The FBI Data Breach Is a Counterintelligence Disaster
On Sept. 23, the FBI disclosed it is investigating a claim from the hacking group ShinyHunters that it stole thousands of FBI employees’ personal information. ShinyHunters claimed to the news website 404 Media, which first broke the story, “We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job.” The FBI, in its advisory on the hacking group published in May, noted that ShinyHunters frequently harasses victims to extort with the victims’ allegedly stolen data—but that claims might be “exaggerated” and that threat actors “may falsely claim to have sensitive or compromising information” simply to elicit a payment.
Details are still unfolding about the incident. ShinyHunters provided 404 Media with a sample of the supposed data. It spanned 5,000 alleged FBI employees and included home addresses, phone numbers, dates of birth, and in some cases, details on the person’s spouse. When 404 Media put some of the information into an open-source intelligence tool, some of the data reportedly checked out. For now, there is at least some indication that the data is real—as are the breach’s victims.
If the FBI data breach is real, it is a counterintelligence disaster for the United States. Foreign adversaries, including Russia and China, are constantly attempting to hack into the United States to steal information, such as trade secrets, classified information, and data on the American public writ large. Having this information in the hands of a hacker group, from which a sophisticated nation-state could potentially steal it—or, even worse yet, having this information published or sold on the dark web, from which any number of threat actors could access it—would expose thousands of FBI personnel to profiling, phishing, foreign intelligence approaches, and much more. Not to mention, having their home addresses out there could lead to doxing (publication of personal information with the intent to intimidate or incite violence), swatting (triggering an armed police response from a bogus 911 call), and even violent retribution, particularly for those working cases such as organized crime, counterterrorism, human trafficking, and similar matters.
As the investigation unfolds, the details will help outline the potential incident’s impact. If the hackers have targeted and broken only into the FBI’s online job portal, then investigators will need to understand the bounds of that data, including when the intrusion was first successful, how much data was available in the system at the time (including at what date the data begins), and how long the hackers were in the system (to figure out the last date at which newly uploaded data may have been compromised). These are not novel questions for cybersecurity experts investigating a breach. But they are critical for understanding the scope of the data exposed. If the hackers penetrated systems beyond the job portal, including other systems that connect to the job portal—although no public details have suggested this happened—then the scope of data theft could be even greater.
The incident is a potential counterintelligence nightmare given how much data it may have exposed and who the victims might be. New FBI hires could go into a number of careers. Some may have applied directly to job areas whose activities and missions are of high interest to foreign nation-states, such as jobs that entail investigating or prosecuting sanctions evasion, export control violations, thefts of intellectual property from U.S. companies, foreign cyber intrusions, terrorism, and intelligence operations both on U.S. soil and against U.S. interests globally. Intelligence services in China, Russia, and Iran could ostensibly try to exfiltrate the data themselves from the cybercriminal group’s servers; an adversary could also, if the data is sold or made available on the dark web, access the data for a lump-sum payment or simply traverse the dark web and click a download button. Knowing who applied to those jobs would enable foreign adversarial governments to try to identify anyone susceptible to blackmail, phish their devices to spy on them, build organizational maps of who works where, and much more. The data would be highly exploitable against the United States.
Illustrating this risk, subsequent reporting from Reuters found that some of the data covers FBI personnel in intelligence-related roles. Job descriptions in the breached dataset for some of those individuals, according to Reuters, span phrases such as human intelligence (HUMINT, or the running of human spies), “data intercept,” “telecom intercept,” “clandestine technical operations,” and roles related to Russia, China, Iran, Hezbollah, and critical infrastructure. Additional digging from 404 Media supposedly identified FBI employees with jobs in the Major Cybercrime Unit and those whose job was described as “remote operations units,” which the journalists concluded refers to a sophisticated hacking capability within the bureau. Those individuals are precisely the kind of public servants that a foreign intelligence or security service in China, Russia, or elsewhere might wish to metaphorically unmask—and potentially target. Even knowing the way that jobs and teams are described could aid a foreign adversary in better understanding, and therefore countering, an organization like the FBI, too.
And those risks just pertain to what could be done in the moment. In the future, a few FBI employees who began working white-collar crime investigations or federal weapons cases could go on to work counterterrorism, sanctions evasion, cases that involve hunting Chinese or Russian spies, and so forth. Suddenly, knowing their names and whose social media accounts and devices to monitor, going back years, is even more valuable to an adversary trying to track and disrupt U.S. national security operations—as well as recruit their own sources within the U.S. government.
