FBI begin investigation afta claims say hackers tiff details of all dia agents

Two FBI agents in Washington DC

Wia dis foto come from, Anadolu via Getty Images

    • Author, Joe Tidy
    • Role, Cyber correspondent, BBC World Service
  • Published
  • Read am in 4 mins

Di United States Federal Bureau of Investigation (FBI) dey investigate claims by one cyber-crime group say dem don tiff sensitive information on all bureau staff - around 38,000 pipo.

Di hackers, Shiny Hunters, tok say dem get di name, role, badge number and personal details of evri FBI agent, including dia home address, phone numbers and spouse information.

Professor Ciaran Martin, di former oga of di National Cyber Security Centre for di UK, tok say - if confamed - di mata dey veri serious wen e come to data breaches.

For one statement wey dem post for X, di FBI tok say dem dey aware of di claim and dem dey "actively and aggressively investigate di matter".

Di criminals claim say dem don breach di FBI servers on Monday night and start to dey contact tori pipo on Tuesday, sharing samples and screenshots of di data wey dem tiff.

Di BBC don see small portion of di data, and e appear to dey genuine.

Who be hackers and how dem enta FBI portal

According to Reuters, some of di data contains details about officials' ​job assignments, including sensitive work against Chinese spies, Russian intelligence and drug cartels.

ShinyHunters na international collective of hackers, wey dey believed to originally start for France.

Di group dey behind plenty high-profile breaches including on Rockstar Games in April and one ogbonge hack on education platform Canvas for May.

Di group claim say dem find vulnerability for di Oracle cloud storage system wey di FBI dey use, and dem use am to breach multiple systems including FBIJOBS, FBI BEAST, wey dey do background checks on employees and applicants, FBI MedLink, wey contain di medical records of agents, and FBI BICS, wey contain investigation information.

For one message wey dem post for di dark web, di group tok say dem no hack di FBI system for money.

Instead, di cyber-criminals want make di agency retract one advisory wey dem bin issue for May dis year about dem, as dem tok say dem dey "offended" by how di FBI describe dia organisation.

Dat FBI public service announcement bin describe ShinyHunters as "threat actors" wey dey often claim say dem get access to sensitive or personal information of pipo, and den use dat fear to dey collect payment from victims.

"Dem dey target major companies across tech, finance, and retail, as dem dey tiff millions of customer records at once," di advisory tok.

ShinyHunters tok say dem dey give di FBI one week to correct or remove wetin dem describe as false allegations against dem, or dem go publish di full database.

How FBI react to di hackers claim

Di FBI neva respond to requests for comment from di BBC.

For dia statement on X, di agency say dem dey try to determine weda or not di hackers bin breach dia systems or dem do am tru third party.

"We dey actively and aggressively investigate dis mata and we dey work closely wit dose third-party providers wey dey support FBIJobs.gov to mitigate any and all risk," di post tok.

For one statement to di BBC, one cyber-security sabi pesin tok say dis na "retaliation attack", wey demonstrate say "no organisation dey safe from di group".

"Di group clearly wan control di narrative around dia activities, to make sure say nobody go tok anytin wey fit spoil dia reputation," William Wright of Closed Door Security tok.

Meanwhile Andrew Brandt of cyber-security firm Huntress tok say dis fit provoke di FBI to track down and prosecute members of di hacking group.

"ShinyHunters gatz feel pretty confident say nobody fit catch dem for dem to threaten govment agency like dis," e tok.