wants the FBI to remove or amend a May public service announcement about the group, and set a Monday deadline for the bureau to act.
  • The group denies the advisory's assertions that it is tied to The Com, runs swatting attacks, or extorts victims with embarrassing photos or videos.
  • Samples went to journalists and also sat on the group's internal forum, where anyone with access could copy them and pass them on.
  • The FBI jobs site, which ShinyHunters temporarily defaced, was still offline as of Monday.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure If the assignments are accurate, the people an agent investigates can learn who is working on them, and DiMaggio says informants and cases tied to that agent are exposed along with the agent.
  • constraint Takedowns and deletion promises cannot shrink the exposure, so protective measures for named staff and their relatives have to assume the samples circulate indefinitely.
  • decision Protection decisions for named agents and families have to be made on samples the FBI has not authenticated, because the copies are spreading while confirmation is still pending.

The office and duty assignment fields are what make this a personnel-protection case [1]. "The counterintelligence concern is that assignment information could help hostile actors identify people working on issues relevant to them. That creates risk for personnel and could put sources or investigations connected to their work at risk," said Jon DiMaggio, principal researcher at Arkem Cyber [9]. "If the information is accurate, agents may have to consider the possibility of being targeted directly," he said [10]. "It is a whole different ball game when you do not know the identity of the person you are investigating, but they know exactly who you are." [10]

A researcher who has studied a sample told CyberScoop, on condition of anonymity, that the data would let a hostile country, a drug cartel or a lone individual find the FBI employee they hold a grievance against [19]. The same researcher said that person could then show up at the employee's home or attack someone close to them [19]. The reporting describes the exposed fields as personal contact information and family details. It does not say whether street addresses are among them [1]. CyberScoop has not seen the data itself [7]. The count of who is covered, which the group says extends to people who applied for FBI jobs, comes from ShinyHunters' own leak-site post [2][3].

Containment is no longer possible, according to Cynthia Kaiser, a former FBI official who is now a senior vice president at Halcyon's ransomware research center [11]. "The link no longer works, but the damage is done," she wrote [12]. "Even technically, once threat actors send victims a sample of what they stole, they have probably made five-plus copies of the stolen data," she added [13]. She also wrote that "the FBI has said that whenever it gets onto ransomware group infrastructure, it finds data that the group promised would be deleted." [14] Any protection plan built around these samples has to assume they stay in circulation whether or not the FBI changes its advisory [13][17].

DiMaggio did not expect the pressure to work in the group's favour. "This is retaliation, which is crazy because they have just put a massive target on themselves. But clearly they are not concerned about the FBI and do not believe the bureau has the capacity to find and arrest them," he said [18].

On the record so far, this is one retaliatory operation aimed at one advisory [15][18]. How the group got in has not been disclosed. The FBI said on Wednesday that its investigation covers the root cause of the incident and its alleged impact on employees' personal data [6].

What to watch

  • Whether the FBI confirms the type and amount of data taken, and whether the duty-assignment fields in the samples are genuine.
  • What ShinyHunters publishes after its Monday deadline passes, and whether it releases more agent or family records.
  • Whether the FBI amends or withdraws its May public service announcement on the group.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories