FBI grapples with fallout from massive data breachFBI正努力应对大规模数据泄露事件的后续影响。
A week after a cybercriminal group claimed to steal sensitive personal data on thousands of current and former FBI employees, the bureau is still assessing the extent of the damage while facing internal criticism about the agency’s handling of the incident.

Kevin Carter/Getty Images/File
A week after a cybercriminal group claimed to steal sensitive personal data on thousands of current and former FBI employees, the bureau is still assessing the extent of the damage while facing internal criticism about the agency’s handling of the incident.
It’s one of the most serious breaches of agency data in years, but some FBI employees have felt left in the dark about whether they’re affected and underwhelmed by the security resources being offered to victims, according to current and former officials.
“Management is lost,” one ex-FBI agent in touch with their former colleagues told CNN. “They’re not providing any clear advice to agents.”
CNN has requested comment from the FBI on its response to the hack.
The issue began a week ago, when hackers broke into an online portal hosting information on FBI job applicants. Social Security numbers, emergency contact information and personal addresses were in the stolen data.
The hackers demanded that the FBI amend a previous advisory issued about the group, saying it was “offended” over how the agency described its alleged tactics for extorting victim organizations.
Many at the FBI and within the cybersecurity industry took the demand as a tacit threat that the hackers would leak the stolen data. (The cybercriminal group now claims that it never planned to publish any of the stolen data, but they have a history of doing so with other victims).
The hackers responsible, known as ShinyHunters, have previously targeted “major companies across tech, finance, and retail, often stealing millions of customer records at once,” according to the FBI’s advisory on the group.
In this case, the stolen data includes information on FBI personnel working in sensitive units focused on China and Russia, among other topics, according to sources who have seen the data.
Patrick T. Fallon/AFP/Getty Images/File
FBI investigating apparent breach after hackers claim to have stolen thousands of federal agents’ data
It was alarming news for the FBI agents who rely on relative anonymity to work the front lines of counterintelligence, terrorism and cybercrime. Some agents are worried that their home addresses could be made public, potentially posing a safety issue for their family while they are traveling, according to sources familiar with the matter.
The far-reaching extent of the breach has also raised serious counterintelligence concerns. Officials fear that detailed personal data stolen by the hackers could be used along with other information compromised in earlier breaches to identify agents in sensitive jobs, according to multiple people briefed on the investigation.
Foreign government adversaries or drug cartels could use the information — were they to acquire it — to try to identify agents who are working undercover or are assigned specific roles that are of interest to them. The FBI will have to try to mitigate safety risks to those employees, the sources say.
Adversaries have weaponized FBI data before. A Mexican drug cartel hired a hacker to surveil the movements of a senior FBI official in Mexico City in or around 2018, gathering information from the city’s camera system that allowed the cartel to kill potential FBI informants, according to a Justice Department inspector general report made public last year.
On Friday, the FBI sent an email to the workforce about the incident emphasizing the bureau’s commitment to the safety of employees and their families, according to people familiar with the message. It encouraged employees to report any safety or security concerns to FBI security personnel. The bureau is operating under the assumption that the hackers have stolen data on all FBI employees, the message said. (The New York Times first reported on the email.)
It’s a blow to one of the nation’s premier cybercrime-fighting organization, which is often called to help clean up hacks at Fortune 500 companies.
The FBI’s cyber, security and victim services divisions are all involved in the response to the hack, according to people familiar with the matter. The goal is to give each employee the resources they need to deal with any threats from the hackers.
But, at least initially, some in the workforce didn’t feel they had access to those resources. FBI agents have turned to agency rumor mills to try to find answers about the breach that leadership haven’t provided, one source said.
Kevin Carter/Getty Images/文件
在网络犯罪团伙声称窃取了数千名现任和前任 FBI 雇员的敏感个人数据一周后,该局仍在评估损失程度,同时还面临着内部对该机构处理此事件方式的批评。
这是近年来最严重的机构数据泄露事件之一,但据现任和前任官员称,一些联邦调查局员工感到自己对是否受到影响一无所知,并且对提供给受害者的安全资源感到失望。
一位与前同事保持联系的前FBI特工告诉CNN:“管理层已经失职了。他们没有给特工们提供任何明确的指导。”
CNN已就FBI对此次黑客攻击事件的回应向其征求意见。
事件始于一周前,当时黑客入侵了一个存储FBI求职者信息的在线门户网站。被盗数据包括社会安全号码、紧急联系人信息和个人地址。
黑客们要求 FBI 修改之前发布的关于该组织的警告,称他们对该机构描述其涉嫌勒索受害组织的方式感到“冒犯”。
联邦调查局和网络安全行业的许多人都认为,这一要求是对黑客的隐性威胁,即他们会泄露被盗数据。(该网络犯罪团伙现在声称,他们从未打算公布任何被盗数据,但他们此前曾对其他受害者这样做过。)
据美国联邦调查局发布的关于该组织的公告称,负责此次事件的黑客组织名为 ShinyHunters,此前曾以“科技、金融和零售等行业的大型公司为目标,经常一次性窃取数百万客户记录”。
据看过相关数据的消息人士透露,此次被盗数据包括有关美国联邦调查局(FBI)在负责中国和俄罗斯等敏感部门工作的人员的信息。
Patrick T. Fallon/法新社/盖蒂图片社/档案照片
黑客声称窃取了数千名联邦特工的数据后,FBI正在调查这起疑似数据泄露事件。
对于那些依靠相对匿名性在反间谍、反恐和网络犯罪前线工作的联邦调查局特工来说,这无疑是个令人担忧的消息。据知情人士透露,一些特工担心他们的家庭住址可能会被公开,从而在他们出差时给家人带来安全隐患。
此次数据泄露事件影响范围之广也引发了严重的间谍活动担忧。据多位了解调查情况的人士透露,官员们担心黑客窃取的详细个人数据可能与此前泄露的其他信息一起被用于识别从事敏感工作的特工。
消息人士称,外国政府敌对势力或贩毒集团如果获取到这些信息,可能会利用这些信息来识别正在执行卧底任务或被指派执行他们感兴趣的特定任务的特工。联邦调查局必须努力降低这些雇员面临的安全风险。
敌对势力此前就曾利用联邦调查局的数据进行攻击。根据去年公布的一份司法部监察长报告,2018年前后,一个墨西哥贩毒集团雇佣了一名黑客,监视一名联邦调查局高级官员在墨西哥城的行踪,并从该市的摄像头系统中获取信息,最终导致该集团杀害了潜在的联邦调查局线人。
据知情人士透露,周五,联邦调查局(FBI)就此事向全体员工发送了一封电子邮件,强调了该局对员工及其家人安全的承诺。邮件鼓励员工向FBI安全人员报告任何安全隐患。邮件还指出,FBI目前假定黑客已窃取了所有FBI员工的数据。(《纽约时报》率先报道了这封邮件。)
这对美国顶尖的网络犯罪打击组织之一来说是一个打击,该组织经常被召集来帮助财富 500 强公司清理黑客攻击造成的损失。
据知情人士透露,联邦调查局的网络安全部门、安全部门和受害者服务部门都参与了此次黑客攻击的应对工作。目标是为每位员工提供应对黑客威胁所需的资源。
但至少在初期,一些员工感觉他们无法获得这些资源。一位消息人士称,联邦调查局特工已经开始从内部传言中寻找答案,以了解领导层尚未提供的有关此次安全漏洞的信息。