Social Security numbers, birth dates compromised in ‘major’ hack of FBI jobs portal
Por John Sakellariadis and Maggie Miller — POLITICO – TOP Stories
FBI investigators have concluded a recent hack of a bureau jobs portal represents a “major” incident — a finding that lends credibility to a cybercrime group’s prior claim that it stole sensitive personal data on “nearly all” of the FBI’s staff.
The bureau made the determination last Tuesday, Sept. 22, and informed Congress on Friday, Sept. 25, according to a copy of a notification sent to lawmakers and viewed by POLITICO.
FBI spokesperson Benjamin Williamson told POLITICO Monday evening that the first agency-wide email about the breach was sent Sept. 22, “less than 12 hours after public reporting surfaced.” He did not respond when asked whether that email made clear the bureau’s conclusion that same day about the hack’s severity.
Three Congressional aides with knowledge of the FBI notice, granted anonymity to share details of the sensitive Congressional communications, confirmed they received the same correspondence last Friday.
Under a federal information security statute, federal agencies must report “major” cybersecurity incidents that are “likely to result in demonstrable harm” to U.S. national security, economic well-being or public safety, or which involve sensitive personal information whose exposure would have one of those effects. MS NOW first reported that the FBI assessed the breach as a major cyber incident.
Such findings were once rare for the FBI. But the agency has now been forced to declare two such major incidents in the last six months, raising questions about the internal security of an agency that handles a broad range of sensitive national security missions, from countering foreign spying campaigns to prosecuting international criminal gangs.
Concern for the safety of FBI staff has also grown, as details of the most recent hack have spread throughout Washington.
While the notification does not name any specific hacking group, cybercriminal group ShinyHunters claimed credit for the breach last week, the same day the FBI declared a major incident. In theory, criminal gangs or foreign spy services could steal or purchase the data stolen by ShinyHunters to threaten, harass or track FBI personnel, presenting a major counterintelligence risk.
The email to congressional offices noted that threat actors accessed an “unclassified” system on its jobs portal website that contained personal information including Social Security numbers, birthdates, phone numbers, addresses and emergency contacts. The FBI’s Cyber Action Team is currently investigating the breach, the email added.
Crista Colvin, acting deputy assistant attorney general at the Justice Department, cautioned in the email that the agency “has not yet identified the full scope of the individuals affected by this incident or the severity of the incident’s impact.”
“The Department is actively addressing this incident and taking steps to safeguard our systems,” Colvin wrote. “The FBI is using appropriate investigative and operational resources to identify and disrupt those responsible.”
Colvin did not immediately respond to an emailed request for comment.
One of the three aides said Republicans on the House Intelligence Committee, which is chaired by Rep. Rick Crawford (R-Ark.), have requested a briefing from the FBI about the hack.
ShinyHunters told 404 Media on Monday that they do not intend to publish the stolen data, but instead had carried out the breach and threatened to release the data in order to “actively combat disinformation” about the group. They took issue with an FBI public service announcement published in May that outlined the group’s tactics and was released after ShinyHunters attacked the Canvas learning system, leaving thousands of schools and universities temporarily offline.
Samples of the data stolen by ShinyHunters and shared with Reuters and The New York Times reportedly included other sensitive data, including the names of units FBI agents are assigned to, including, in some cases, sensitive roles in counterintelligence or counternarcotics.
One U.S. official with knowledge of the breach said investigators suspect ShinyHunters stole the data by exploiting an unpatched vulnerability in an Oracle database system the group first targeted in a hacking spree this summer.
In a blog post Friday, Google’s security research team said ShinyHunters had begun a new “mass exploitation” campaign that exploited the same bug by circumventing a temporary workaround many organizations using those databases had deployed instead of fully patching the underlying issue.
In the original warning about the summer hacking campaign from ShinyHunters, Google warned that the workaround — which involved using a firewall instead of patching the bug itself — was “insufficient” and could be bypassed.
The Friday blog post from Google did not name any of the organizations impacted by the campaign.
Fonte: POLITICO – TOP Stories