The hackers have claimed to have hacked the anti-hackers. FBI rushes to investigate if ShinyHunters hack of thousands of employees is real - Ars Technica
Some day, government agencies will take security seriously, but today, is not that day. (Apologies to Aragorn, in LotR: RotK.)
On Tuesday, 404 Media reported that ShinyHunters took down the agency site, FBIJobs.gov, then posted a banner on the homepage that said “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.”
About two to three terabytes of data were taken, ShinyHunters told The New York Times. None of the data has been leaked yet, but it included “names of current and former agents as well as applicants and corresponding home addresses, phone numbers, names of spouses, certain medical information, and other data.”
None of the data has been published, but I can't imagine that will last. And the FBI - Funded, But Incompetent - has not admitted that the data is real.
Why would hackers do such a thing? Because they were mad that the FBI published false allegations about ShinnyHunters, and they were "severely offended." (Seems legit to me.)
In a message posted on the dark web that was reviewed by Ars, ShinyHunters said it was “severely offended” that the FBI alleged that they sometimes use “exaggerated claims” to extract payments from victims. “We wish to state unequivocally our threats and claims are very real,” the group said. “Not exaggerated and never a bluff.”
And they are not looking for money. They want the FBI to set the record straight, according to their version of the facts.
The group’s motive was not to extort the FBI or seek a ransom, it claimed. Instead, the strike was meant to force the FBI to either remove or edit a May advisory warning about ShinyHunters that the group said circulated “disinformation in an attempt to ‘disrupt’ our operations.”
That information being that ShinnyHunters engaged in SWATting and Sextortion, which they deny.
The section of the FBI that they are really targeting, is the FBI Cyber Division, headed by Brett Leatherman. Click thru for the details. It would be interesting to know how they penetrated the FBI. It seems it was a job applicant and HR site, so it may be by way of a 3rd party, or it could be that site was viewed as low priority. But the federal government has been hacked many times.
The largest hack of the US Government, that I am aware of, was the 2015 hack of The Office of Personnel Management. That impacted 21.5 million people, both inside and outside the government.