Hackers stole data on thousands of employees. FBI then sent out cybersecurity awareness reminder
The theft by a criminal hacking group of reams of sensitive personal data involving potentially tens of thousands of former and current F.B.I. employees is emerging as one of the worst breaches of sensitive government information, leaving the bureau rushing to protect its personnel as an uncertain deadline loomed.
Nearly a week after the group, known as ShinyHunters, revealed it had pilfered intimate details about bureau personnel from the agency’s jobs portal and threatened to leak them online, F.B.I. investigators are still piecing together how the breach took place and the total damage.
The hack appears to have swept up home addresses, Social Security numbers, secretive job assignments and much more, according to a New York Times analysis of some of the records. Some are already comparing it to China’s breach of more than 20 million records from the Office of Personnel Management over a decade ago, considered so catastrophic that officials and lawmakers vowed to never let something like it happen again.
Many F.B.I. employees first learned about the hack when news reports about it surfaced on Tuesday, according to current and former officials. The next day, F.B.I. staff received an email reminding them that October is cybersecurity awareness month, which struck some as tone deaf in light of the breach, one of those people said.
On Friday, bureau leaders, in an internal memo to its rank and file, declared the hack a cybersecurity incident and acknowledged its employees had personal information stolen.
“We are operating under the premise that the threat actor is also exfiltrating PII of all F.B.I. employees,” according to the memo, which was described by someone who had seen it, using the abbreviation for personally identifiable information.
The memo said the agency would offer virtual briefings in the weeks ahead and instructed employees to remain vigilant at home and at work, report any unsolicited contacts or threats, avoid answering calls from unknown numbers and set up voice mail accounts with A.I.-generated voices. “Bureau leadership remains committed to supporting the safety of you and your family,” it said.
Still, many past and present personnel remain in the dark about whether their data has been purloined. In recent days, some have anxiously asked Times reporters whether their names are contained in the hacked data, wondering whether they needed to take steps to protect themselves or their families. [Continue reading…]