Security

Hackers publish personal data on thousands of US police officers and federal agents

Comment

Image Credits: Drew Angerer / Getty Images

A hacker group has breached several FBI-affiliated websites and uploaded their contents to the web, including dozens of files containing the personal information of thousands of federal agents and law enforcement officers, TechCrunch has learned.

The hackers breached three sites associated with the FBI National Academy Association, a coalition of different chapters across the U.S. promoting federal and law enforcement leadership and training located at the FBI training academy in Quantico, VA. The hackers exploited flaws on at least three of the organization’s chapter websites — which we’re not naming — and downloaded the contents of each web server.

The hackers then put the data up for download on their own website, which we’re also not naming nor linking to given the sensitivity of the data.

The spreadsheets contained about 4,000 unique records after duplicates were removed, including member names, a mix of personal and government email addresses, job titles, phone numbers and their postal addresses.

The FBINAA could not be reached for comment outside of business hours. In a statement Saturday the FBINAA said it was working with federal authorities to investigate the breach. “We believe we have identified the three affected Chapters that have been hacked and they are currently working on checking the breach with their data security authorities.”

TechCrunch spoke to one of the hackers, who didn’t identify his or her name, through an encrypted chat late Friday.

“We hacked more than 1,000 sites,” said the hacker. “Now we are structuring all the data, and soon they will be sold. I think something else will publish from the list of hacked government sites.” We asked if the hacker was worried that the files they put up for download would put federal agents and law enforcement at risk. “Probably, yes,” the hacker said.

The hacker claimed to have “over a million data” [sic] on employees across several U.S. federal agencies and public service organizations.

It’s not uncommon for data to be stolen and sold in hacker forums and in marketplaces on the dark web, but the hackers said they would offer the data for free to show that they had something “interesting.”

Unprompted, the hacker sent a link to another FBINAA chapter website they claimed to have hacked. When we opened the page in a Tor browser session, the website had been defaced — prominently displaying a screenshot of the encrypted chat moments earlier.

The hacker — one of more than ten, they said — used public exploits, indicating that many of the websites they hit weren’t up-to-date and had outdated plugins.

In the encrypted chat, the hacker also provided evidence of other breached websites, including a subdomain belonging to manufacturing giant Foxconn. One of the links provided did not need a username or a password but revealed the back-end to a Lotus-based webmail system containing thousands of employee records, including email addresses and phone numbers.

Their end goal: “Experience and money,” the hacker said.

Updated Saturday with a statement from the FBINAA.

New book looks inside Apple’s legal fight with the FBI

More TechCrunch

The Rabbit r1 was the must-have gadget of early 2024, but the blush fell off it pretty quick when the company’s expansive promises failed to materialize. CEO Jesse Lyu admits…

Rabbit’s web-based ‘large action model’ agent arrives on r1 as early as this week

Two of the industry’s most famous sisters, Erin and Sara Foster, sit down alongside business partner Phil Schwarz at TechCrunch Disrupt 2024 to talk about consumer investing, culture curation, and…

Consumer, culture, and creators with Erin and Sara Foster at TechCrunch Disrupt 2024

The “embedded digital access credentials” work over Bluetooth.

Boston Dynamics’ Spot can now autonomously unlock doors

AI memory management startup Letta just emerged from stealth with $10 million in seed led by Felicis and a bunch of big-name angels.

Letta, one of UC Berkeley’s most anticipated AI startups, has just come out of stealth

The White House issued a long-anticipated proposal Monday that would ban Chinese smart cars because internet-connected vehicles pose a national security risk. The proposal, made amid an escalating trade war,…

First TikTok, now smart cars: How Biden’s new proposed ban will affect U.S. automakers

Meta Connect starts Wednesday at 10 a.m. PT and is set to focus on Meta’s XR platforms, the metaverse, and its generative AI platform, Llama.

Meta Connect 2024: How to watch the metaverse and generative AI event

With TechCrunch Disrupt 2024 right around the corner, we’re thrilled to introduce the companies hosting Side Events that will extend the buzz and excitement to the thousands of attendees and…

TechCrunch Disrupt 2024 Side Events schedule: Women in Tech, SignalFire, Llama Lounge, and more to host

Ahead of the launch of Google TV Streamer, the company’s new set-top streaming box, the tech giant is also bringing updates to all Google TV devices. This includes a home…

Google TV receives a major update ahead of the launch of its new streaming box 

Featured Article

Zin Boats’ bigger, faster electric leisure craft is built from the hull up

After taking on water during the pandemic, Zin Boats is back with a bigger, better electric watercraft that it has built from the hull up — again.

