The FBI is scrambling to assess what one expert calls a potentially history-making data breach that may have exposed intimate details on tens of thousands of its own people, the New York Times reports. Criminal hacking group ShinyHunters says it broke into FBIJobs.gov and grabbed home addresses, Social Security numbers, TSA PreCheck IDs, emergency contacts, background check information including medical and psychiatric data, and even sensitive assignment details for current and former bureau employees, including those in counterintelligence and national security roles, per the Times.
ShinyHunters publicly framed the hack as retaliation for an FBI warning about the group and initially threatened to leak the data unless the advisory was altered or removed, then later claimed it never planned to publish the files and called the operation a "marketing campaign." Security analysts warn the data could still be sold to criminals or foreign intelligence services and say the breach could rival or surpass the impact of the Office of Personnel Management hack carried out by China more than a decade ago, adding to a troubling record of recent security lapses at the bureau.
An internal memo told staff to assume all personally identifiable information was taken and urged them to be on guard at home and work, but CNN spoke to potentially affected people who are "underwhelmed" at the security resources they've been offered, and "in the dark" as to whether they were affected. Meanwhile, the CBC takes a closer look at ShinyHunters, which is linked to dozens of other major data breaches.