🛡 VULNERABILIDADES 🛡

Exclusivo: ShinyHunters Asegura que Datos del FBI No Serán Filtrados al Terminar el Ultimátum

🛡CyberObservatorio
Exclusivo: ShinyHunters Asegura que Datos del FBI No Serán Filtrados al Terminar el Ultimátum
Idioma

Exclusivo: ShinyHunters Asegura que Datos del FBI No Serán Filtrados al Terminar el Ultimátum

Fuente: HackRead

### La ambigua postura del grupo de extorsión ShinyHunters sobre los datos del FBI

En un contexto donde la ciberseguridad se ha convertido en una preocupación primordial para instituciones gubernamentales y empresas privadas, el grupo de hackers conocido como ShinyHunters ha levantado una ola de inquietud tras sus declaraciones sobre la supuesta apropiación de datos del FBI. Este grupo, que ya ha sido vinculado con varios incidentes de hacking, ha afirmado que no tiene intención de publicar ni vender la información que afirma haber robado, aclarando su posición mientras se acerca el final del plazo que había concedido a la agencia para corregir o retirar un polémico informe sobre cibercrimen.

A través de una declaración exclusiva enviada a Hackread.com, ShinyHunters subrayó que desde un inicio había decidido no liberar los datos del FBI. En su misiva, el grupo describió la atención mediática generada por su supuesta violación de la seguridad del FBI y su mensaje posterior como una “campaña de marketing” destinada a resaltar su desacuerdo con las afirmaciones realizadas sobre ellos en un informe de la agencia. “La razón por la que hemos declarado en múltiples ocasiones que esto no es extorsión es porque, desde el principio, tomamos la decisión de que nunca publicaríamos estos datos”, afirmaron.

Imagen del articulo

Esta aclaración llega tras el ataque que el grupo perpetró el 22 de septiembre contra el portal de empleos del FBI. Según reportó Hackread.com en su momento, ShinyHunters logró desfigurar el portal y afirmó haber comprometido otros sistemas de la agencia después de obtener acceso inicial a través de lo que describieron como una vulnerabilidad de día cero en Oracle PeopleSoft.

Los hackers indicaron que su punto de entrada fue la dirección apply.fbijobs.gov y aseguraron haber realizado movimientos laterales hacia otros servicios, incluyendo la infraestructura de AWS GovCloud. Según sus propias afirmaciones, el grupo descargó entre 2 TB y 3 TB de información, que incluía datos de empleados del FBI y de solicitantes de empleo.

La respuesta del FBI no se hizo esperar, confirmando que estaba investigando las alegaciones de actividad no autorizada que afectaban a FBIJobs.gov y la supuesta exposición de información personal identificable de empleados. En un comunicado, el FBI mencionó que estaba al tanto de un grupo de delincuencia cibernética que alegaba haber comprometido este portal y el posible impacto en la información personal de los empleados del FBI.

Posteriormente, los hackers publicaron un mensaje extenso dirigido al director del FBI, Christopher Wray, y a Brett Leatherman, director asistente de la División Cibernética del FBI. En este mensaje, ShinyHunters expresó que su comunicación era una respuesta a lo que consideraban acusaciones falsas por parte de la agencia. En particular, el grupo se opuso a las afirmaciones del FBI que indicaban que ShinyHunters podría exagerar sus aseveraciones sobre el acceso a información sensible, utilizar tácticas de acoso, e incluso amenazar a las víctimas y sus familias.

La amenaza de “dar una semana” al FBI para corregir o retirar lo que consideraban acusaciones falsas fue una de las partes más controvertidas de su mensaje. ShinyHunters insistió en que sus amenazas y afirmaciones eran reales y “nunca un engaño”, al tiempo que reiteraron que su acción contra el FBI no tenía motivaciones financieras ni se trataba de un intento de extorsión. Sin embargo, no especificaron qué ocurriría si el FBI no cumplía después de una semana.

Algunos informes de medios y discusiones públicas interpretaron este periodo de una semana como un ultimátum, después del cual se publicaría la información robada. Ahora, el grupo sostiene que esa interpretación fue incorrecta, afirmando que nunca especificaron lo que sucedería al finalizar la semana. “Redactamos nuestras declaraciones con mucho cuidado y nunca aclaramos ni especificamos lo que haríamos si la entidad víctima no cumplía dentro del plazo que el público interpretó como un ‘ultimátum’”, indicaron.

El grupo también admitió que había evitado responder a las preguntas de los periodistas sobre lo que sucedería si el FBI no accedía a sus demandas. Reiteraron que nunca se refirieron al periodo de una semana como un “ultimátum” y que el objetivo de su demanda era ganar visibilidad para su disputa con el FBI.

ShinyHunters se defendió argumentando que la atención generada por su mensaje inicial era parte de una estrategia de marketing para proteger su negocio y combatir activamente la desinformación. “Si hubiésemos hecho esta declaración de forma normal, entonces esta atención a nuestras palabras e intenciones nunca hubiera sido tan amplia”, explicaron.

El grupo reconoció que su mensaje original podría haber sido interpretado de manera diferente, sobre todo debido a sus operaciones previas que involucraban datos corporativos robados. “Esto no fue una amenaza. Puede haber sido redactado como una amenaza, pero en última instancia, el público ha llevado esta historia fuera de contexto y ha hecho sus propias suposiciones y especulaciones”, afirmaron.

