网络犯罪团伙声称窃取美国联邦调查局人员及求职者数据


2026-09-23 16:59:58 EDT / 哥伦比亚广播公司新闻

作者

一个臭名昭著的网络犯罪团伙声称已于周一入侵美国联邦调查局(FBI),并窃取了该机构人员及求职申请者的相关数据。

这个自称为“猎影者(ShinyHunters)”的团伙,在暗网发布的通讯内容及与多家媒体的沟通中声称,他们窃取了2至3太字节的与FBI及司法部工作人员相关的数据。黑客们称他们利用了人力资源管理软件甲骨文PeopleSoft的一个新漏洞。

监控数据泄露网站的开源勒索软件情报档案库RansomLook已捕获并存档了两份以“猎影者”名义发布的声明,内容涉及该团伙声称入侵FBI一事。

周二,“猎影者”在一篇致FBI局长卡什·帕特尔(Kash Patel)及FBI网络部门助理局长布雷特·莱斯曼(Brett Leatherman)的帖子中称:“我们已经入侵了FBI。”

这些网络犯罪分子表示,他们掌握了几乎所有FBI探员以及申请FBI职位人员的敏感信息。他们列出受影响的服务包括刑事司法、人力资源及Medlink系统。

周二,FBI职业招聘页面顶部显示“系统不可用”的提示,内容为:“Apply.fbijobs.gov网站及特别探员申请者门户目前无法访问。如遇紧急日程安排问题,请联系您的申请者协调员。给您带来不便,我们深表歉意。”

FBI尚未确认此次入侵事件,但于周二表示,其已“留意到有关未经授权活动影响FBIjobs.gov网站的声称,目前正在调查中”。

周三,该机构发布了更详细的声明:“FBI已留意到一个网络犯罪企业团伙声称入侵了FBIJobs.gov门户,并声称影响了FBI员工的个人身份信息(PII)。虽然入侵点仍未确定——无论是第三方还是FBI自身的企业系统——我们正在积极主动地调查此事,并与支持FBIJobs.gov网站的第三方提供商密切合作,以降低任何及所有风险。”

路透社及404 Media报道称,黑客向这些媒体提供的部分数据与真实的FBI或司法部人员信息相符,但两家媒体均未证实这些记录来自FBI系统。哥伦比亚广播公司新闻也未独立核实这些发现。

FBI文件证实,该机构的招聘部门确实在使用PeopleSoft软件及AWS GovCloud。虽然“猎影者”的声称尚未被哥伦比亚广播公司新闻核实,但此次新软件漏洞、FBI系统遭入侵及大规模数据窃取事件均具有合理性。

在“猎影者”被RansomLook存档的帖子中,该团伙抱怨FBI在2026年第二季度发布的一份快报报告,并驳斥了该局对该团伙及其作案手法的定性。该团伙称,FBI曾暗示“猎影者”有时会夸大其入侵权限、骚扰受害者或其亲属、参与“爆警”(swatting)行动,并虚假声称掌握对方的敏感材料。该团伙还对FBI对其的描述提出异议,否认其勒索要求是以牟利为目的,并拒绝将其行动定性为勒索、胁迫或敲诈。

2026年5月,FBI发布了两则与“猎影者”相关活动的警告。5月8日的快报公告描述了该团伙的“生态系统”——警告称其会窃取凭证、滥用可信供应商及云服务关系,还会实施数据窃取和敲诈,有时还会伴随骚扰行为。

一周后,美国互联网犯罪投诉中心(IC3)发布咨询警告,称使用“猎影者”名义的作案者可能会真实或夸大其入侵权限、威胁受害者及其亲属、参与“爆警”行动,并虚假声称掌握敏感材料,以此向目标施压。

在这两则警告中,FBI都建议相关组织不要支付赎金或与该团伙进行任何交涉。

该团伙给FBI下达了一周期限,要求其“更正或删除”此前快报报告中的部分内容。

今年早些时候,5月25日至6月9日期间,谷歌也记录到“猎影者”利用了另一个甲骨文PeopleSoft的零日漏洞。

哥伦比亚广播公司新闻已联系甲骨文公司置评。

“猎影者”是一个至少自2020年以来一直活跃的网络敲诈团伙。尽管该团伙因大规模数据及云服务盗窃行为而广为人知,但安全研究人员并不将其视为一个单一固定的组织,而是将其视作一个不断变化的威胁行动者生态系统。

