FBI says contractor’s failure led to his employment website being hacked

WASHINGTON — The FBI’s internal review of a hack of its job portal last month has so far determined that a “security lapse” on the part of a contractor running the site was to blame for the breach.

“To date, our review has determined that the incident occurred as a result of a security failure of a platform managed by a third-party organization – after a contractor failed to implement a security patch explicitly issued to secure the platform,” Cyber ​​Division Deputy Director Brett Leatherman said in a statement Tuesday.

The statement said the FBI fired the contractor, whom it did not identify, “and has taken all necessary steps to mitigate any additional risk and protect our personnel. We will continue to bring responsible parties to justice, with multiple arrests already underway.”

The hack of the FBIJobs.gov portal took place late last month and ShinyHunters, a cyber-extortion company, claimed credit for it.

A representative for the group told NBC News at the time that it used the job portal to access other agencies’ programs, stealing between 2 and 3 terabytes of files. NBC News has not been able to verify the extent of the allegations.

Leatherman’s statement appears to confirm that the agency believes ShinyHunters is responsible.

“The FBI will aggressively investigate this cyber incident involving FBIjobs.gov and the ShinyHunters cybercrime group with all available resources,” its statement said.

FBI Director Kash Patel announced on social media last week that a member of the group had been arrested. The arrest took place on September 15, a week before ShinyHunters claimed credit for the attack.

“This morning, the FBI and our partners, the Netherlands National Police, announce the arrest of one of the suspected leaders of ShinyHunters, a global group of cybercrime and threat actors linked to cyberattacks in the United States, the Netherlands, and around the world,” he wrote.

“As we speak, FBI teams are actively working with our partners to obtain and execute more leads in the ongoing investigation based on this arrest,” his post on X reads.

Some FBI employees were upset after learning of the hack through the media and said the agency was slow to respond, a person familiar with agency communications said last week.

The FBI said in a previous statement that it was “in regular communication with anyone who may be affected” and that the agency “treats the security of its information and that of its personnel as top priorities.”

ShinyHunters is a loosely defined group, with members scattered around the world. He regularly hacks companies to steal their data and threatens to publish it on the dark web if he is not paid.

Gn bussni

Scroll to Top