Skip to content

Product1 publisher3 min readPublished

ShinyHunters demands an FBI advisory retraction as the price of not leaking staff data

The group says it holds two to three terabytes of FBI employee records and will publish them unless the bureau pulls language from a May 15 public service announcement about its tactics. The FBI says it is investigating.

The Product Desk · Product desk

Photograph accompanying ShinyHunters demands an FBI advisory retraction as the price of not leaking staff data
Photo: nbcnews.com

What happened

  • ShinyHunters claimed the FBI intrusion on Monday and said it will publish what it describes as two to three terabytes of employee data unless the bureau retracts a public warning about its tactics within a week.
  • The language the group wants removed sits in a May 15 FBI public service announcement that describes practices the group contests.
  • On Tuesday it sent Nextgov/FCW and other outlets an apparent sample of roughly 5,000 entries carrying names, home addresses, phone numbers and details about spouses and siblings.
  • The FBI said it is aware of a criminal group claiming a compromise of the FBIJobs.gov portal and alleged impact to employee personal information, and that it is investigating.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision The bureau now has to decide whether taking down published guidance is a thing it will trade for silence, and whichever way it goes, every other crew that reads FBI advisories can see the answer.
  • exposure Because the claimed entry point is the jobs portal, people who only applied to the bureau sit in the same pool as staff, and a home address cannot be rotated the way a credential can.
  • contradiction The route in is contested: the group says it exploited vulnerabilities in Amazon and Oracle services, the bureau says the cause is undetermined, and neither company has answered a request for comment.

Hundreds of the people in the stolen set are intelligence analysts and other employees involved in clandestine collection and surveillance, two people familiar with the matter told Nextgov/FCW [4]. Their subject areas include Russia, China, Hezbollah and cartel intelligence [5]. Those people said the job titles offer only a small picture of the employees' duties, but may still help outsiders identify people working in sensitive parts of the bureau [6]. Some of them work in the Remote Operations Unit, which builds specialized tools to target computers and networks, and one works in the FISA Management Unit [7].

Most extortion is payable in money. This one asks for a deletion: the group wants specific language gone from a page the bureau itself published [1][2], and the week it allowed runs out on Monday [16]. The Nextgov/FCW account describes the retraction as the condition for withholding the data and does not say the advisory prompted the intrusion.

Anyone with a browser can check whether the page came down, while a deletion of two to three terabytes is unverifiable [1], and the sample the group mailed to newsrooms this week is beyond recall [3].

Etay Maor, vice president of threat intelligence at Cato Networks, said the direct claim of an FBI breach is "an unusually provocative move" and should be taken seriously [11]. The group claimed responsibility in May for accessing Canvas, the education technology platform used by thousands of U.S. institutions [15]. Doc McConnell, a former cyber policy official at the White House and the Cybersecurity and Infrastructure Security Agency who now heads policy and compliance at Finite State, called the incident "troubling news" for employees and applicants alike [12] and compared it to the 2015 breach at the Office of Personnel Management. "The breach of OPM's personnel records in 2015 resulted in a decade of credit monitoring for millions of affected individuals, and the full counterintelligence impact will likely never be known. This breach appears to contain similar data, creating potential security concerns for the victims if it is made publicly available," he said [13]. Cynthia Kaiser, senior vice president of Halcyon's Ransomware Research Center and a former deputy director of the FBI's Cyber Division, said that when any group directly targets the agency, "they should expect that the FBI is going to marshal additional resources to bring them more quickly to justice" [14].

Teams that publish threat guidance treat the publishing itself as a one-way cost. Legal reviews the draft, the page goes up, the ticket closes, and the budget ends there. An edit request from the crew named in the page, backed by leverage, is a cost that sits outside the plan. Here the demand arrived after publication and named the page [1][2].

At publication time, does this page describe tradecraft a funded crew would pay to have removed? And do we hold personal records about our own people that the same crew can reach? A team that answers yes twice already owns a retraction decision, whether or not a demand has arrived, including the part about who signs the refusal. The bureau's version of that decision expires Monday [16].

What to watch

  • Whether the May 15 public service announcement is still posted unchanged once the group's deadline passes.
  • Whether Amazon or Oracle answers the claim that vulnerabilities in their services were the route into the bureau's data.
  • What the FBI offers employees and job applicants whose home addresses and family details are in the circulating sample.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories