Published

ShinyHunters Tells CBC It Won’t Publish Stolen FBI Employee Data
Image: Number 1 News

Crime · updated 1h ago · 2 min read

ShinyHunters Tells CBC It Won’t Publish Stolen FBI Employee Data

Happened

ShinyHunters say they will not publish or leak FBI employee data. Hackers stole data on FBI employees, including addresses, Social Security numbers, and job details.

Split on

Whether non-leak claim is credible.

Left out

9 of 11 outlets skipped it: BBC saw stolen fitness-for-work medical records samples.

12outlets compared

404 MediaCBCCNNEl DiarioHackreadMalwarebytesNewserNewsNation

Same story, two versions

tap a side to read it in full

HackreadHackread

“The ShinyHunters extortion group says it will not publish or sell the FBI data it claims to have stolen”
Read the original ↗

CNNCNN

“(The cybercriminal group now claims that it never planned to publish any of the stolen data, but they have a history of doing so with other victims).”
Read the original ↗
VS

CNN casts ShinyHunters’ no-leak claim as unproven, while Hackread foregrounds the group’s statement that it never intended to publish.

ShinyHunters backs off

ShinyHunters told CBC News it will not publish the sensitive information it obtained in a massive FBI data breach, while the group said it cannot guarantee what will happen with data it already shared. ShinyHunters claimed responsibility for stealing a trove from the FBI last Tuesday and gave the law enforcement agency one week to rescind an “unflattering statement,” according to CBC News.

ShinyHunters told CBC News it was never planning to release the sensitive data, adding that “The reason why we have stated multiple times that this is not extortion is because since the very beginning we had made our decision that we would never publish this data.” Ian Lin, an ethical hacker and head of research and development at Toronto-based cybersecurity company Packetlabs, told CBC News that “There's going to be people that are willing to pay a high price for this data,” even if the group says it will not leak it.

Image from 404 Media
404 Media404 Media
SourcesCBCCBC

FBI says cyber incident

The FBI confirmed Saturday that it was involved in a “cybersecurity incident” tied to the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII). The FBI said it was “actively and aggressively investigating this matter” while working with third-party providers that support FBIJobs.gov to “mitigate any and all risk,” according to NewsNation.

The New York Times reported that an internal memo told staff to operate under the premise that the threat actor is also exfiltrating PII of all F.B.I. employees. The New York Times also reported that many F.B.I. employees first learned about the hack when news reports surfaced on Tuesday, and that the next day staff received an email reminding them that October is cybersecurity awareness month.

Image from CBC
CBCCBC

Medical data raises stakes

BBC News reports it has seen samples of stolen FBI agents’ medical examinations, including “fitness-for-work” reports that identify FBI agents by name and address and include blood and urine test results. ShinyHunters shared samples with journalists as proof of its claims, and the BBC stated: “The samples shared with journalists appear genuine and include names, addresses, phone numbers, badge numbers, job titles and information about spouses.”

“The samples shared with journalists appear genuine and include names, addresses, phone numbers, badge numbers, job titles and information about spouses.”

MalwarebytesMalwarebytes

TechCrunch reported that the FBI has declared a “cyber security incident” in an internal notification to staff and said the notification told employees that their names, addresses, job titles, and their Social Security numbers were exposed. TechCrunch also reported that several media outlets confirmed the stolen data included medical information, such as records relating to blood and urine samples, as well as psychiatric reports.