The Daily - Inside the Devastating Hack of the F.B.I.

Episode Date: September 30, 2026

A little over a decade ago, after hackers broke into the U.S. government and stole the personnel records of millions of federal workers, officials vowed that it would never happen again. Something sim...ilar recently did — to the F.B.I.Dustin Volz, who covers cybersecurity for The New York Times, tells the story of the attack, the group behind it and what could happen to the stolen data.Guest: Dustin Volz, a cybersecurity and intelligence reporter for The New York Times.Background reading: The hackers said they had stolen thousands of sensitive F.B.I. personnel records.The embarrassing breach at the F.B.I. has fueled fears of harm to its employees.Photo: Julia Demaree Nikhinson/Associated Press For more information on today’s episode, visit nytimes.com/thedaily. Transcripts of each episode will be made available by the next workday. Subscribe today at nytimes.com/podcasts or on Apple Podcasts, Spotify and Amazon Music. You can also subscribe via your favorite podcast app here https://www.nytimes.com/activate-access/audio?source=podcatcher. For more podcasts and narrated articles, download The New York Times app at nytimes.com/app. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Transcript
Discussion (0)
Starting point is 00:00:00 From New York Times, I'm Michael Barrow. This is the Daily. A little over a decade ago, after hackers broke into the U.S. government and stole the personnel records of millions of federal workers, U.S. officials found that it would never happen again. It just did, this time, to the FBI. Today, my colleague, cybersecurity reporter Dustin Volz, tells the story of this devastating attack, the group behind it,
Starting point is 00:00:38 and what now happens to the hypersensitive data that those hackers have stolen. It's Wednesday, September 30th. Dustin, welcome back to the Daily. Thank you. Good to be here. Good to have you. You cover the world of hacking cyber attacks, and this hack is a doozy. So can you just describe the scale of what just happened at the FBI?
Starting point is 00:01:13 It is a doozy. And I think more important than the scale, which could be tens of thousands of current and former FBI employees affected here, I think the scope of it is what's really important because the hackers were able to break into a government jobs bore world the FBI uses and not just steal names and phone numbers and emails, but far more sensitive to. about these officials, including their spouse's names, in some cases, their children's names, their addresses, their secretive job titles, and even details that could be used to help a hacker follow them during their travels.
Starting point is 00:01:56 Let me just zero in on one of these staggering things you just said, job titles at the FBI. What kind of job titles were revealed in this hack? So the FBI is a pretty secret organization. A lot of the work they do is public, but a lot of it is behind the scenes. And so the job titles might not be classified, but they are very, very sensitive. And they might reveal things such as an agent working in counterintelligence against foreign spies or working on a China desk or a Russia desk. And these are FBI officials that you sort of never really
Starting point is 00:02:30 hear about. You never meet. And they spend oftentimes decades of their lives working behind the scenes to try to pursue various alleged criminals. So this hack accessed information so detailed that the hackers who now have it can see which people within the FBI are assigned to which of our foreign adversaries. That's very intrusive. It is, and it's not just their job titles. It's also, in many cases, they're supervisors. And in many ways, you almost can build a map of the FBI's.
Starting point is 00:03:06 workforce and see what people are doing, learn more about their investigations, and potentially respond in other ways, depending on what your pursuit or interests are. Right. And your pursuit could be to end such an FBI investigation. Your pursuit could be to seek revenge on an FBI agent, to extort them. Who knows? This information would seem to arm you to do any number of those things. Absolutely. One of the top concerns that I've been hearing for the past week from a number of former FBI officials that I've spoken to, including senior officials who worked on cybersecurity issues, is that these are going to be FBI agents who maybe put violent criminals behind bars, you know, maybe prosecuted the mafia and are now, you know, if the data surface is publicly exposed to forms of retaliation.
Starting point is 00:03:54 You know, I think it's important for people to understand that these types of FBI agents zealously guard their privacy. They do everything they can to make sure their addresses are not listed. These people are not on social media. and now you have this database that is out there that reveals all sorts of intimate details. So given the scale of what you're laying out here, where does this, how does this stack up against previous hacks into the United States government? So about 12 years ago, U.S. officials this morning are blaming Chinese hackers for another serious data breach. The Chinese government hacked the Office of Personnel Management, also known at a personal management, also known OPM, and stole more than 20 million records of U.S. government employees and contractors,
Starting point is 00:04:42 as well as something like 5 million fingerprints. As one official told us, Charlie, this is bad. There is no way to put lipstick on this pig. And that was kind of considered a historic hack of epic magnitude that the Chinese intelligence services would be dining out for years, if not decades. I remember it. Why wasn't this information encrypted? The encryption is one of the many tools that systems can use.
