FBI Hack Exposed FBI’s Own Hacking Unit


FBI Hack Exposed FBI’s Own Hacking Unit

The catastrophic hack of at least thousands of FBI officials’ personal data, including their addresses, phone numbers, and even their spouses, includes members of the FBI’s secretive hacking team, potentially revealing who exactly is in that unit, 404 Media has found.

The findings further highlight how sensitive the stolen data is, and how valuable it may be to criminals or to foreign intelligence agencies. There is very little public information about the FBI’s hacking unit, including the operations it conducts, the tools it uses, or which agents are part of it.

💡
Do you work at the FBI? Do you know anything else about this hack? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

The FBI said in a statement it “is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII). While the point of breach is still undetermined — whether a third-party or the FBI’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.”

404 Media first broke news of the breach on Tuesday. The group responsible, ShinyHunters, shared a list of 5,000 alleged FBI officials with 404 Media. 404 Media verified parts of the data by cross-referencing it with open source records available in the research tool OSINT Industries, and previously compromised data in Darkside, a tool made by cybersecurity company District 4.

As well as the officials’ personal information, the list of 5,000 officials includes each person’s job title or team. Those include titles such as Special Agent, Threat Intake Examiner, and Major Cyber Crimes Unit. Reuters reported on Wednesday some of the job titles include those related to investigating China or Russia. 

404 Media found three of the entries in the data specifically mention “remote operations units.” The Remote Operations Unit, or ROU, is the FBI’s hacking unit. For much of the previous decade, the ROU was focused on making and deploying tools to investigate the dark web, according to a 2020 report from the Office of the Inspector General. The ROU was “instrumental” in developing the network investigative technique (NIT) — the FBI’s parlance for a hacking tool — the agency deployed on a dark web child abuse site the FBI ran for two weeks in order to identify site visitors.

After budget decreases, its focus has shifted to tools for national security investigations, the report says. Much of the rest of that report discussing the ROU is redacted.

The parts of the hacked data related to the ROU expose each person’s address, a list of phone numbers for them, and in some cases the name of their spouses and their phone numbers. 404 Media searched one of the ROU official’s phone numbers in Darkside, and found previously breached data indicating they used to work for the Secret Service.

One person in the data also appears to be a student, with the data describing them as a “student workforce trainee.”

The ROU has previously used classified hacking tools in ordinary criminal investigations, raising questions over whether defendants were able to scrutinize how evidence against them was collected.

Scroll to Top