ShinyHunters, the data theft and extortion crew that has stolen sensitive information belonging to millions of cancer patients, university and K-12 students and Carnival cruisers, wanted to preserve their reputation and keep their “business” afloat.
On Friday, the FBI confirmed the breach to The Register, after earlier in the week saying the bureau was investigating ShinyHunters’ claims.
Then, they breached the FBI’s managed servers on AWS GovCloud and swiped thousands of personnel files belonging to current, former, and prospective FBI workers.
“We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,” the group claimed in a message posted online and addressed to FBI Director Kash Patel and Brett Leatherman, assistant director of the FBI’s Cyber Division.
According to a spokesperson for ShinyHunters, the FBI hack isn’t about the money, and the crew did not demand a multimillion-dollar extortion payment to not leak the agents’ personal details.
The FBI bulletin, published soon after the group breached ed-tech giant Instructure's Canvas platform and claimed to have stolen data tied to hundreds of millions of students, teachers, and staff, said ShinyHunters uses “harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.”
ShinyHunters contends this is all false.
The spokesperson said they and others in the crew started off as GnosticPlayers before rebranding as ShinyHunters in 2020, and that they have since seen the “majority” of GnosticPlayers members arrested.
Alliance Risk CEO David Vainer before told The Register he estimates the figure sits somewhere between $5 million and $30 million.