The hack of FBI computer systems exposed sensitive personal information about nearly every FBI employee, as well as thousands of local law-enforcement officials who worked on FBI task forces, six current and former FBI officials told MS NOW.
FBI officials and outside experts are calling the breach one of the worst counterintelligence disasters in modern history. They say it raises questions about whether negligence was a factor in allowing it to happen.
One FBI agent who works on cybersecurity matters chalked the breach up to “incompetence.”
“This was a vulnerability that supposedly they thought they patched, but managed to miss one of the ways to patch it,” the agent said in a text message, adding that the cause was “definitely incompetence.”
The sensitive employee information that was stolen “should never have been tied to the Internet, either. It belonged on our internal system and some dumbass moved it all” to an internet-facing system, the agent said.
The agent added that the FBI obtained chats in which the hackers expressed disbelief that such sensitive information was available to them so easily.
Google’s threat intelligence experts issued a public warning in June about the vulnerability the hackers exploited, and the FBI took steps to shore up its systems, two cyber security experts told MS NOW, speaking on the condition of anonymity to discuss a sensitive matter.
But the hackers found a way around the FBI patch, they said.
“It’s the fault of whoever in the FBI is responsible for our cyber security,” said the FBI cyber security agent who blamed the breach on “incompetence.” The agent added, “But also whoever pushed that information from our internal system to the Internet.”
An FBI official told MS NOW that the hack was the result of a vulnerability in software maintained by a third-party vendor. The official didn’t respond to questions about the allegations of FBI incompetence.
Cybersecurity experts say the hacking group, which calls itself ShinyHunters — a reference to a game pursuing rare and valuable Pokémon characters — got in through the FBIJobs.gov portal by exploiting a previously unknown vulnerability in Oracle PeopleSoft, the human resources software. The hackers did not penetrate the FBI’s core investigative network or any classified systems, the current and former officials said.
Nonetheless, the information they stole could be extremely damaging.
An internal FBI message obtained by MS NOW said that the data exposed included names, home addresses, cell phone numbers, FBI email addresses and employee ID numbers, in addition to personal identifying information for emergency contacts, including Social Security numbers and personal email addresses.
The hackers obtained that information for nearly every FBI employee and also for more than 8,000 state and local law enforcement officers who worked on FBI task forces, current and former officials said. The FBI official confirmed that task force officers were victims and said they were being notified.
ShinyHunters released a sample of 5,000 records but has since said its group does not plan to release the full data set. Still, experts warn that foreign adversaries, including China and Russia, are likely trying to steal it.
“Beyond causing significant reputational damage to the FBI, the incident poses a longer-term national security threat to the United States,” researchers from the Center for Strategic and International Studies think tank said in an analysis released this week.
Experts say the breach harkens back to the 2015 hack by Chinese intelligence agents of the Office of Personnel Management, an attack that yielded China information on nearly every federal employee, including fingerprints and highly sensitive details from their security clearance applications.
The information obtained from the FBI in theory would provide adversaries a roadmap about agents and analysts working on sensitive matters, and could offer opportunities for foreign intelligence officials to blackmail or recruit vulnerable FBI employees, experts say.
In the employee notifications, the FBI said it would offer sessions titled “Public Disclosures and Mitigation Strategies,” adding: “These briefings provide proactive steps all personnel can take to minimize vulnerabilities.”
“The FBI continues to investigate the recent Cyber incident, which we have confirmed involved a failure of a platform managed by a third-party vendor,” an FBI spokesman said in a statement.
The post ‘Incompetence’: Massive FBI hack hit most employees and extends to local officials appeared first on MS NOW.
From MS Now.

Leave a Reply