专家称,此次黑客攻击可能使探员面临诈骗、勒索和针对性攻击。作者:乔·泰迪。入侵美国联邦调查局(FBI)的网络犯罪分子称,他们掌握该局数千名特别探员高度敏感的医疗数据。
Experts say the hack could leave agents vulnerable to scams, blackmail and targeted attacks. By Joe Tidy Cyber-criminals who hacked the FBI say they have extremely sensitive medical data for thousands of its special agents.
英国广播公司新闻部看到了被盗“适岗体检”资料的样本,其中包括血液和尿液检测结果,以及医生备注中提到的“贝类和香蕉过敏”等信息。
BBC News has seen samples of the stolen "fitness-for-work" medical examinations, which contain information such as blood and urine test results, and doctors' notes mentioning conditions such as a "shellfish and banana allergy".
这些记录包括探员的完整姓名和住址,以及与医疗问题有关的信息,如“尿血”和“高胆固醇”。
The records include agents' full names and addresses, as well as references to medical concerns including 'blood in the urine' and 'high cholesterol'.
专家表示,这起黑客攻击——FBI目前正在调查——可能使探员面临诈骗、勒索和针对性攻击,还可能帮助犯罪分子冒充执法人员。
Experts say the hack - which the FBI is investigating - could leave agents vulnerable to scams, blackmail and targeted attacks, as well as help criminals impersonate law enforcement officers.
“这份名单将数千名探员与其医疗和适岗记录对应起来,”Cato Networks威胁情报副总裁伊泰·毛尔说。
"The list maps thousands of agents against their medical and fitness records," said Etay Maor, vice-president of threat intelligence at Cato Networks.
“密码被盗后可以重置,但医疗记录不能。因此,一旦这些数据外泄,就会永久面临安全风险。这种永久性的风险覆盖整个员工队伍,正是此次泄露之所以如此严重的原因。”FBI尚未回应置评请求。不过,该局周三承认发生了数据泄露,并表示正在“积极调查”事件是如何发生的。
"Passwords can be reset if stolen, but medical records cannot, so once this data is out, it stays compromised for good. That permanence, applied across an entire workforce, is what makes this leak so serious." The FBI has not responded to requests for comment. However, on Wednesday it acknowledged the breach and said it was "aggressively investigating" how it happened.
网络犯罪组织ShinyHunters声称已于周一入侵FBI系统,随后在其暗网网站上发布了有关此次攻击的详细信息。该组织还向记者分享了所谓被盗数据的样本,并提出勒索要求。
The cyber-criminal group ShinyHunters claims it breached FBI systems on Monday, and later posted details of the attack on its darknet site. The group also shared samples of the alleged stolen data with reporters, along with an extortion demand.
不同寻常的是,这些黑客并没有索要金钱,而是要求撤回FBI于5月发布的一份通报,并声称该通报“冒犯”了他们。
Unusually, the hackers are not demanding money. Instead, they are seeking a retraction of an FBI advisory published in May, which they claim "offended" them.
向记者分享的样本似乎是真实可信的,其中包括姓名、住址、电话号码、警徽编号、职务以及配偶信息。这些记录似乎涉及数千名探员,其中包括副局长等高级官员。
The samples shared with journalists appear genuine and include names, addresses, phone numbers, badge numbers, job titles and information about spouses. The records appear to relate to thousands of agents, including senior officials such as deputy directors.
英国国家网络安全中心的前负责人基兰·马丁教授表示,如果这次黑客攻击被证实属实,那么这将是“数据泄露事件中最严重的一次”。据路透社报道,被盗的数据中包含了一些与俄罗斯、中国及贩毒集团有关的调查人员的个人信息。
Professor Ciaran Martin, the former head of the UK's National Cyber Security Centre, has described the hack - if confirmed - "as serious as it gets when it comes to data breaches." 'Phishing, impersonation, identity fraud' The news agency Reuters reports that some of the data includes information on agents involved in investigations relating to Russia, China and drug cartels.
最初人们认为此次攻击仅影响了FBI现有的38,000名员工,但黑客们声称实际受影响的人数可能远高于这个数字。
It was initially thought the breach affected the FBI's 38,000 current employees, but the hackers now claim the number could be far higher.
CyberSmart公司的首席执行官兼联合创始人杰米·阿克塔尔表示,虽然应对黑客的说法应保持谨慎,但此次数据泄露事件确实非常令人担忧。他解释说:“这些数据可能被用于制造极具说服力的网络钓鱼攻击、身份欺诈、敲诈勒索,甚至针对执法人员的恶意行动,其潜在后果极其严重。”
The group says it underestimated the scale of the data theft and now claims to hold sensitive information on around 60,000 current and former FBI staff. Jamie Akhtar, chief executive and co-founder of CyberSmart, said the hackers' claims should be treated with caution but that the breach appeared to be extremely concerning. "Such data could be used for highly convincing phishing, impersonation, identity fraud, blackmail or even operations targeting law-enforcement personnel, making the potential implications particularly serious," he said.
这些黑客通过即时通讯工具Telegram用英语与记者联系,并声称如果FBI不满足他们的要求,他们将在五天内公开所有被盗数据。
The hackers, who communicate with reporters in English via the messaging service, Telegram, say they will publish the full dataset in five days unless the FBI meets their demands.
ShinyHunters是一个自2019年以来一直活跃的国际黑客组织,曾参与多起备受关注的网络攻击事件,包括针对Rockstar Games和教育平台Canvas的攻击。该组织声称利用了FBI使用的Oracle云存储系统中的漏洞,从而获得了多个系统的访问权限,这些系统包括用于员工和申请人背景调查的FBIJobs、存储医疗记录的FBI MedLink,以及存放调查信息的FBI BICS。
ShinyHunters is an international hacking collective that has been active since 2019 and has been linked to a number of high-profile cyber-attacks, including incidents affecting Rockstar Games and the education platform Canvas. The group claims it exploited a vulnerability in an Oracle cloud storage system used by the FBI, gaining access to multiple platforms including FBIJobs, FBI BEAST, which handles background checks on employees and applicants, FBI MedLink, which stores medical records, and FBI BICS, which contains investigative information.
FBI在X(前Twitter)上发布的声明中表示,他们仍在调查这些黑客究竟是直接入侵了其系统,还是通过第三方服务提供商实施了攻击。"我们正在积极主动地调查此事,并与支持 FBIJobs.gov 的第三方供应商密切合作,以消除任何和所有风险,"声明称。关注全球顶尖科技新闻与趋势。不在英国?
In a statement posted on X, the FBI said it was still trying to determine whether the hackers had breached its systems directly or compromised a third-party provider. "We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk," the statement said. to follow the world's top tech stories and trends. Outside the UK? Sign up here.