Stolen FBI data reveals employees’ roles in intelligence and surveillance被盗的FBI数据揭示了员工在情报和监视中的角色
Exposed analysts work on areas including China, Russia, and electronic surveillance. ShinyHunters claimed responsibility for the breach this week. The FBI said it’s investigating.

Kevin Carter / Contributor / Getty Images
Exposed analysts work on areas including China, Russia, and electronic surveillance. ShinyHunters claimed responsibility for the breach this week. The FBI said it’s investigating.
Data stolen in a major hacking group’s alleged intrusion into FBI systems is believed to contain personal information on hundreds of FBI intelligence analysts and other employees involved in clandestine intelligence-gathering and surveillance, according to two people familiar with the matter.
The analysts focus on myriad subject areas like Russia, China, Hezbollah, and cartel-related intelligence, said the people, who spoke on the condition of anonymity because the exposures are sensitive. The employees’ roles only offer a small picture of their duties, but may still help outsiders identify people working in sensitive parts of the bureau.
ShinyHunters claimed responsibility for the breach Monday, threatening to release what it described as two to three terabytes of FBI employee data unless the bureau retracted a public warning about its tactics within a week.
On Tuesday, the group sent Nextgov/FCW and other news outlets an apparent sample of that data containing roughly 5,000 entries listing employees’ names, home addresses, phone numbers and information about their spouses and siblings.
Multiple individuals also work on human intelligence-gathering, as well as roles involving electronic surveillance activities that make use of telecom interception techniques and other covert access mechanisms. Some employees work in the FBI’s Remote Operations Unit, which builds specialized tools to target computers and networks.
One person works in the bureau’s FISA Management Unit, which handles the processing of applications and renewals under the Foreign Intelligence Surveillance Act that governs surveillance and search standards used to collect foreign intelligence.
The FBI said it was aware of “a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information” and added that it is investigating the matter.
The agency said the cause of the breach was still undetermined. ShinyHunters previously said it exploited vulnerabilities in Amazon and Oracle services to access the bureau data. Neither company has returned a request for comment.
Reuters and 404 Media previously reported details regarding the intelligence roles and the ROU staff.
The language ShinyHunters wants removed appears in a May 15 FBI public service announcement that describes practices the hacking group contests. The group has built a global reputation for various hacking achievements. In May, it claimed responsibility for accessing Canvas , the popular education tech platform used by thousands of U.S. institutions.
The direct claim of an FBI breach is “an unusually provocative move” and should be taken seriously, said Etay Maor, the vice president of threat intelligence at Cato Networks.
Exposure of sensitive bureau staffing data could pose profound counterintelligence risks. For employees who do not publicly identify themselves as working for the FBI, the exposure could reveal both their jobs and how to reach them outside secure work environments. Linking that information to home addresses and relatives’ details could make it easier for nation-state groups and cyber criminals to target employees and their families with harassment, scams or threats.
The breach would be “troubling news” for both FBI employees and applicants, said Doc McConnell, a former cyber policy official at the White House and the Cybersecurity and Infrastructure Security Agency.
McConnell, who now heads policy and compliance at Finite State, compared the incident to the OPM hack a decade ago .
“The breach of OPM’s personnel records in 2015 resulted in a decade of credit monitoring for millions of affected individuals, and the full counterintelligence impact will likely never be known. This breach appears to contain similar data, creating potential security concerns for the victims if it is made publicly available,” he said.
The bureau will likely work more assertively to crack down on ShinyHunters. When any group directly targets the agency, “they should expect that the FBI is going to marshal additional resources to bring them more quickly to justice,” said Cynthia Kaiser, the SVP of Halcyon’s Ransomware Research Center and former deputy director of the FBI’s Cyber Division.
The incident follows other cyberattacks involving the bureau and its leadership this year. In March, pro-Iran hacking group Handala published material from FBI Director Kash Patel’s personal email account, which the bureau said contained historical information unrelated to government business. Separately, a suspected China-linked intrusion into an FBI system exposed surveillance targets’ phone numbers.