Starting point is 00:05:10 I'll look to my colleagues at DHS for their response. No, I want to know from you why the information wasn't encrypted. It was a huge deal, and it prompted all sorts of congressional hearings. The status was unacceptable when leadership has to resign. Resignation from the director. This was during the Obama administration. And a lot of vows to better protect data, put it behind lock and key. to make sure this never happened again.
Starting point is 00:05:40 Obviously, they failed. They failed. And a lot of officials are telling me that this current hack could be as bad or in some ways worse than what happened with the OPM breach because of the granularity of the data at issue and because of who took it.
Starting point is 00:06:00 Hmm, well, talk about that. Who took it? What do we know about the hackers who did this? Why they did it? precisely how they did it. So the hackers in this case are not a foreign intelligence agency. Instead, they are a loose collective of young criminal hackers believed to be operating in countries around the world.
Starting point is 00:06:22 And these hackers go by the name, shiny hunters. Hackers often have very interesting names. Analysts say that this one seems to be a reference to the popular video game Pokemon in which gamers go after it. is extremely rare and exotic, shiny Pokemon. Got it. So the shiny hunters are out there not to just get everyday paydays, but to score big hits, to bring home big game.
Starting point is 00:06:49 And they are breaking into hundreds of organizations to extort them, in some cases, for payments of millions of dollars. So they're basically in the business of ransomware. Yes, but it's not a traditional ransomware group. Instead of breaking into an organization and locking up their files and demanding payment, what they do instead is they break into an organization, steal all of that data, and then threaten to do things with it, like publish it online, unless they're given a payment via Bitcoin in oftentimes as little as 72 hours.
Starting point is 00:07:23 And they go after all sorts of companies, no matter how big, AT&T, Ticketmaster, educational software used by students around the country and the world. I mean, these are just a few names that stick out. So this would seem to be a real departure from this group's normal MO of going after companies, threatening to release things, getting paid. The FBI is not Ticketmaster, and it's not an education software company. So why target the premier law enforcement agency of the United States? That's a great question. It is certainly audacious to go after the FBI. And it really surprised a lot of people.
Starting point is 00:08:02 It surprised me. It surprised a lot of security researchers. and it certainly surprised, I think, the FBI and a lot of former officials who worked there. The hackers said when they disclosed this hack that essentially they were doing this as a form of revenge. For what? They said they were seeking retribution from the FBI
Starting point is 00:08:23 for a public service advisory that the Bureau issued back in May of this year where they warned that the shiny hunters, hackers are very, very serious and doing a lot of damage and in that they detailed their tactics. The FBI said that they engage in harassment and intimidation of victims to try to secure payment. Such as. Such as revealing private photos that they've stolen from victims,
Starting point is 00:08:50 launching swatting attacks where local law enforcement is called into the address of a victim to scare them maybe with guns drawn, all sorts of harassment type activities that the shodding. Johnny Hunter's group says, hey, look, we extort victims, but we don't do those kinds of things. And the FBI needs to correct the record. So basically, they're mad that they're not being seen by the FBI for the honorable thieves they see themselves to be. They feel like the FBI has incorrectly maligned them as something even worse than they are. Yes, they view themselves as honorable thieves. At least some of them do.
Starting point is 00:09:27 They talk about their work as if it's almost a business that they are running. and they are very good at what they do. And in this case, what they did or what they've claimed to have done is to find a zero-day computer flaw. This is a type of flaw that is unknown to the world that has not been previously disclosed to attack a Oracle PeopleSoft product that is used for helping with HR and financial records and data management for companies. and what they have said is that they use this zero day to compromise the FBI to get this historic and current data from the jobs portal and walk away with it. And so the world learns about this hack last Tuesday when the group posts on its dark web forum that they have hacked the FBI. And in their statement, which calls out Director Cash Patel, as well as the cyber leader of the FBI, they say,
Starting point is 00:10:30 we need you to fix this public service alert or else, essentially. And in that statement, they also include conveniently a email to contact them. So being a reporter, as I am what to do, I reached out to them. I sent them a note and said, hi, I hear that you have hacked the FBI. What a funny position to be in. It was. I honestly did not expect them to respond at all, but they were eager to do so and got back to me, I think, within about 10 minutes. Wow. And that's when they sent me a sample of data that they said was from the hack of the individuals who had their data compromised.
