2026-10-09T17:19:42.074Z / 美国有线电视新闻网(CNN)
作者:肖恩·林加斯、埃文·佩雷斯
2小时前发布
发布时间:2026年10月9日美国东部时间下午1:19
内森·霍华德/路透社
据两名了解此事的消息人士透露,FBI已在宾夕法尼亚州逮捕一名男子,官员认为该男子协助策划了近期一起造成重大损失的黑客攻击事件,该事件导致FBI现任及前雇员的敏感数据被泄露。
FBI局长卡什·帕特尔于周五宣布了此次逮捕行动,但未透露逮捕地点以及该男子涉嫌在此次黑客攻击中所扮演的角色。
“本周早些时候,我们的外勤特工逮捕了另一名被认为是此次黑客攻击所属网络犯罪集团共犯的嫌疑人,”帕特尔周五表示。
消息人士称,调查人员仍在追查其他涉嫌参与此次黑客攻击的人员。
上周,FBI宣布荷兰当局已逮捕该犯罪集团“所谓的头目之一”,该集团名为“赏金猎人”(ShinyHunters)。
相关阅读
凯文·卡特/盖蒂图片社/资料图
FBI应对大规模数据泄露风波 阅读时长:4分钟
《纽约时报》最先报道了这名在宾夕法尼亚州被捕男子的消息。
FBI拒绝向CNN提供更多细节。
此次FBI的强力行动发生在该局数年来遭遇的最严重数据泄露事件之一之后。“赏金猎人”集团于上月宣称对入侵FBI招聘门户网站一事负责,并获取了数千名现任及前FBI雇员的个人数据。据看过泄露数据的消息人士透露,负责中俄敏感事务的FBI人员身份已被曝光。
“赏金猎人”通过其暗网网站要求FBI修改此前针对该集团发布的预警公告,称其对FBI在公告中描述该组织勒索受害机构的所谓手段感到“被冒犯”。网络安全行业内多数人将这一要求视为“赏金猎人”会泄露被盗数据的默示威胁。但黑客随后声称,他们从未有过泄露数据的意图。
美国有线电视新闻网此前曾报道,一些FBI雇员对此次事件后为受害者提供的安全资源感到不满。
在内部批评和媒体监督之下,帕特尔和FBI高级网络官员布雷特·莱斯曼发布了一系列公开声明和视频信息,通报调查进展。其中一些信息是直接针对网络犯罪分子的。
“逮捕行动会改变那些愿意开口的人的心态,而被缴获的网络基础设施则能帮我们锁定剩余人员,”莱斯曼在荷兰当局逮捕嫌疑人后发布的一段视频中说道,“你在这场游戏里待得越久,我们对你的了解就越多。你知道该如何联系我们,我们也知道该如何找到你。我建议你主动联系我们,选择权现在还在你手上。”
FBI内部也针对此次重大安全漏洞的发生原因展开了调查。莱斯曼上周表示,FBI经调查认定,负责管理该局招聘门户网站的一名承包商未对“专门用于保护该平台”的软件进行更新。他还表示,FBI已“解雇了该承包商”。
“赏金猎人”称,涉事软件是甲骨文公司开发的一款人力资源平台。据谷歌威胁情报小组透露,该黑客组织曾在今年5月和6月利用该软件的漏洞攻击教育行业目标。但时隔数月后,FBI的这名承包商显然仍未安装针对该软件的安全补丁。
FBI arrests key suspect in major hack of agents’ data
2026-10-09T17:19:42.074Z / CNN
By Sean Lyngaas, Evan Perez
2 hr ago
PUBLISHED Oct 9, 2026, 1:19 PM ET
The logo of the Federal Bureau of Investigation is displayed on a building in Washington, DC, on November 28, 2025.
Nathan Howard/Reuters
The FBI arrested a man in Pennsylvania who officials believe helped orchestrate a recent damaging hack that exposed sensitive data of current and former FBI personnel, according to two sources familiar with the matter.
FBI Director Kash Patel announced the arrest on Friday but did not disclose where it occurred or what role the man is suspected of playing in the hack.
“Earlier this week, our agents in the field arrested another suspected co-conspirator” of the cybercriminal group believed to be responsible for the hack, Patel said on Friday.
An investigation is ongoing into other people believed to be involved in the hack, the sources said.
Last week, the FBI announced that Dutch authorities arrested “one of the alleged leaders” of the criminal group, known as ShinyHunters.
Related article The seal of the Federal Bureau of Investigation, displayed at the J. Edgar Hoover Building in Washington, DC, on August 8. Kevin Carter/Getty Images/File FBI grapples with fallout from massive data breach 4 min read
The New York Times first reported on the arrest of the man in Pennsylvania.
The FBI declined to provide additional details to CNN.
The forceful FBI response comes after one of the most serious breaches of the bureau’s data in years. ShinyHunters last month claimed responsibility for breaking into an FBI jobs portal and gaining access to the personal data on thousands of current and former FBI employees. The identities of FBI personnel working in sensitive units on China and Russia were exposed, according to sources who have seen the data.
ShinyHunters used their dark-web site to demand that the FBI amend a previous advisory issued about the group, before the hack, saying it was “offended” over how the agency described its alleged tactics for extorting victim organizations. Many in the cybersecurity industry took the demand as a tacit threat that ShinyHunters would leak the stolen data. The hackers later claimed that was never their intention.
Some FBI employees felt underwhelmed by the security resources being offered to victims of the breach, CNN previously reported.
Amid the internal criticism and media scrutiny, Patel and a senior FBI cyber official, Brett Leatherman, put out a series of public statements and video messages with updates on the investigation. Some were addressed to the cybercriminals.
“Arrests have a way of changing who is willing to talk and seized infrastructure has a way of showing us who is left,” Leatherman said in a video posted after the arrest by Dutch authorities. “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
There has also been an inquest at the FBI over how such a critical security lapse happened. The FBI determined that a contractor managing the bureau’s jobs portal failed to update software “explicitly issued to secure the platform,” Leatherman said last week. The FBI has “removed the contractor,” he said.
The software in question is a human-resources platform made by Oracle, ShinyHunters has said. The hackers previously used a flaw in the software to attack targets in the education sector in May and June, according to Google’s Threat Intelligence Group. But months later, the FBI contractor apparently still had not applied a security patch that was available for the software.
发表回复