FBI rushes to investigate if ShinyHunters hack of thousands of employees is real

FBI rushes to investigate if ShinyHunters hack of thousands of employees is real

FBI 紧急调查 ShinyHunters 黑客组织窃取数千名员工数据的真实性

The FBI is now investigating claims from a hacker group that thousands of current and former employees’ personal data was stolen after the group exploited a previously unknown bug found on an agency jobs website.

FBI 目前正在调查一个黑客组织的声明,该组织声称利用了 FBI 招聘网站上一个此前未知的漏洞,窃取了数千名现任和前任员工的个人数据。

On Tuesday, 404 Media reported that ShinyHunters took down the agency site, FBIJobs.gov, then posted a banner on the homepage that said “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.” About two to three terabytes of data were taken, ShinyHunters told The New York Times.

周二,404 Media 报道称,ShinyHunters 攻陷了 FBI 的招聘网站 FBIJobs.gov,并在主页上发布了一条横幅,写着“本网站已被 SHINYHUNTERS 接管”。ShinyHunters 向《纽约时报》透露,他们窃取了约 2 到 3 TB 的数据。

None of the data has been leaked yet, but it included “names of current and former agents as well as applicants and corresponding home addresses, phone numbers, names of spouses, certain medical information, and other data.” According to Bloomberg, the data could be used to potentially retaliate against agents, with one sample appearing to include “potentially sensitive professional information on the FBI employees’ work focus such as counter-intelligence work on China, Russia and Iran, as well as work against street gangs.”

目前这些数据尚未泄露,但据称其中包括“现任和前任特工及申请人的姓名,以及相应的家庭住址、电话号码、配偶姓名、部分医疗信息和其他数据”。据彭博社报道,这些数据可能被用于针对特工的潜在报复,其中一个样本似乎包含了“FBI 员工工作重点的潜在敏感专业信息,例如针对中国、俄罗斯和伊朗的反间谍工作,以及打击街头帮派的工作”。

The group’s motive was not to extort the FBI or seek a ransom, it claimed. Instead, the strike was meant to force the FBI to either remove or edit a May advisory warning about ShinyHunters that the group said circulated “disinformation in an attempt to ‘disrupt’ our operations.”

该组织声称,其动机并非勒索 FBI 或索要赎金。相反,此次攻击旨在迫使 FBI 删除或修改五月份发布的一份关于 ShinyHunters 的警告公告,该组织称该公告散布了“旨在‘破坏’我们行动的虚假信息”。

In a message posted on the dark web that was reviewed by Ars, ShinyHunters said it was “severely offended” that the FBI alleged that they sometimes use “exaggerated claims” to extract payments from victims. “We wish to state unequivocally our threats and claims are very real,” the group said. “Not exaggerated and never a bluff.” ShinyHunters was also upset that the FBI claimed the group conducts swatting attacks against corporate workers and makes sextortion threats. That “never” happens, ShinyHunters said.

在暗网发布并经 Ars 审核的一条消息中,ShinyHunters 表示,对于 FBI 指控他们有时利用“夸大其词”来勒索受害者钱财,他们感到“深受冒犯”。该组织表示:“我们明确声明,我们的威胁和声明都是非常真实的,绝非夸大,也从不虚张声势。”ShinyHunters 还对 FBI 声称该组织对企业员工进行“假报警”(swatting)攻击和性勒索威胁感到不满。ShinyHunters 称,这种情况“从未”发生过。

To get the advisory changed, ShinyHunters told FBI director Kash Patel and the assistant director of the FBI Cyber Division, Brett Leatherman, that they had one week to comply with demands or presumably risk a breach of sensitive employee data.

为了促使 FBI 修改公告,ShinyHunters 告知 FBI 局长 Kash Patel 和 FBI 网络部门助理局长 Brett Leatherman,他们有一周的时间来满足要求,否则可能会面临敏感员工数据泄露的风险。

Not many details have been released on how ShinyHunters got access to the data. ShinyHunters would only tell NYT that “it had weaponized a zero-day, or previously undiscovered, computer bug within the Oracle PeopleSoft software, an application that companies use for human resources and financial management.” So far, Oracle is silent on that bug, reports said, while ShinyHunters said it plans to continue using the zero-day for its “businesses’ normal operations.”

关于 ShinyHunters 如何获取这些数据,目前披露的细节并不多。ShinyHunters 仅向《纽约时报》透露,他们“利用了 Oracle PeopleSoft 软件中的一个零日漏洞(即此前未被发现的计算机漏洞),该软件是企业用于人力资源和财务管理的应用程序。”据报道,Oracle 目前对该漏洞保持沉默,而 ShinyHunters 表示计划继续利用该零日漏洞进行其“业务的正常运营”。

The FBI has not confirmed that the hack occurred, but it has begun probing the claims. On Wednesday, the FBI said in an X post that “the point of breach is still undetermined—whether a third-party or the FBI’s enterprise.” Until more information is known, the FBI said, “we are actively and aggressively investigating this matter and working closely” with third-party providers that support the jobs site “to mitigate any and all risk.”

FBI 尚未证实此次黑客攻击是否发生,但已开始调查相关声明。周三,FBI 在 X 上发文称,“目前尚不确定入侵点——究竟是第三方还是 FBI 的企业系统。”FBI 表示,在获得更多信息之前,“我们正在积极且深入地调查此事,并与支持该招聘网站的第三方供应商密切合作,以减轻所有潜在风险。”

As of Wednesday, the jobs site remained inaccessible, as sources inside the FBI told Bloomberg that all personnel received an email warning them to “take steps to protect themselves while the investigation continues.”

截至周三,该招聘网站仍无法访问。据 FBI 内部消息人士向彭博社透露,所有员工都收到了一封电子邮件,警告他们在调查期间“采取措施保护自己”。

ShinyHunters has not said what will happen if the FBI misses the deadline, but cybersecurity experts told the NYT that most likely the data will be leaked online. “We cannot comment on what we will do if the FBI does not comply with our request,” ShinyHunters said in an email to the NYT. “We reiterate we are not extorting the FBI and this is NOT financially motivated.” “Our intention, goal, and motive is solely to set the record straight,” the group said.

ShinyHunters 并未说明如果 FBI 未能在截止日期前满足要求会发生什么,但网络安全专家告诉《纽约时报》,数据很可能会被泄露到网上。ShinyHunters 在给《纽约时报》的电子邮件中表示:“如果 FBI 不满足我们的要求,我们将采取什么行动,对此我们不予置评。我们重申,我们并非在勒索 FBI,这也不是出于经济动机。”该组织表示:“我们的意图、目标和动机仅仅是为了澄清事实。”