Starting point is 00:11:23 They sent you essentially a sample of the hacked material to prove that they've done what they say they have done. Yes, it was sort of like, you know, we've stolen a lot of stuff and here's a receipt. And they shared that information and said, you know, we have a deadline for the FBI to retract or remove this public statement. Tuesday, September 29th. And the officials and security experts that I spoke with were very much under the impression that they were going to leak some or, or all of the data that they had obtained online. They would publish all this very sensitive FBI personnel data if the FBI didn't meet their demand.
Starting point is 00:12:09 Yes. So the clock is ticking. I am emailing with the hackers. I ask them point blank, what are you going to do if the deadline passes and the FBI does not comply? They say no comment. But meanwhile, the fear and anxiety is growing
Starting point is 00:12:24 in the security community within the FBI that come the deadline, they could do something very dramatic and just publish FBI names and titles and family member names, all of the data online for the whole world to see. And then on Monday, a day before the deadline comes to pass, the hackers reach out with a new message
Starting point is 00:12:48 that twists the story on its head. We'll be right back. So, Dustin, what did these hackers say right before this deadline that ultimately ends a really different, changing the whole direction of this story. So the hackers reach out in a lengthy email and tell me, we have a clarification.
Starting point is 00:13:21 We are not going to publish this FBI data online. Hmm. We are not going to do it. And anybody who thought otherwise was mistaken. So essentially, nothing to see here. Let's all move on. I mean, how do you understand such a complete backing down from their normal tactics? And a sudden claim that the thing,
Starting point is 00:13:43 everyone feared seemingly quite justifiably was, oh, kind of total misunderstanding. Look, far be it from me to try to get inside the minds of a diffuse network of international hackers. But here's what strikes me. The FBI says they are aggressively investigating this, working with third parties to go after the hackers, essentially. They are treating this as a five-alarm fire internally. Meanwhile, the news of the hack is getting more and more attention. The hackers are doling out exclusives to various media outlets about exactly what they've taken. That drumbeat continues. And you see the reaction building, too, from former FBI officials, security experts, saying this is historically bad when we think about the theft of data from the government.
Starting point is 00:14:32 And so all of this is building into a crescendo as this deadline approaches. And that's when the hackers decide to issue this updated statement. Now, like I said, it's hard to know exactly what their motivations are. This is a loose collective of hackers. It's believed to be a bunch of different people working together from across the globe. And so it is very possible that you have different factions that have different views about how hard they want to push this, right? Some might be saying, hey, let's milk this for all it's worth. Let's keep going.
Starting point is 00:15:07 Others might think, you know, maybe we have gotten what we wanted. We got the attention and let's sit back. Right. I mean, it seems quite reasonable to speculate that perhaps one of the factions within this collective of diffuse hackers may have made the claim to the rest of them that what they did here was ultimately maybe just a little too ambitious, that this is not AT&T, this is not Ticketmaster, and that kicking this Hornets Nest, the FBI, that that might be a huge mistake and that it would backfire and that it might even destroy this group. It's hard to know, but it's very possible. And I mean, think of, you know, the mafia or other criminal organizations over the years. Like, this is not an unusual situation where you do have competing factions that might have disagreements about what they should do, how they should carry out their business. However, if they thought they were going to get the FBI off their back by vowing to not publish the data, they were wrong. Hmm.
Starting point is 00:16:04 Wrong how. On Tuesday. I'm Brett Leatherman, assistant director of the FBI's cyber division. Brett Leatherman, who has a great name for an FBI official, came out in a public video. Today, our partners at the Dutch National Police announced the arrest of one of the alleged leaders of Shiny Hunters. And he touts in this video, the recent arrests in the Netherlands of a 24-year-old hacker believed to be a key figure in the Shiny Hunter's group. Now, to the remaining members of Shiny Hunters. And he says, essentially, to the rest of the gang.
Starting point is 00:16:39 Other groups believed anonymity or their friends would protect them, and they were wrong. You know how to find us, and we know how to find you. We are coming after you. I suggest you reach out first while the choice is still yours. Well, while the FBI issues these threats and no doubt is vigorously attempting to find all these hackers and arrest them, the reality is that all of this data is still floating around. within the hackers' computer systems, and I suppose even in the email of some reporters.
