Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

FBI investigates claims of widespread agent data theft

According to reports, the Federal Bureau of Investigation is looking into allegations from a cyber criminal group that it has acquired sensitive personal information belonging to all bureau personnel. The group claims to possess details for approximately 38,000 individuals, including names, roles, badge numbers, and private contact information.

According to reports, a cyber criminal collective, known as Shiny Hunters, has asserted that it successfully breached the FBI's systems and exfiltrated comprehensive personal data concerning all its agents. The alleged stolen information reportedly includes names, job assignments, badge numbers, home addresses, phone numbers, and details about spouses. The group began contacting journalists, providing samples and screenshots of the purported data.

The FBI has acknowledged the claims and stated it is actively and aggressively investigating the matter. If confirmed, this incident represents a highly significant data breach due to the sensitive nature of the information and the individuals involved. Data protection officers should review their organisation's incident response plans, particularly concerning breaches involving highly sensitive personal data and potential national security implications, and ensure robust employee data protection measures are in place.

This incident highlights the critical importance of protecting employee personal data, especially for organisations handling sensitive information.

Who this binds
FBI
What changed
The FBI confirmed it is investigating claims of a data breach affecting its personnel.

Send this to your team

A cyber criminal group claims to have stolen sensitive personal information belonging to all FBI agents, prompting an investigation by the bureau.

Today's question

A cyber criminal group claims to have exfiltrated sensitive personal information, including names, roles, badge numbers, home addresses, phone numbers, and spouse details, for approximately 38,000 personnel from a federal agency. The agency has acknowledged the claims and is actively investigating. What is a key immediate action for data protection officers in other organisations, as highlighted by this incident?

  1. Review their organisation's incident response plans, especially for breaches involving highly sensitive personal data and national security implications.
  2. Assess the territorial scope of the alleged data breach to determine if international data transfer regulations apply to their own organisation.
  3. Update their organisation's data processing agreements with third party vendors to include specific clauses on national security data.
  4. Conduct a comprehensive data protection impact assessment for all employee data processing activities within their organisation.

Answer this question on the site

Worth knowing

  1. Wayne Memorial Hospital and Regional Urology settle data breach lawsuits

    Healthcare privacy professionals should note that these settlements demonstrate ongoing financial and legal consequences for US healthcare providers like Wayne Memorial Hospital and Regional Urology following data breaches.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.