NEXT STORY: Trump's FBI shut down investigation into defense contractor's alleged bribes
凯文·卡特 / 供稿人 / Getty Images
被曝光的分析师研究领域包括中国、俄罗斯和电子监控。ShinyHunters本周声称对此次数据泄露事件负责。联邦调查局表示正在对此事进行调查。
据两名知情人士透露,一个大型黑客组织涉嫌入侵 FBI 系统,窃取的数据据信包含数百名 FBI 情报分析员和其他参与秘密情报收集和监视工作的雇员的个人信息。
知情人士透露,这些分析师的工作重点涵盖众多领域,例如俄罗斯、中国、真主党以及与贩毒集团相关的情报。由于信息敏感,这些人士要求匿名。虽然这些员工的职责描述仅能展现其工作内容的一小部分,但或许仍有助于外界识别在情报局敏感部门工作的人员。
ShinyHunters 周一声称对此次数据泄露事件负责,并威胁称,除非 FBI 在一周内撤回对其策略的公开警告,否则将公布其所称的 2 至 3 TB 的 FBI 员工数据。
周二,该组织向 Nextgov/FCW 和其他新闻媒体发送了一份疑似该数据样本,其中包含大约 5,000 条记录,列出了员工的姓名、家庭住址、电话号码以及有关其配偶和兄弟姐妹的信息。
多人从事人力情报收集工作,以及利用电信拦截技术和其他秘密访问手段进行电子监控活动。部分员工在联邦调查局远程行动部门工作,该部门负责开发针对计算机和网络的专用工具。
该局的 FISA 管理部门有一名工作人员,负责处理根据《外国情报监视法》提出的申请和续签事宜。该法规定了用于收集外国情报的监视和搜索标准。
美国联邦调查局表示,他们已注意到“一个网络犯罪团伙声称入侵了 FBIJobs.gov 门户网站,并声称对联邦调查局员工的个人身份信息造成了影响”,并补充说,他们正在调查此事。
该机构表示,此次数据泄露的原因尚未确定。ShinyHunters此前曾表示,他们利用亚马逊和甲骨文服务的漏洞访问了该局的数据。两家公司均未回复置评请求。
路透社和 404 Media 此前报道了有关情报角色和 ROU 人员的详细信息。
ShinyHunters希望删除的措辞出现在5月15日FBI发布的一则公共服务公告中,该公告描述了该黑客组织所反对的一些做法。该组织因其各种黑客攻击成就而享誉全球。今年5月,该组织声称对入侵Canvas负责,Canvas是美国数千所教育机构广泛使用的热门教育技术平台。
Cato Networks 威胁情报副总裁 Etay Maor 表示,直接声称 FBI 遭到入侵是“一种异常挑衅的举动”,应该认真对待。
敏感的联邦调查局人员配置数据泄露可能构成严重的间谍风险。对于那些不公开表明自己是联邦调查局员工的人来说,数据泄露不仅会暴露他们的工作岗位,还会暴露他们在安全工作环境之外的联系方式。将这些信息与家庭住址和亲属信息关联起来,可能使国家级犯罪集团和网络犯罪分子更容易对员工及其家人进行骚扰、诈骗或威胁。
曾任白宫和网络安全与基础设施安全局网络政策官员的麦康奈尔表示,此次泄露事件对联邦调查局员工和申请人来说都是“令人不安的消息”。
现任 Finite State 政策与合规主管的 McConnell 将此次事件与十年前的 OPM 黑客事件相提并论。
“2015年美国人事管理局(OPM)人事档案泄露事件导致数百万受影响人员长达十年的信用监控,其造成的全部反间谍影响可能永远无法估量。此次泄露事件似乎包含类似数据,如果公开,可能会给受害者带来安全隐患,”他说道。
联邦调查局可能会采取更积极的措施打击 ShinyHunters 勒索软件组织。Halcyon 勒索软件研究中心高级副总裁、前联邦调查局网络部门副主任辛西娅·凯泽表示,任何组织一旦直接攻击联邦调查局,“就应该预料到联邦调查局会调动更多资源,更快地将他们绳之以法”。
今年早些时候,联邦调查局及其领导层还遭受过其他网络攻击。今年3月,亲伊朗黑客组织Handala公布了联邦调查局局长卡什·帕特尔个人邮箱中的邮件,联邦调查局称这些邮件包含与政府事务无关的历史信息。此外,一起疑似与中国有关的入侵事件也导致联邦调查局系统遭到入侵,监控目标的电话号码被泄露。
下一篇报道:特朗普领导下的联邦调查局叫停了对国防承包商涉嫌受贿的调查