FBI arrests key suspect in major hack of agents’ dataFBI逮捕了一起特工数据重大黑客攻击案的关键嫌疑人
The FBI arrested a man in Pennsylvania who officials say helped orchestrate a recent damaging hack that exposed sensitive data of current and former FBI personnel, according to two sources familiar with the matter.

Nathan Howard/Reuters
The FBI arrested a man in Pennsylvania who officials say helped orchestrate a recent damaging hack that exposed sensitive data of current and former FBI personnel, according to two sources familiar with the matter.
FBI Director Kash Patel announced the arrest on Friday but did not disclose where it occurred or what role the man is suspected of playing in the hack.
“Earlier this week, our agents in the field arrested another suspected co-conspirator” of the cybercriminal group believed to be responsible for the hack, Patel said on Friday.
An investigation is ongoing into other people believed to be involved in the hack, the sources said.
Last week, the FBI announced that Dutch authorities arrested “one of the alleged leaders” of the criminal group, known as ShinyHunters.
Kevin Carter/Getty Images/File
FBI grapples with fallout from massive data breach
The New York Times first reported on the arrest of the man in Pennsylvania.
The forceful FBI response comes after one of the most serious breaches of the bureau’s data in years. ShinyHunters last month claimed responsibility for breaking into an FBI jobs portal and gaining access to the personal data on thousands of current and former FBI employees. The identities of FBI personnel working in sensitive units on China and Russia were exposed, according to sources who have seen the data.
ShinyHunters used their dark-web site to demand that the FBI amend a previous advisory issued about the group, before the hack, saying it was “offended” over how the agency described its alleged tactics for extorting victim organizations. Many in the cybersecurity industry took the demand as a tacit threat that ShinyHunters would leak the stolen data. The hackers later claimed that was never their intention.
Some FBI employees felt underwhelmed by the security resources being offered to victims of the breach, CNN previously reported.
Amid the internal criticism and media scrutiny, Patel and a senior FBI cyber official, Brett Leatherman, put out a series of public statements and video messages with updates on the investigation. Some were addressed to the cybercriminals.
“Arrests have a way of changing who is willing to talk and seized infrastructure has a way of showing us who is left,” Leatherman said in a video posted after the arrest by Dutch authorities. “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
There has also been an inquest at the FBI over how such a critical security lapse happened. The FBI determined that a contractor managing the bureau’s jobs portal failed to update software “explicitly issued to secure the platform,” Leatherman said last week. The FBI has “removed the contractor,” he said.
The software in question is a human-resources platform made by Oracle, ShinyHunters has said. The hackers previously used a flaw in the software to attack targets in the education sector in May and June, according to Google’s Threat Intelligence Group. But months later, the FBI contractor apparently still had not applied a security patch that was available for the software.
内森·霍华德/路透社
据两名知情人士透露,联邦调查局在宾夕法尼亚州逮捕了一名男子,官员称该男子协助策划了最近一起破坏性黑客攻击事件,该事件泄露了联邦调查局现任和前任人员的敏感数据。
美国联邦调查局局长卡什·帕特尔周五宣布了逮捕行动,但没有透露逮捕地点或该男子涉嫌在黑客攻击中扮演的角色。
帕特尔周五表示:“本周早些时候,我们的一线特工逮捕了另一名涉嫌参与此次黑客攻击的网络犯罪团伙的同谋。”
消息人士称,目前正在对其他涉嫌参与此次黑客攻击的人员进行调查。
上周,美国联邦调查局宣布,荷兰当局逮捕了名为 ShinyHunters 的犯罪集团的“一名涉嫌头目”。
Kevin Carter/Getty Images/文件
FBI正努力应对大规模数据泄露事件的后续影响。
《纽约时报》率先报道了这名男子在宾夕法尼亚州被捕的消息。
在联邦调查局遭遇近年来最严重的数据泄露事件之一后,该局做出了强有力的回应。上个月,ShinyHunters 黑客组织声称对入侵联邦调查局招聘网站并获取数千名现任和前任联邦调查局雇员的个人数据负责。据看过这些数据的消息人士透露,在负责中国和俄罗斯事务的敏感部门工作的联邦调查局人员的身份信息遭到泄露。
ShinyHunters利用其暗网网站要求FBI修改此前发布的关于该组织的警告(该警告发布于黑客攻击之前),称FBI对其涉嫌敲诈勒索受害组织的手段描述“感到不满”。网络安全行业的许多人士将此要求解读为ShinyHunters将泄露被盗数据的隐性威胁。但黑客们后来声称这并非他们的本意。
据 CNN 此前报道,一些 FBI 员工对向此次数据泄露事件的受害者提供的安全资源感到失望。
在内部批评和媒体密切关注下,帕特尔和联邦调查局高级网络官员布雷特·莱瑟曼发布了一系列公开声明和视频信息,更新了调查进展。其中一些声明和视频信息是直接针对网络犯罪分子发布的。
“逮捕行动往往会改变谁愿意开口,而缴获的基础设施则能让我们看清谁还活着,”莱瑟曼在荷兰当局逮捕行动后发布的一段视频中说道。“你待在这里的时间越长,我们对你的了解就越多。你知道如何找到我们,我们也知道如何找到你。我建议你趁现在还有机会,先主动联系我们。”
联邦调查局也已就此次重大安全漏洞的发生展开调查。莱瑟曼上周表示,联邦调查局认定,负责管理该局招聘门户网站的承包商未能更新“明确用于保护平台安全的软件”。他还表示,联邦调查局已“撤换了该承包商”。
ShinyHunters 表示,涉事软件是 Oracle 开发的人力资源平台。谷歌威胁情报小组称,黑客此前曾利用该软件的漏洞,在 5 月和 6 月对教育行业的目标发动攻击。但数月过去,这家 FBI 承包商显然仍未安装该软件的可用安全补丁。