2026-09-28T23:09:31.394Z / https://www.cnn.com/2026/09/28/politics/fbi-fallout-data-breach-hacking
就在一个犯罪网络宣称窃取了数千名现任及前FBI雇员的敏感个人数据一周后,该局仍在评估事件造成的损害程度,同时面临内部对机构处理此次事件方式的批评。
这是多年来该局遭遇的最严重的数据泄露事件之一,但据现任和前任官员透露,一些FBI雇员对自己是否受到影响毫不知情,且对向受害者提供的安全资源感到不满。
“管理层毫无头绪,”一名与前同事保持联系的前FBI探员告诉CNN。“他们没有向探员提供任何明确的指导。”
CNN已请求FBI就其应对此次黑客攻击的举措置评。
事件始于一周前,黑客闯入了一个存储FBI求职者信息的在线门户。被盗数据包含社会保障号码、紧急联系信息和个人住址。
黑客要求FBI修改此前针对该组织发布的一份公告,称他们对该局描述其涉嫌敲诈受害组织的手段感到“被冒犯”。
FBI内部及网络安全行业的许多人将这一要求视为含蓄威胁,表明黑客将泄露被盗数据。(该犯罪网络如今声称从未计划发布任何被盗数据,但他们此前曾对其他受害者实施过数据泄露发布行为。)
根据FBI针对该组织的公告,此次负责攻击的黑客组织名为“ShinyHunters”,此前曾将“科技、金融和零售行业的大型公司作为目标,通常一次就窃取数百万条客户记录”。
据看过被盗数据的消息人士透露,此次被盗数据包含在针对中国和俄罗斯等议题的敏感部门工作的FBI人员信息。
对于依赖相对匿名身份开展反间谍、反恐和网络犯罪前线工作的FBI探员而言,这是一则令人震惊的消息。据知情人士透露,一些探员担心自己的家庭住址可能被公开,这可能会在他们出差期间给家人带来安全隐患。
此次泄露波及范围之广也引发了严重的反间谍担忧。据多名听取调查简报的人士透露,官员们担心,黑客窃取的详细个人数据若与此前泄露事件中获取的其他信息结合,可能会识别出从事敏感工作的探员。
外国敌对政府或贩毒集团若获取这些信息,可能会利用其试图识别正在卧底或担任其感兴趣的特定职务的探员。消息人士称,FBI将不得不努力降低这些雇员面临的安全风险。
敌对势力此前曾利用FBI数据实施武器化攻击。根据去年公开的美国司法部监察长报告,2018年左右,一个墨西哥贩毒集团雇佣黑客监视墨西哥城一名高级FBI官员的行踪,通过该市监控系统收集的信息,该贩毒集团得以杀害潜在的FBI线人。
据知情人士透露,周五,FBI向全体员工发送了一封关于此次事件的邮件,强调该局对雇员及其家属安全的承诺。邮件鼓励员工向FBI安保人员报告任何安全或安保方面的担忧。邮件称,该局假设黑客已经窃取了所有FBI雇员的数据。(《纽约时报》率先报道了这封邮件。)
这对美国首屈一指的网络犯罪打击组织之一来说是一记重击,该机构经常被邀请协助清理财富500强企业遭遇的黑客攻击事件。
据知情人士透露,FBI的网络安全、安保和受害者服务部门均参与了此次黑客攻击事件的应对工作。其目标是为每位雇员提供应对黑客威胁所需的资源。
但至少在最初阶段,部分员工感觉无法获取这些资源。一名消息人士称,FBI探员只能借助机构内部的谣言渠道,试图寻找领导层未提供的关于此次数据泄露的答案。
FBI grapples with fallout from massive data breach
2026-09-28T23:09:31.394Z / https://www.cnn.com/2026/09/28/politics/fbi-fallout-data-breach-hacking
A week after a cybercriminal group claimed to steal sensitive personal data on thousands of current and former FBI employees, the bureau is still assessing the extent of the damage while facing internal criticism about the agency’s handling of the incident.
It’s one of the most serious breaches of agency data in years, but some FBI employees have felt left in the dark about whether they’re affected and underwhelmed by the security resources being offered to victims, according to current and former officials.
“Management is lost,” one ex-FBI agent in touch with their former colleagues told CNN. “They’re not providing any clear advice to agents.”
CNN has requested comment from the FBI on its response to the hack.
The issue began a week ago, when hackers broke into an online portal hosting information on FBI job applicants. Social Security numbers, emergency contact information and personal addresses were in the stolen data.
The hackers demanded that the FBI amend a previous advisory issued about the group, saying it was “offended” over how the agency described its alleged tactics for extorting victim organizations.
Many at the FBI and within the cybersecurity industry took the demand as a tacit threat that the hackers would leak the stolen data. (The cybercriminal group now claims that it never planned to publish any of the stolen data, but they have a history of doing so with other victims).
The hackers responsible, known as ShinyHunters, have previously targeted “major companies across tech, finance, and retail, often stealing millions of customer records at once,” according to the FBI’s advisory on the group.
In this case, the stolen data includes information on FBI personnel working in sensitive units focused on China and Russia, among other topics, according to sources who have seen the data.
It was alarming news for the FBI agents who rely on relative anonymity to work the front lines of counterintelligence, terrorism and cybercrime. Some agents are worried that their home addresses could be made public, potentially posing a safety issue for their family while they are traveling, according to sources familiar with the matter.
The far-reaching extent of the breach has also raised serious counterintelligence concerns. Officials fear that detailed personal data stolen by the hackers could be used along with other information compromised in earlier breaches to identify agents in sensitive jobs, according to multiple people briefed on the investigation.
Foreign government adversaries or drug cartels could use the information — were they to acquire it — to try to identify agents who are working undercover or are assigned specific roles that are of interest to them. The FBI will have to try to mitigate safety risks to those employees, the sources say.
Adversaries have weaponized FBI data before. A Mexican drug cartel hired a hacker to surveil the movements of a senior FBI official in Mexico City in or around 2018, gathering information from the city’s camera system that allowed the cartel to kill potential FBI informants, according to a Justice Department inspector general report made public last year.
On Friday, the FBI sent an email to the workforce about the incident emphasizing the bureau’s commitment to the safety of employees and their families, according to people familiar with the message. It encouraged employees to report any safety or security concerns to FBI security personnel. The bureau is operating under the assumption that the hackers have stolen data on all FBI employees, the message said. (The New York Times first reported on the email.)
It’s a blow to one of the nation’s premier cybercrime-fighting organizations, which is often called to help clean up hacks at Fortune 500 companies.
The FBI’s cyber, security and victim services divisions are all involved in the response to the hack, according to people familiar with the matter. The goal is to give each employee the resources they need to deal with any threats from the hackers.
But, at least initially, some in the workforce didn’t feel they had access to those resources. FBI agents have turned to agency rumor mills to try to find answers about the breach that leadership haven’t provided, one source said.
发表回复