Starting point is 00:17:15 That's right. So just because the hackers said they're not going to publish it, first of all, they could change their mind and decide to do that later. But also, there's nothing to stop them from selling the hacked data to the highest bidder or multiple bidders, including Russian and Chinese intelligence agencies that might have deep interest in learning everything they can about the FBI's workforce.
Starting point is 00:17:39 So the idea that this is the end of the story is definitely not the case because this is data that is now out there. They've shared it with several different news outlets. There are security researchers who have come forward and publicized that they have also obtained the sample data set as well. It's unclear how. But once you start sharing data with other people, it tends to take on a life of its own. And it really can't be put back in the box.
Starting point is 00:18:07 I have to ask, Dustin, because I'm genuinely curious and listeners maybe, too, you said you got a sample of this hacked material. What do you, what do we, the Times, do with this if I can ask? You know, this was a difficult issue for us to deal with internally. Should we even look at it? And if we look at it, what should we do with it? Should we analyze it? Should we report on it? How much should we report on it?
Starting point is 00:18:34 These were a lot of questions we had internally with our lawyers and our standards. team about sort of how do we want to handle this material that is out there. Mm-hmm. We are not sharing it with anyone, and we are securing it to the best of our ability. So what seems clear is that the FBI, when it comes to this data, is not at all out of the woods. And that makes me want to go back to, Dustin, what you had described as the government's response to that infamous OPM hack all those years ago, when it said, we're never going to let this happen again, and it does happen again. Because ultimately, this feels like a very meaningful, not just security breakdown, but a betrayal of people at the FBI who signed up for really sensitive law enforcement work
Starting point is 00:19:24 within understanding that their personal information would be protected implicitly. That's a reasonable bargain to reach with your employer if your employer is the FBI. and instead the FBI left its personnel system so vulnerable that this hack happened. And these workers are now in real unnecessary peril. That's right. You know, I think there's a lot of current and former officials that we've been hearing from at the FBI who are very frustrated about the situation and made clear to us that they didn't even know that a data set like this existed. And had questions about why it existed and why would there be a place where there's a repository of so much,
Starting point is 00:20:03 intimate information that seemingly is kept for years without being deleted, without being purged, that a hacker could access and take. And a lot of these officials said, you know, working for the FBI can be a dangerous job. I sign up for this, but my family doesn't. And the fact that this data set includes emergency contacts, spouses, siblings, in some cases, children, That is, I think, what is especially alarming to a lot of the people who work at the FBI, that it's not just them that have to worry about it, but their entire families in some cases. And to me, this demonstrates that even though the government has come a long way since that last big hack, that hack of OPM, it still has a very long way to go to protect its systems,
Starting point is 00:21:00 and more importantly, to protect its people. Well, Dustin, thank you very much. I appreciate it. Thank you for having me. You can read more from Dustin Volz and all of our reporters on the New York Times app. If you don't already have the app, we want to let you know that if you download it right now, you'll get access to all of our journalism free for one month. So give it a try. We'll be right back.
Starting point is 00:21:52 Here's what else you need to another day. The Times reports that in the months before OpenAI's artificial intelligence went rogue and attacked the startup company Hugging Face, two OpenAI employees raised an alarm with their superiors but were ignored. In emails, the employees worried that OpenAI's newest artificial intelligence models were not being appropriately monitored during testing. In response, their superiors said that that testing needed to be, move ahead to meet deadlines. And workers said that no new safety protocols were created.
Starting point is 00:22:33 And in a temporary victory for the Trump administration, the Supreme Court allowed the government to keep deporting people to countries they aren't from and may have no connection to. These so-called third-country deportations, including to authoritarian countries with human rights abuses, were the focus of Monday's episode of the show. And while the justices cleared the way for those deportations to continue for now, they fast-tracked a final ruling in the case for next year. Today's episode was produced by Alex Stern,
Starting point is 00:23:17 Olivia Nat, and Eric Kruppke, with help from Jack DeSidoro. It was edited by Annie Minoff. Contains music by Pat McCusker, Rowan Misto, and Diane Wong. and was engineered by Alyssa Moxley. Our theme music is by Wonderly. That's it for the daily.
Starting point is 00:23:47 I'm Michael Bobara. See you tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.