Info

This Week in Security: ShinyHunters Won’t Dox the FBI

This Week in Security: ShinyHunters Won’t Dox the FBI

404 Media reports that the ShinyHunters group who stole multiple terabytes of FBI employee data say they do not plan to release the data. Known for ransomware and extortion of …. This Week in Security: ShinyHunters Won’t Dox the FBI, Pentagon Data Stolen, and OBS Vulnerable.

Known for ransomware and extortion of innumerable companies and government agencies, ShinyHunters used a zero-day vulnerability in Oracle PeopleSoft to compromise the employment site of the FBI and pivot into scraping the content of FBI AWS instances, claiming to have the full employment and health data of all FBI agents, employees, and spouses. The hacker group took exception to an FBI press release that claimed that the group over-stated stolen data and that they directly harass victims and victim’s families. The group publicized the FBI data breach, demanding a retraction of the statements, and it was generally assumed that the group would follow their typical methods of releasing the data publicly if the demands were not met.

The group has told 404 media that they had always agreed internally to not release the stolen data, saying “This was all a marketing campaign to protect our business and actively combat disinformation”. Meanwhile the FBI continues the investigation, and Shiny Hunters may be hoping to defer some of the ire. Pentagon Data Breach A data breach at the Defense Manpower Data Center lasted for nine months before it was discovered, and allowed unknown attackers to exfiltrate information on military personnel.

The information stolen includes social security numbers and “operational specialty” data about where a service member is employed within the armed forces.


Discover more from ChuckysCarnage

Subscribe to get the latest posts sent to your email.

Leave a comment