A pesar de la confusión generada, ShinyHunters rechazó que su intención fuera buscar dinero en el caso del FBI y reiteró que nunca planeó publicar la información que dice poseer. “Nada sucederá”, afirmaron en relación al final del periodo de una semana.

Con todo, este comunicado no retracta la afirmación subyacente del grupo de que comprometieron los sistemas del FBI o que obtuvieron información sensible. Simplemente cambia la narrativa sobre lo que buscan hacer con esa información. El FBI, por su parte, ha reconocido que está investigando el supuesto compromiso, pero no ha confirmado públicamente la cantidad ni el contenido total de los datos que el grupo afirma haber obtenido.

En un panorama donde las amenazas cibernéticas son cada vez más sofisticadas y frecuentes, este episodio subraya la vulnerabilidad de las instituciones gubernamentales y la necesidad urgente de reforzar las medidas de seguridad para proteger la información sensible de los ciudadanos.

Exclusive: ShinyHunters Says FBI Data Won’t Be Leaked When Ultimatum Ends

Source: HackRead

The ShinyHunters extortion group says it will not publish or sell the FBI data it claims to have stolen, clarifying its intentions as the one-week period it gave the agency to correct or remove a disputed cybercrime report approaches its end. In a statement sent exclusively to Hackread.com, the group said it had decided from the beginning that the alleged FBI data would not be released. The group described the publicity surrounding its FBI breach and subsequent message to the agency as a “marketing campaign” intended to draw notice to its dispute with claims made about the group in an FBI report. “The reason why we have stated multiple times that this is not extortion is because since the very beginning we had made our decision that we would never publish this data,”ShinyHunterstold Hackread.com. “We have never intended to nor have we ever planned to.” The clarification follows the group’s September 22attack on the FBI Jobs portal. As Hackread.com reported at the time, the group defaced the portal and claimed to have compromised other FBI systems after gaining initial access through what it described as an Oracle PeopleSoft zero-day. The hackers later told Hackread.com thatapply.fbijobs.govwas their entry point and claimed they moved laterally into other services, including AWS GovCloud infrastructure. The group claimed to have downloaded between 2TB and 3TB of information, including FBI employee and job applicant data. The FBI later confirmed it was investigating claims of unauthorized activity affecting FBIJobs.gov and alleged exposure of employee personally identifiable information. The FBI is aware of a cyber-criminal enterprise group claiming a compromise of thehttps://t.co/CXFsC8cNUAportal and alleged impact to FBI employee personally identifiable information (PII). While the point of breach is still undetermined—whether a third-party or the FBI’s… Following the breach, the hackers published a lengthy message addressed toFBI Director Kash Pateland Brett Leatherman, assistant director of the FBI’s Cyber Division. The group said it was responding to what it considersfalse allegationsmade by the FBI about the group. The message specifically objected to FBI statements that ShinyHunters may exaggerate claims of access to sensitive information, use harassment tactics including threatening victims and their family members or swatting, and falsely claim to possess sensitive or compromising material. The hackers denied those activities and also rejected being associated with “The Com.” The message gave the FBI “a time of 1 week” to correct or remove what it described as false allegations. In its original message, the group said its threats and claims were real and “never a bluff,” while insisting that its action against the FBI was neither financially motivated nor an extortion attempt. The original message repeatedly denied financial motivation and described the episode as neither ransom nor extortion. It did not, however, specify what would happen if the FBI declined to comply after one week. Some media reports and public discussion interpreted the one-week period as a deadline, after which the stolen FBI data would be published. The group now says that interpretation was incorrect and that it never stated what would happen when the week ended. “We worded our statements very carefully and we never clarified nor specifically stated what we would do if the victim entity did not comply within what the public interpreted as a ‘deadline’,” the group told Hackread.com. The group also said it deliberately declined to answer journalists who previously asked what would happen if the FBI did not comply. It also said it never referred to the one-week period as a “deadline.” Explaining the one-week demand, the group told Hackread.com that gaining publicity for its dispute with the FBI was part of the plan. “This was all a marketing campaign to protect our business and actively combat disinformation,” the group said. “If we made this statement normally, then this much attention to our words and intentions would’ve never been this widespread.” The group acknowledged that its original message could have been interpreted differently, particularly given its previous operations involving stolen corporate data. “This was not a threat. It may have been worded like a threat, but ultimately the public has driven this story out of context and made their own wild assumptions and speculations,” the group said. The group also acknowledged why people might expect the information to be published or sold, pointing to its own history. It saidprevious operationscould explain why some readers interpreted the FBI message as an indication that stolen information would eventually be released. For the FBI case, the group again denied seeking money and said it had never planned to publish the information it claims to possess. “Nothing will happen,” ShinyHunters told Hackread.com about the end of the one-week period. The statement does not withdraw the group’s underlying claim that it compromised FBI systems or obtained sensitive information. It changes what the hackers say they intend to do with that information. The FBI has acknowledged investigating the alleged compromise but has not publicly confirmed the amount or full contents of the data the group claims to have obtained. Umbreon Image by Hung Tran fromPixabay–FBI Photo by David Trinks onUnsplash)

Exclusivo: ShinyHunters Asegura que Datos del FBI No Serán Filtrados al Terminar el Ultimátum | Ciberseguridad - NarcoObservatorio