What Should the U.S. Government Do in Response to the FBI Hack?
Photo: Beata Zawrzel/NurPhoto via Getty Images
Last week, the job application website of the Federal Bureau of Investigation (FBI) was hacked, with sensitive data of at least 5,000 FBI agents exfiltrated by a cybercriminal group known as the ShinyHunters. Although the actors claim they will not publish this data, there is a strong expectation that they have made copies of the dataset and will sell them on the dark web for subsequent exploitation by other malicious actors.
The incident has already been labeled a counterintelligence disaster. Beyond causing significant reputational damage to the FBI, the incident poses a longer-term national security threat to the United States. But it also offers a clear-cut case for an urgent, targeted, and proportionate use of offensive cyber capabilities, and for sending a clear message about what is off-limits for cybercriminals.
Shifting from Cybercrime to a National Security Threat
Cybercriminals are traditionally financially motivated, but, in this case, the ShinyHunters hacked the FBI in retaliation for an advisory the agency published in May, which they considered defamatory to their criminal business operations. The ramifications are disproportionate: Estimates suggest the incident may have exposed the personally identifiable information of tens of thousands of former and current employees, including Social Security numbers and family details and employees’ intelligence assignments and medical records. This stems in part from the nature of the underlying software vulnerability that led to the hack, supposedly enabling the breach of multiple FBI systems, including its jobs portal, its system for background checks, medical records, and investigations information. It is unclear how long this vulnerability was in place and whether it has been remediated, leaving open the possibility that the exploit itself may prove even more valuable to U.S. adversaries and criminals than the FBI dataset alone.
The severity of the incident ultimately stems from two factors: how the data can be exploited by others and the cumulative advantage it provides over time. In the short term, the incident poses a serious personnel security threat, as other cybercriminals could exploit the stolen data to conduct credit card or identity fraud using federal employees’ details. However, the more time passes, the more the threat becomes acute: Should the ShinyHunters sell the data—whether to other cybercriminal groups, states, or, worse, data brokers or resellers—the risk arises of the data being available ad infinitum. This raises serious risks of retaliation against FBI personnel—and potentially their relatives, and even informants—from serious and organized crime groups or cartels. In the longer term, the counterintelligence risks grow significantly. The U.S. track record of data breaches against federal employee data paints an ugly picture. Some state adversaries—particularly China—are already thought to have stolen or acquired data on millions of U.S. federal employees through historical incidents, including the Office of Personnel Management hack in 2015. Layering the stolen FBI data on top of existing intelligence repositories would go some way to enriching adversaries’ visibility of U.S. agents and operatives, aggregating multiple stolen datasets to build detailed profiles of individual personnel.
What Should the U.S. Government’s Response Look Like?
Below are four suggested options for the U.S. government to respond to the breach.
- Do nothing. This would comprise a reactive effort, essentially providing protective security advice and services to FBI personnel, basic online data protection monitoring services, and other welfare support to affected employees. This approach would offer minimal deterrent or signaling value to the actors in question and do little other than to bandage over a long-term vulnerability for the United States. It is unlikely to sit well domestically, with members of the House Intelligence Committee having already requested a formal briefing from the FBI on the hack.
- Mount a traditional law enforcement–led response. As the next tier of response, U.S. law enforcement could investigate and seek to prosecute the ShinyHunters—building upon Dutch law enforcement’s quick arrest of one ShinyHunters member—as well as other actors responsible for the breach and distribution of FBI data. This has successful precedents, with U.S. interagency operations between law enforcement and intelligence partners having resulted in the arrests and prosecutions of high-profile cybercriminals such as LockBit’s Dmitry Yuryevich Khoroshev, REvil’s Yaroslav Vasinskyi, and Oleksii Oleksiyovych Lytvynenko, who was recently convicted of an elaborate ransomware operation that extorted victims for over $150 million. However, these operations are painstaking, resource-intensive, and slow, weakening any potential signaling value that might come from a fast U.S. government response.