Zin Boats’ bigger, faster electric leisure craft is built from the hull up

The countdown to TechCrunch Disrupt 2024 is on, and so are rebooted ticket prices! Save up to $600 on individual ticket types before September 27. Take advantage of these huge…

5 days left to grab rebooted ticket prices for TechCrunch Disrupt 2024

TikTok announced on Monday that its redesigned “Subscription” monetization offering is rolling out to eligible creators in select regions, including Brazil, France, Germany, Spain, the U.K., Indonesia, Italy, Japan, South…

TikTok launches expanded subscriptions feature for creators

Though it briefly worked on a passenger plane, the company decided after raising some money in 2022 that a cargo variant of the Pelican was more practical in the short…

Pyka fields interest from defense as $40M round goes to scaling up its electric autonomous planes

The new fund has already made around 20 investments, and it will operate with a generalist thesis, investing across the whole of Europe.

All Iron Ventures rebrands as Acurio Ventures with a new €150M ‘follow-on’ fund

Cloudflare announced plans on Monday to launch a marketplace in the next year where website owners can sell AI model providers access to scrape their site’s content. The marketplace is…

Cloudflare’s new marketplace will let websites charge AI bots for scraping

Legacy automakers are experiencing a sort of existential crisis as they grapple with whether to stick to plans to go all-electric or hedge with hybrids. This sudden appetite for options…

Thor and Harbinger’s new hybrid RV will let you spend more time at the campsite

For the longest time, RSS readers have followed an “Inbox Zero” design philosophy by showing an unread count against each source. If you have more than a dozen feeds plugged…

The new Reeder app is built for RSS, YouTube, Reddit, Mastodon and more

James McGinniss has been obsessed with decarbonization and the energy grid since he was a high schooler over a decade ago. Now, his startup David Energy has a lofty goal:…

David Energy is going up against Goliath energy incumbents

Data orchestration platform Kestra just raised an $8 million funding round led by Alven, with existing investors Isai and Axeleo participating once again.

Kestra raises another $8M for its open-source orchestration platform

Jump offers full-time contracts to freelancers looking for some stability and the benefits involved with a full-time job.

Jump raises $12M to help freelancers get benefits just like employees

A new Financial Times profile of Masayoshi Son opens with SoftBank’s CEO seeming to hit bottom, staring at his “ugly” face on Zoom and telling himself, “I have done nothing…

SoftBank’s Masayoshi Son has been planning his comeback

Automattic CEO and WordPress co-creator Matt Mullenweg unleashed a scathing attack on a rival firm this week, calling WP Engine a “cancer to WordPress.” Mullenweg criticized the company — which…

Matt Mullenweg calls WP Engine a ‘cancer to WordPress’ and urges community to switch providers

Synex Medical just raised $21.8 million to build a portable MRI capable of testing glucose and other important molecules without the need to extract blood.

Synex founder, once detained at the border with an 80-pound magnet, is building portable MRIs to test glucose

Jony Ive, the legendary designer who left his full-time role at Apple five years ago, is working on a new startup with OpenAI and its CEO Sam Altman. The collaboration…

Yup, Jony Ive is working on an AI device startup with OpenAI

The Pedego’s Cargo e-bike is marketed as a powerful and sporty ride that’s geared towards parents toting kids around town and anyone who needs to schlep heavy gear.  I spent…

Pedego’s Cargo e-bike: Sporty, stylish and powerful for $4,000

The IPO market has not roared back in 2024 as many investors hoped it would — not yet, at least. Elevated interest rates (this week’s 50 bps rate cut notwithstanding)…

Ibotta’s CEO explains why startups shouldn’t try to time the IPO market

We put together a list of some of our favorite under-the-radar features that you might have missed.

A guide to iOS 18’s hidden features and smaller updates

Featured Article

Linus Torvalds explains why aging Linux developers are a good thing

Linux’s luminary linchpin, Linus Torvalds, says that despite longstanding reports of burnout in the open source software development realm, Linux is as strong as ever.

Linus Torvalds explains why aging Linux developers are a good thing

This glossary includes some of the most common terms and expressions we use in our articles, and explanations of how — and why — we use them.

The TechCrunch Cyber Glossary

Featured Article

Some startups are going ‘fair source’ to avoid the pitfalls of open source licensing

The fair source concept is designed to help companies align themselves with the “open” software development sphere, without encroaching into existing licensing landscapes.

Some startups are going ‘fair source’ to avoid the pitfalls of open source licensing

Speaking Saturday at the UN Summit of the Future, Google CEO Sundar Pichai described AI as “the most transformative technology yet” and announced a new fund for AI education and…

Google CEO Sundar Pichai announces $120M fund for global AI education