这至少是今年以来影响FBI及其员工的第三起潜在重大网络事件。

今年3月,FBI披露其侦测到针对其某一系统的可疑网络活动。该系统存储非保密及执法敏感信息,例如电话记录器——这是一种实时记录电话号码、IP地址、信令及其他信息的监控工具——以及追踪溯源监控返回数据,还有与FBI刑事调查对象相关的个人身份信息。

同月晚些时候,帕特尔的个人电子邮件账户遭到与伊朗有关联的黑客攻击。

雅各布·罗森(Jacob Rosen)与莎拉·N·林奇(Sarah N. Lynch)为本报道撰稿。

Cybercriminal group claims it stole FBI personnel and applicant data

2026-09-23 16:59:58 EDT / CBS News

By

A notorious cybercriminal group claims it breached the FBI on Monday and stole data about personnel and job applicants.

The group, which calls itself ShinyHunters, claimed in communications posted on the dark web and exchanges with multiple media outlets that it stole 2 to 3 terabytes of data related to FBI and Justice Department workers. The hackers claim to have used a new vulnerability with Oracle PeopleSoft, a human resources management program.

RansomLook, an open-source ransomware intelligence archive that monitors data leak sites, has captured and archived two statements posted under the ShinyHunters identity concerning the group’s claimed FBI breach.

On Tuesday, ShinyHunters claimed in a post that was addressed to FBI Director Kash Patel and FBI Cyber Division Assistant Director Brett Leatherman: “We have compromised the FBI.”

The cybercriminals said they possessed sensitive information concerning nearly all FBI agents, as well as people who applied for FBI jobs. It listed criminal justice, human resources and Medlink systems among the services that were affected.

On Tuesday, the home page for FBI careers had a “System Unavailable” message at the top of the page. It read, “Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable. For urgent scheduling issues, please reach out to your Applicant Coordinator. We apologize for the inconvenience.”

The FBI has not confirmed the breach, but said Tuesday it was aware “of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.”

On Wednesday, the agency offered a more detailed statement: “The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII). While the point of breach is still undetermined — whether a third party or the FBI’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.”

Reuters and 404 Media reported that portions of data supplied by the hackers to those media outlets correspond to real FBI or Justice Department personnel, though neither has established that the records came from FBI systems. CBS News has not independently verified these findings.

FBI documents confirm that the agency’s recruiting arm uses PeopleSoft and AWS GovCloud. The new software vulnerability, breach of the FBI’s systems and large-scale data theft are plausible, though ShinyHunters’ claims have not yet been verified by CBS News.

In the group’s post, which was saved by RansomLook, ShinyHunters complained about an FBI FLASH report issued during the second quarter of 2026 and disputed the bureau’s characterization of the group and its tactics. The group said the FBI had suggested that ShinyHunters sometimes exaggerates access, harasses victims or relatives, participates in swatting and falsely claims to possess compromising material. The group also took issue with the FBI’s description of ShinyHunters, denying that its demands are financially motivated and rejecting descriptions of their actions as ransom, coercion or extortion.

In May 2026, the FBI issued two warnings related to ShinyHunters-linked activity. A May 8 FLASH bulletin described what it called the group’s ecosystem — warning of stolen credentials, abuse of trusted vendor and cloud relationships, plus data theft and extortion sometimes involving harassment.

A week later, an Internet Crime Complaint Center (IC3) advisory cautioned that actors using the ShinyHunters name may make real or exaggerated claims of access, threaten victims and relatives, engage in swatting and falsely allege they hold compromising material in order to pressure targets.

In both warnings, the FBI advised organizations not to pay or engage with their demands.

The group gave the FBI a deadline of one week to “correct or remove”portions of the earlier FLASH report.

Earlier this year, from May 25 through June 9, Google also documented ShinyHunters exploiting a different Oracle PeopleSoft zero-day vulnerability.

CBS News has reached out to Oracle for comment.

ShinyHunters is a cyber extortion group that has been active since at least 2020. While it is widely known for executing large-scale data and cloud theft, security researchers treat it not as one single, fixed entity, but rather as a shifting ecosystem of threat actors.

This is at least the third potentially major cyber incident to impact the FBI or its employees so far this year.

In March, the FBI revealed it had detected suspicious cyber activity targeting one of its systems. That system stores unclassified and law enforcement sensitive information, such as pen registers — which are surveillance tools that record phone numbers, IP addresses, signaling and other information, in real time — and trap-and-trace surveillance returns, as well as personally identifiable information related to subjects of FBI criminal probes.

Later that same month, Patel’s personal email account was targeted by hackers linked to Iran.

Jacob Rosen and Sarah N. Lynch contributed to this report.

评论

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

湘ICP备2026001899号-2