No, The FBI Didn’t Warn Of An International Cyberattack—Its Email Was Hacked
Image ID 148214040 © via Pop Nukoonrat | Dreamstime.com
If you recently received an email from the Federal Bureau of Investigation (FBI) warning of a cyberattack, it’s possible the message could be fake. Over the weekend, hackers gained access to the agency’s external email system, sending out thousands of spam emails to individuals and organizations.
The FBI said that the spam messages were sent via the Law Enforcement Enterprise Portal system, which is used to keep in touch with state and local officials, and was fortunately not part of the agency’s main corporate email service.
“No actor was able to access or compromise any data or (personally identifiable information) on FBI’s network. Once we learned of the incident, we quickly remediated the software vulnerability, warned partners to disregard the fake emails, and confirmed the integrity of our networks,” the bureau said.
According to The Washington Post, cybersecurity experts noted that the fake emails sent by the hackers didn’t contain malicious attachments or viruses, which could mean that they weren’t using a pre-planned attack to exploit the portal’s vulnerability. It’s posited that the hackers weren’t able to access any of the FBI’s internal databases, including state secrets or classified documents.
“It could have just been a group or individuals looking to get some street cred to tout on underground forums,” explained Austin Berglas, a former assistant special agent at the FBI’s New York office cyber branch.
“I would think that it would be some sort of criminal group or some sort of ‘hacktivist’ group,” he said.
As per The Spamhaus Project, a watchdog tracking international cyber threats, the email’s subject line read: “Urgent: Threat actor in systems,” with the note claiming to be from the Department of Homeland Security. It said the emails had resulted in “a lot of disruption because the headers are real, they really are coming from FBI infrastructure,” causing recipients to think the threat was imminent.
Within the message was a reference to hacking group the Dark Overlord, which has been known to demand hefty ransoms after stealing important data. Back in 2017, the group allegedly stole students’ records in several states, as well as select shows on Netflix. The “threat actor” named in the email, Vinny Troia, is actually a cybersecurity expert who wrote about the group’s activities last year.
“These are very childish actions intended to discredit me for putting out a report which exposed [a hacker’s] identity and involvement in several other hacking groups, including the Dark Overlord, Gnostic Players, and Shiny Hunters,” said Troia.
Thankfully, as Berglas put it, the hackers didn’t use the FBI’s email account for more villainous means. He said: “When you have ownership of a trusted dot-gov account like that, it can be weaponized and used for pretty nefarious purposes. [The FBI] probably dodged a bullet.”
[via The Washington Post, cover image via Pop Nukoonrat | Dreamstime.com]
Also check out these recent news