Ransomware gang ShinyHunters boldly attacked the FBI this week, alleging that it hacked into the FBI’s job site, defaced it, then stole sensitive records of employees and applicants, including human resources records of current employees.

The gang alleges that it exploited a vulnerability in Oracle’s PeopleSoft product that enabled remote code execution allowing them to download between two and three terabytes of data. The group released a sampling of the data to journalists, including FBI employees’ names, home addresses, telephone numbers, Social Security numbers, assignments, dates of birth, and details about relatives.

ShinyHunters says it attacked the FBI following an FBI cyber alert published in May that the gang alleges made false statements.

While ShinyHunters’ claims have not been verified, picking a fight with the agency that is responsible for prosecuting cyber crime is surely an escalation that the FBI will no doubt respond to in kind.

Those using Oracle’s PeopleSoft are urged to update the software with patches when they become available.

Photo of Linn Foster Freedman Linn Foster Freedman

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her…

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her practice on compliance with all state and federal privacy and security laws and regulations. She counsels a range of public and private clients from industries such as construction, education, health care, insurance, manufacturing, real estate, utilities and critical infrastructure, marine and charitable organizations, on state and federal data privacy and security investigations, as well as emergency data breach response and mitigation. Linn is an Adjunct Professor of the Practice of Cybersecurity at Brown University and an Adjunct Professor of Law at Roger Williams University School of Law.  Prior to joining the firm, Linn served as assistant attorney general and deputy chief of the Civil Division of the Attorney General’s Office for the State of Rhode Island. She earned her J.D. from Loyola University School of Law and her B.A., with honors, in American Studies from Newcomb College of Tulane University. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.