
WASHINGTON — The FBI’s internal review of a hack of its jobs portal last month has so far determined that a “security failure” by a contractor managing the site caused the breach. “To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” Cyber Division Assistant Director Brett Leatherman said in a statement Tuesday. The statement said the FBI has removed the contractor, which it did not identify, “and taken all necessary steps to both mitigate any further risk and protect our workforce. We will continue to bring the responsible parties to justice, with multiple arrests already occurring.”The hack of the FBIJobs.gov portal took place late last month, and ShinyHunters, a cyber-extortion outfit, claimed credit for it.A representative of the group told Jattvibe News at the time that it used the job portal to gain access to other agency programs, stealing between 2 and 3 terabytes of files. Jattvibe News was not able to verify the extent of the claims. Leatherman’s statement appeared to confirm that the agency believes ShinyHunters is responsible.“The FBI will aggressively investigate this cyber incident involving FBIjobs.gov and the cyber-criminal group ShinyHunters with all available resources,” his statement said.FBI Director Kash Patel announced on social media last week that a member of the group had been arrested. The arrest took place on Sept. 15, a week before ShinyHunters claimed credit for the attack. “This morning @FBI and our partners the Dutch National Police are announcing the arrest of one of the alleged leaders of ShinyHunters — a global cybercrime and threat actor group linked to cyberattacks in the United States, the Netherlands, and around the world,” he wrote.“As we speak FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest,” his post on X said. Some FBI employees were upset to have learned about the hack from the media and said the agency had been slow to respond, a person familiar with the agency’s communications said last week. The FBI had said in a previous statement that is “in regular communication with anyone who may be impacted,” and that the agency “treats the security of its information and the safety of its workforce as top priorities.”ShinyHunters is a loosely defined group, with members scattered around the globe. It routinely hacks companies to steal their data and threatens to publish it on the dark web if not paid.


