'We hacked the FBI:' Hackers say they have data on all FBI employees
‘We hacked the FBI:’ Hackers say they have data on all FBI employees
“我们黑进了 FBI”:黑客声称掌握了所有 FBI 员工的数据
A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, phone number, and information on their spouse. 一个高调的黑客组织声称,他们已经入侵了多个与 FBI 相关的服务,并窃取了“所有 FBI 员工及申请人”的数据。该组织名为 ShinyHunters,其代表告诉 404 Media,这些数据包括 FBI 特工的姓名、家庭住址、电话号码以及其配偶的相关信息。
The data breach could be massively significant and may have all sorts of national security and counterintelligence implications. Criminals from the same ecosystem as ShinyHunters have previously used hacked data like phone records to track, intimidate, and harass the FBI agents investigating them. The highly sensitive data could also be a boon to foreign intelligence agencies who want to better understand how one of the most important law enforcement and intelligence agencies in the U.S. operates. And if the data fell into the hands of more criminals, FBI agents and their spouses could face serious threats to their safety. 此次数据泄露可能影响巨大,并可能引发各种国家安全和反间谍方面的连锁反应。与 ShinyHunters 同属一个生态系统的犯罪分子此前曾利用电话记录等被盗数据,追踪、恐吓和骚扰调查他们的 FBI 特工。这些高度敏感的数据也可能成为外国情报机构的“福音”,帮助他们更好地了解美国最重要的执法和情报机构之一是如何运作的。如果这些数据落入更多犯罪分子手中,FBI 特工及其配偶的人身安全可能会面临严重威胁。
“We hacked the FBI. We hold data on all FBI employees and applicants,” the representative of the group told 404 Media. “我们黑进了 FBI。我们掌握了所有 FBI 员工和申请人的数据,”该组织代表告诉 404 Media。
💡Do you work at the FBI? Do you know anything else about this hack? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co. 💡您在 FBI 工作吗?您是否还了解关于此次黑客攻击的其他信息?我很希望能收到您的消息。请使用非工作设备,通过 Signal(账号:joseph.404)安全地给我发信息,或发送电子邮件至 joseph@404media.co。
The representative provided 404 Media with a sample appearing to contain the personal data of 5,000 FBI employees. That data included an alleged address, phone number, date of birth, and in some cases details on their spouse. 该代表向 404 Media 提供了一份样本,其中似乎包含了 5,000 名 FBI 员工的个人数据。这些数据包括据称的住址、电话号码、出生日期,在某些情况下还包括其配偶的详细信息。
404 Media put some of the sample phone numbers into open source intelligence tool OSINT Industries and found they did correspond to people with the same name as listed in the sample file. 404 Media also searched some of the records through compromised data tool Darkside, made by cybersecurity company District 4. That revealed some of the phone numbers are associated with U.S. Department of Justice personnel. 404 Media 将部分样本电话号码输入开源情报工具 OSINT Industries 进行查询,发现它们确实对应着样本文件中列出的同名人员。404 Media 还通过网络安全公司 District 4 开发的泄露数据查询工具 Darkside 搜索了部分记录,结果显示其中一些电话号码与美国司法部的人员有关。
ShinyHunters also defaced the FBI jobs website on Tuesday. That defacement says, “this site has been seized by ShinyHunters,” which is an obvious nod to the seizure notices the FBI and other law enforcement agencies often put on sites after taking them down. The representative said ShinyHunters carried out the hack on Monday night. At the time of writing, the FBI jobs website says, “Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable.” The defacement adds, “All FBI data was compromised including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.” 周二,ShinyHunters 还篡改了 FBI 的招聘网站。篡改页面上写着“本网站已被 ShinyHunters 查封”,这显然是在模仿 FBI 和其他执法机构在关闭网站后通常会发布的查封通知。该代表称,ShinyHunters 是在周一晚上实施的攻击。截至发稿时,FBI 招聘网站显示:“Apply.fbijobs.gov 和特工申请门户网站目前无法访问。”篡改页面还补充道:“所有 FBI 数据均已泄露,包括现任和前任 FBI 员工的 PII/PHI(个人身份信息和受保护的健康信息)以及所有申请人信息。我们掌握的数据远不止这里所说的这些。”
The announcement ended with another obvious jibe at the administration, this time mocking President Trump’s Truth Social post style: “Thank you for your attention to this matter.” 公告最后再次对政府进行了明显的嘲讽,这次模仿的是特朗普总统在“真实社交”(Truth Social)上的发帖风格:“感谢您对此事的关注。”
After publication of this article, an FBI spokesperson told 404 Media in an email “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” 本文发布后,一位 FBI 发言人在电子邮件中告诉 404 Media:“FBI 已知悉有关影响 FBIjobs.gov 的未经授权活动的声明,目前正在进行调查。”
The representative said ShinyHunters said the group used a zero day exploit in an Oracle product called PeopleSoft. From there, the group managed to access AWS GovCloud servers and downloaded data. The representative said the exfiltrated data totalled between two and three terabytes. Typically, ShinyHunters hacks targets and then attempts to extort them. The group threatens to publicly release more compromised data if the victim organization or company doesn’t pay a hefty fee. Obviously, it is unlikely that the FBI would ever pay a ransom like this. 该代表称,ShinyHunters 利用了 Oracle 公司名为 PeopleSoft 的产品中的一个零日漏洞。以此为突破口,该组织成功访问了 AWS GovCloud 服务器并下载了数据。该代表表示,窃取的数据总量在 2 到 3 TB 之间。通常情况下,ShinyHunters 会在入侵目标后尝试进行勒索。如果受害组织或公司不支付巨额费用,该组织就会威胁要公开更多泄露的数据。显然,FBI 不太可能支付此类赎金。
When asked if ShinyHunters was going to attempt to extort the FBI, the representative said, “what we plan to do is not something I’d call extortion, maybe coercion.” “This is not financially motivated,” they added. 当被问及 ShinyHunters 是否打算勒索 FBI 时,该代表表示:“我们计划做的事情我不称之为勒索,或许是胁迫。”他们补充说:“这并非出于经济动机。”
In a post on its leak website, ShinyHunters said the FBI made “false allegations” in a previously published report. Previously, the FBI said that ShinyHunters exaggerates its claims of access to sensitive data to illicit payment, that the group sends threatening text messages and phone calls to victims and their families, and sometimes performs swattings. In the post, ShinyHunters said it is “allowing you [the FBI] a time of 1 week to correct” or remove the report. 在泄密网站的一篇帖子中,ShinyHunters 指责 FBI 在之前发布的一份报告中做出了“虚假指控”。此前,FBI 曾表示 ShinyHunters 为了非法获利而夸大其获取敏感数据的能力,该组织还会向受害者及其家人发送威胁短信和电话,有时甚至会进行“假报警”(swatting)。ShinyHunters 在帖子中表示,他们“给你们(FBI)一周时间来更正”或删除该报告。
Update: this piece has been updated to include more information from previously compromised data, a statement from the FBI, and information from a post on ShinyHunter’s website. 更新:本文已更新,纳入了更多来自此前泄露数据的信息、FBI 的声明以及来自 ShinyHunters 网站帖子的信息。
About the author: Joseph is an award-winning investigative journalist focused on generating impact. His work has triggered hundreds of millions of dollars worth of fines, shut down tech companies, and much more. More from Joseph Cox 关于作者:Joseph 是一位屡获殊荣的调查记者,致力于产生社会影响力。他的报道曾引发数亿美元的罚款,导致多家科技公司倒闭,等等。更多来自 Joseph Cox 的报道。