
A week after a cybercriminal group announced the theft of sensitive personal data of thousands of current and former employees of the US Federal Bureau of Investigation (FBI), the bureau is still assessing the extent of the damage, while facing internal criticism over its handling of the incident, as employees felt they were left without clear information about whether they had been harmed or not, and resented the security resources available to victims.
AI-generated summary
Hostile actors have previously exploited FBI data for hostile purposes. A Mexican drug cartel hired a hacker to monitor the movements of a high-ranking FBI official in Mexico City in 2018, gathering information from the city's surveillance camera system that enabled the gang to kill potential FBI informants.
CNN) - A week after a cybercriminal group announced the theft of sensitive personal data belonging to thousands of current and former employees of the US Federal Bureau of Investigation (FBI), the bureau is still assessing the extent of the damage, while facing internal criticism over its handling of the incident.
This breach is considered one of the agency's most serious data breaches in years, but some employees felt they were left without clear information about whether they had been harmed or not, and they also expressed dissatisfaction with the security resources available to victims, according to current and former officials.
A former agent in the office, who is still in contact with his former colleagues, told CNN: “The management is lost; they do not provide any clear advice to clients.”
CNN requested comment from the FBI about its response to the hacking operation.
The problem began a week ago, when hackers penetrated an electronic portal containing information for applicants to work in the office. The stolen data included social security numbers, emergency contact information, and personal addresses.
The hackers asked the office to amend a previous warning it issued regarding the group, expressing their dissatisfaction with the way the agency described their alleged methods of blackmailing victim institutions.
Many within the office and in the cybersecurity sector viewed this demand as an implicit threat that the hackers would leak the stolen data. The criminal group now claims that it never planned to publish any of the stolen data, but that it has a history of doing so with other victims.
The group responsible for the hack, known as ShinyHunters, had previously targeted “major companies in technology, finance, and retail, often stealing millions of customer records at once,” according to the warning the office issued about the group.
In this case, the stolen data includes information about office employees working in sensitive units focused on China and Russia, among other files, according to sources who have seen the data.
This news constituted a source of great concern to the office’s agents, who depend on a degree of confidentiality and anonymity while working on the front lines to combat espionage, terrorism, and cybercrime.
Some members are concerned about the possibility of their home addresses being revealed to the public, which could pose a threat to the safety of their families during their travel, according to sources familiar with the matter.
The widespread scope of the hack also raised serious counterintelligence concerns. Officials fear that the detailed personal data stolen by the hackers - combined with other information stolen in previous breaches - could be used to identify agents in sensitive positions, according to several people briefed on the details of the investigation.
Hostile government entities or drug gangs can use this information - if they obtain it - to try to identify agents working undercover or assigned to specific tasks that interest those entities.
Sources indicate that the FBI will have to work to reduce the security risks that these employees may face.
Hostile parties have previously exploited FBI data for hostile purposes. A Mexican drug cartel hired a hacker to monitor the movements of a high-ranking bureau official in Mexico City in 2018, collecting information from the city's surveillance camera system that enabled the gang to kill potential FBI informants, according to a report by the Justice Department's inspector general published last year.
On Friday, the office sent an email to employees about the incident, stressing its commitment to the safety of employees and their families, according to people who saw the message.
The letter urged employees to report any safety or security concerns to the office's security personnel, and the letter also explained that the office was dealing with the situation based on the assumption that hackers had stolen data belonging to all office employees.
The New York Times was the first to publish news about this letter.
This incident is a strong blow to one of the most prominent national institutions concerned with combating cybercrime, an institution that is often called upon to help address the effects of breaches suffered by major companies listed in the Fortune 500 magazine.
The office's security, cybercrime, and victim services divisions are all involved in the hack response efforts, according to informed sources; The goal is to provide each employee with the necessary resources to deal with any threats that may arise from hackers.
However, some employees felt, at least initially, that they had no access to these resources.
One source said FBI agents turned to rumor sources within the agency to try to find answers about the hack, answers that were not provided by leadership.
AI outlook — possibilities, not facts
The office will issue formal guidance to employees on personal protection steps after the internal assessment is completed
Likely · Within days
Pressure will increase on the office to improve its transparency in communicating with employees during cyber incidents
Possible · Within weeks

The Chinese artificial intelligence company DeepSec is close to raising 80 billion yuan in a financing round with support from Catel and Tencent, in a move aimed at strengthening its technological independence and developing its advanced models away from total dependence on American chips.

An OpenAI official admitted before the Australian Parliament to mishandling the hacking of an artificial intelligence program into a government website, coinciding with a report comparing the foldable Samsung Galaxy Z Fold8 and iPhone Duo.
During a New York City Council session, former employees who left Anthropic, OpenAI, and Google DeepMind warned of a reckless culture at major technology companies, stressing that the race to develop uncontrollable technologies could lead to humanity losing control over artificial intelligence and perhaps the extinction of the human race, while prominent executives agreed on the need to slow down development.

Italian Prime Minister Giorgia Meloni has submitted a request to the European Union Intellectual Property Office to register her voice as a trademark to protect herself from artificial intelligence-generated deepfake clips. The request included a four-second audio recording in which the phrase “I am Giorgia Meloni” is repeated twice, and the request is still under consideration.

The Norwegian government intends to propose a temporary ban on the use of glasses equipped with artificial intelligence and cameras in public places, to protect individuals from audio or video recording without their knowledge, with the exception of private uses.

A Pew Research Center study examines the spread of content written with artificial intelligence on the Internet, and presents expert opinions on the challenges of processing the Arabic language and the impact of automated models on writing style and human creativity.