The supposedly breached FBI data, exploited years down the line, would be as if a nation-state hacked a U.S. military academy, stole information on all the cadets, and used that data to start building dossiers on every single person in the data, so that someone who later goes into a special forces unit, intelligence role, or senior commanding position could have their names and personal data laid out clearly from the initial breach. Novel artificial intelligence data analytic capabilities make this problem even worse, allowing nation-states that could access this or other breached data to conduct more sophisticated pattern analysis and anomaly detection within datasets. The end goal is all about exploitation against U.S. security interests.
Beyond counterintelligence threats, it is essential to mention that nation-states and other threat actors, including organized crime groups and domestic violent extremists, could use data on FBI employees’ names, home addresses, and spouses to dox them. They could use it to swat FBI agents and their families, sending armed police storming into their homes based on a bogus 911 call, as bad actors increasingly do to public officials. They could even use it to attempt violent retribution against those individuals—perhaps for contributing to the prison sentence of a friend or family member, disrupting a lucrative business operation, dismantling a terror cell, or fighting domestic violent extremism, within the bounds of the law and the Constitution, at home.
Public servants, their families, and their children already face growing violent threats around the country, across the political spectrum. The types of public servants targeted are numerous, including mayors, school board members, county clerks, 911 call center operators, and state legislators, among others. Some in the national security community, especially military service members, face threats already at some of the highest rates. Having this data available online adds to the enormous pools of data already available on public servants and every other American. As it stands, outdated, legalistic approaches to public records privacy allow data brokers to harvest and then post online for search and sale the data of virtually every single American, including, undoubtedly, current and prospective FBI employees. This has been an enormous problem for stalking and gendered violence in the American population writ large for years. As more data on public servants is breached and political actors work to stigmatize and dehumanize public servants, incidents such as the FBI data breach make a data-to-violence pipeline problem even worse.
To address this incident, the FBI and the U.S. government will first need to verify its authenticity and then map its scope. From there, it can identify particular countermeasures that are needed, such as enhanced online threat monitoring and data scrubbing (to the extent possible), physical security measures, and cybersecurity measures for its impacted current or prospective employees. It is possible that additional, more sensitive measures need to be taken to protect people working certain jobs. But it is also a critical reminder of the policy failures at play.
Nation-states and cybercriminals can theoretically break into any system at any time; no database or computer is impenetrable. But it certainly doesn’t help U.S. cyber defenses when political leaders decide to gut the Cybersecurity and Infrastructure Security Agency, arbitrarily fire public servants across the national security apparatus, cut or shut down intelligence community components looking at future threats, and reassign federal agents normally working cyber issues—including cybercrime, the very modus operandi of the group allegedly behind this incident—to work on immigration roundups and deportations. These are people whose skill sets, knowledge, and, in many cases, experience are vital to supporting U.S. cyber defenses.
Foreign adversaries don’t stop trying to hack, steal, and exploit U.S. data just because of domestic changes within the United States. This breach is a reminder that while ordinary and reasonable changes can occur in any government at any time, there’s a much greater chance that discord in the U.S. national security and cybersecurity posture will contribute, one way or another, to major incidents that harm the country. Such chaos adds to the fact that U.S. government agencies, including the FBI, have been warning about the dangers of internet-connected systems for well over a decade at least (if not longer in some cases), without always shoring up important flaws in their own infrastructures.
What needs to be done right now is not a mystery. The U.S. government needs to reinvest in cybersecurity hiring and talent development, focusing on the full talent life cycle, from public education and talent recruitment all the way to employee retention and community post-job departure or retirement. It needs to ensure cybersecurity requirements and best practices are properly adopted across its contracting apparatus, so that the right controls are in place any time a federal system, such as a job portal, connects to an outside, third-party vendor. The same goes for any time a private company provides any tech-related assistance, product, or service to the U.S. government. Relatedly, federal legislators and policymakers should continue to consider in what cases, and at what points, different private-sector companies may or should be held liable for harms associated with software insecurity.
Policymakers also need to curtail the amount of exploitable data widely available on the commercial data broker market. Doing so, beyond reducing a threat surface in and of itself, can help ensure that when criminal actors or nation-states hack a dataset or buy it on the dark web, it is not so easy to combine it with troves of other data, such as on FBI employees’ online search activity, phone geolocations, finances, and beyond. But perhaps most importantly, the U.S. national security community needs to begin to question if it fully appreciates just how much foreign adversaries may consider data—including American data—to be a strategic asset for exploitation.
The FBI data breach, if it’s real, is a glaring counterintelligence and physical safety threat. It will hardly be the last.
