"Crisis" in the FBI Due to Being Targeted by the "Most Dangerous Data Breach in Years".. What’s the Story?
- A week after a cybercriminal group announced the theft of sensitive personal data belonging to thousands of current and former employees of the Federal Bureau of Investigation (FBI), the bureau is still assessing the extent of the damage while facing internal criticism regarding its handling of the incident. This breach is considered one of the most serious data breaches the agency has faced in years.
New Face 24
·4 minutes read

- A week after a criminal cyber group announced the theft of sensitive personal data concerning thousands of current and former employees of the Federal Bureau of Investigation (FBI), the bureau is still assessing the extent of the damage, while facing internal criticism regarding its handling of the incident. This breach is considered one of the most serious data breaches the agency has faced in years, yet some employees feel they have been left without clear information on whether they have been affected or not, and they have expressed dissatisfaction with the security resources available to victims, according to current and former officials.
A former agent of the bureau - who is still in contact with his former colleagues - told Afaq News: "The management is lost; they are not providing any clear advice to the clients." Afaq News requested a comment from the FBI regarding its response to the breach.
The problem began a week ago when hackers breached an online portal containing private information about applicants for positions at the bureau, and the stolen data included social security numbers, emergency contact information, and personal addresses. The hackers demanded that the bureau amend a previous warning it issued regarding the group, expressing their dissatisfaction with the way the agency described their alleged methods of extorting victim organizations.
Many within the bureau and the cybersecurity sector considered this demand an implicit threat that the hackers would leak the stolen data, noting that the criminal group now claims it never intended to publish any of the stolen data, although it has a history of doing so with other victims. The group responsible for the breach, known as ShinyHunters, has previously targeted "major companies in technology, finance, and retail, often stealing millions of customer records at once," according to the warning issued by the bureau regarding this group.
In this case, the stolen data includes information about employees in the bureau who work in sensitive units focused on China and Russia, among other files, according to sources familiar with the data. This news has raised significant concerns for the bureau's clients who rely on a degree of confidentiality and anonymity while working on the front lines of counterintelligence, counterterrorism, and cybercrime.
Some individuals feel anxious about the possibility of their home addresses being disclosed to the public, which could pose a risk to the safety of their families while they are traveling, according to sources familiar with the matter. The extensive nature of the breach has raised serious concerns regarding counterintelligence; officials fear that the detailed personal data stolen by hackers—combined with other information stolen in previous breaches—could be used to identify clients holding sensitive positions, as reported by several individuals familiar with the investigation.
Hostile government entities or drug cartels could use this information—if obtained—to attempt to identify clients who are working undercover or tasked with specific missions that interest those entities. Sources indicate that the FBI will need to work on mitigating the security risks that these employees may face.
Hostile entities have previously exploited data from the FBI for adversarial purposes; a Mexican drug cartel hired a hacker to monitor the movements of a senior official in the bureau in Mexico City in 2018, gathering information from the city's surveillance camera system that enabled the cartel to kill potential informants for the bureau, according to a report by the Justice Department's inspector general published last year. On Friday, the bureau sent an email to employees regarding the incident, reaffirming its commitment to the safety of employees and their families, according to individuals who reviewed the message.
The message urged employees to inform security personnel at the bureau of any safety or security concerns, and it clarified that the bureau is addressing the situation based on the assumption that the hackers have stolen data pertaining to all bureau employees. The New York Times was the first to report on this message.
This incident represents a significant blow to one of the leading national institutions concerned with combating cybercrime, an agency that is often called upon to assist in addressing the fallout from breaches affecting major companies listed in Fortune 500. The bureau's security, cybercrime, and victim services divisions are all involved in the response efforts to the breach, according to informed sources; the goal is to provide every employee with the necessary resources to deal with any threats that may arise from the hackers.
However, some employees initially felt that they had no way to access those resources. One source mentioned that FBI agents turned to rumor sources within the agency in an attempt to find answers regarding the breach, answers that were not provided by the leadership.
Suggested
Read also
PoliticsBritain Threatens to Take a Major Step Forward in Boycotting Settlements
PoliticsInformed Official: Qatar Delivered America's Response to Araqchi's Seven-Day Proposal
Culture