ArsTechnica

FBI rushes to investigate if ShinyHunters hack of thousands of employees is real

To get the advisory changed, ShinyHunters told FBI director Kash Patel and the assistant director of the FBI Cyber Division, Brett Leatherman, that they had one week to comply with demands or presumably risk a breach of sensitive employee data.

FBI warns employees to be safe

Not many details have been released on how ShinyHunters got access to the data. ShinyHunters would only tell NYT that “it had weaponized a zero-day, or previously undiscovered, computer bug within the Oracle PeopleSoft software, an application that companies use for human resources and financial management.” So far, Oracle is silent on that bug, reports said, while ShinyHunters said it plans to continue using the zero-day for its “businesses’ normal operations.”

The FBI has not confirmed that the hack occurred, but it has begun probing the claims. On Wednesday, the FBI said in an X post that “the point of breach is still undetermined—whether a third-party or the FBI’s enterprise.” Until more information is known, the FBI said, “we are actively and aggressively investigating this matter and working closely” with third-party providers that support the jobs site “to mitigate any and all risk.”

As of Wednesday, the jobs site remained inaccessible, as sources inside the FBI told Bloomberg that all personnel received an email warning them to “take steps to protect themselves while the investigation continues.”

ShinyHunters has not said what will happen if the FBI misses the deadline, but cybersecurity experts told the NYT that most likely the data will be leaked online.

“We cannot comment on what we will do if the FBI does not comply with our request,” ShinyHunters said in an email to the NYT. “We reiterate we are not extorting the FBI and this is NOT financially motivated.”

“Our intention, goal, and motive is solely to set the record straight,” the group said.



Source link