“我们黑进了FBI”:黑客声称掌握了所有FBI员工的数据
'We hacked the FBI:' Hackers say they have data on all FBI employees

原始链接: https://www.404media.co/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees/

黑客组织“ShinyHunters”声称已侵入联邦调查局(FBI)系统,据称窃取了 2 至 3 TB 的数据,其中包括所有现任和前任 FBI 员工及申请人的个人信息。该组织声称他们利用了甲骨文(Oracle)PeopleSoft 软件中的一个零日漏洞,从而入侵了亚马逊云科技(AWS)的 GovCloud 服务器。 为了支持其说法,黑客向 404 Media 提供了一份包含 5,000 条记录的样本,其中涵盖了姓名、家庭住址、电话号码和配偶详细信息,研究人员已使用开源情报工具对这些数据进行了核实。该组织还曾短暂篡改了 FBI 的招聘网站。 尽管 ShinyHunters 以勒索著称,但他们称此次特定攻击并非出于经济动机,而是为了“胁迫”。此次泄密造成了严重的国家安全风险,因为这些敏感个人数据可能被外国情报机构或犯罪组织利用,以跟踪、骚扰或恐吓特工。FBI 尚未对此置评,但受影响的招聘门户网站已下线。

黑客声称已入侵一个包含所有联邦调查局(FBI)员工个人信息的数据库。Hacker News 上的讨论指出,此次入侵是通过一个 PeopleSoft(甲骨文人力资源系统)的零日漏洞实现的,该漏洞促使攻击者横向移动到了政府云环境中。 评论者们正在讨论此次黑客攻击的影响,许多人对过度依赖第三方企业软件所带来的系统性漏洞表示担忧。一些用户将其与 2015 年的美国人事管理局(OPM)数据泄露事件进行了对比,另一些人则批评了企业和政府的安全实践,质疑离岸外包和行政裁员是否削弱了国家数字基础设施的安全性。 对于这些指控的真实性,目前仍存在质疑,有人推测这些数据可能是一个旨在诱捕攻击者的“蜜罐”。此外,这一事件引发了人们的讽刺,认为 FBI 近期在大力强调采用人工智能工具,而此次泄露却形成了鲜明对比;另一些人则在思考,这是否反映出美国在面对日益猖獗的网络对手时,其网络安全韧性正在整体下滑。
相关文章

原文

A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, phone number, and information on their spouse.

The data breach could be massively significant and may have all sorts of national security and counterintelligence implications. Criminals from the same ecosystem as ShinyHunters have previously used hacked data like phone records to track, intimidate, and harass the FBI agents investigating them. The highly sensitive data could also be a boon to foreign intelligence agencies who want to better understand how one of the most important law enforcement and intelligence agencies in the U.S. operates. And if the data fell into the hands of more criminals, FBI agents and their spouses could face serious threats to their safety.

“We hacked the FBI. We hold data on all FBI employees and applicants,” the representative of the group told 404 Media.

💡

Do you work at the FBI? Do you know anything else about this hack? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at [email protected].

The representative provided 404 Media with a sample appearing to contain the personal data of 5,000 FBI employees. That data included an alleged address, phone number, date of birth, and in some cases details on their spouse.

404 Media put some of the sample phone numbers into open source intelligence tool OSINT Industries and found they did correspond to people with the same name as listed in the sample file. 404 Media also searched some of the records through compromised data tool Darkside, made by cybersecurity company District 4. That revealed some of the phone numbers are associated with U.S. Department of Justice personnel.

ShinyHunters also defaced the FBI jobs website on Tuesday. That defacement says, “this site has been seized by ShinyHunters,” which is an obvious nod to the seizure notices the FBI and other law enforcement agencies often put on sites after taking them down. The representative said ShinyHunters carried out the hack on Monday night. At the time of writing, the FBI jobs website says, “Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable.”

The defacement adds, “All FBI data was compromised including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.”

The announcement ended with another obvious jibe at the administration, this time mocking President Trump’s Truth Social post style: “Thank you for your attention to this matter.”

The FBI did not immediately respond to a request for comment.

The representative said ShinyHunters said the group used a zero day exploit in an Oracle product called PeopleSoft. From there, the group managed to access AWS GovCloud servers and downloaded data. The representative said the exfiltrated data totalled between two and three terabytes. 

Typically, ShinyHunters hacks targets and then attempts to extort them. The group threatens to publicly release more compromised data if the victim organization or company doesn’t pay a hefty fee. Obviously, it is unlikely that the FBI would ever pay a ransom like this.

When asked if ShinyHunters was going to attempt to extort the FBI, the representative said, “what we plan to do is not something I’d call extortion, maybe coercion.”

“This is not financially motivated,” they added.

Update: this piece has been updated to include more information from previously compromised data.

联系我们 contact @ memedata.com