- Mount a multi-agency offensive cyber operation to retrieve the stolen data and any copies. An offensive cyber operation offers an urgent, targeted, and proportionate response to an urgent problem. The U.S. government should mount an offensive cyber operation led by U.S. Cyber Command to steal back the data from the ShinyHunters group and to disrupt its infrastructure. Such an operation could be tightly scoped; limited to locating, authenticating, and exfiltrating the dataset and destroying any copies found; and exiting without leaving traces on the criminal groups’ systems. Messaging from senior FBI officials suggests that law enforcement knows the location of the perpetrators. Aided by forensic evidence from a seized laptop belonging to one of the perpetrators, the United States may therefore be able to locate the data before it is sold to other adversaries or distributed further.
Pursuing this via Cyber Command would not be the usual route: A cybercriminal incident usually merits a law enforcement–led operation by the FBI. However, given the speed of response required, U.S. Cyber Command should take the lead, along with the FBI and other relevant partners, similar to the takedown of the REvil ransomware group in 2021. This would enable the execution of an offensive cyber operation at speed, given the greater latitude that Cyber Command has to move through overseas-based infrastructure. It would also enable a law enforcement operation to take place in parallel, and for notifications to be issued to any potential future victims identified from digital forensics efforts. Although Cyber Command’s threshold for offensive cyber operations usually involves nation-state actors, in this case, the clear threat posed to U.S. equities offers a national security justification. - Mount an aggressive campaign against the group, its infrastructure, and the wider ecosystem. On the furthest end of the spectrum, the U.S. government could undertake disruption operations to dismantle the infrastructure, finances, and leadership of ShinyHunters, and to degrade the broader cybercrime ecosystem in which it operates. Maintaining an aggressive tempo of offensive cyber operations, it could disrupt and dismantle the ShinyHunters’ infrastructure and defame the group in underground criminal fora, noting how much the cybercriminal ecosystem trades on reputation and bravado. This would bring the added benefit of preventing other actors (including states) from hacking the ShinyHunters themselves to steal the stolen FBI data.
Why stop there? A maximum response could also look beyond the ShinyHunters—to known affiliates, enablers, or service providers, selectively disrupting their operations, or even unmasking individual actors. It could also exploit rivalries and tensions between different groups; for example, the ShinyHunters recently hacked Cl0p, a prolific ransomware group, and also showed signs of internal divisions over its brand. Accompanying this range of activity with messaging in cybercriminal fora—that the United States knows ShinyHunters’ identities, whereabouts, and operations—may help to deter less sophisticated or determined cybercriminals. And to maintain a steady operational tempo and enhanced posture, the administration could bring in private sector companies under a recent presidential memorandum authorizing a program to enable private sector offensive cyber operations against cybercrime, as a useful test case.
That said, it is just as important that any maximum response is followed by a reversion to norms where the United States can leverage its broader tools of cyber statecraft. This might include measures such as sanctioning the perpetrators and any identified affiliates to deny them the gains of their attacks, longer-term diplomatic efforts on international norms against data theft, continued technical intelligence gathering, and effects operations to shape the broader cybercriminal ecosystem.
What Would an Offensive Cyber Operation Achieve?
This incident offers a prime target for demonstrating U.S. offensive cyber capabilities. In the immediate term, an offensive cyber operation by the U.S. government could go some way to mitigating a significant national security risk. In addition to the seized devices that Dutch law enforcement already have in their possession, an offensive cyber operation could provide a wealth of intelligence on the ShinyHunters, their affiliates, enablers—both actors and services—and even future targets they may have been planning to attack.
But timing is key: If it acts quickly, the U.S. government might be able to retrieve the dataset and identified copies. If the data is already gone—i.e., sold to other actors—the operation shifts to becoming about shaping cybercriminal behavior over the longer term. Over the last few years, organizations that were once considered off-limits, such as hospitals, schools, and airports, are now routinely targeted by cybercrime. It is therefore vital that the U.S. government impose real costs on the actors responsible for this incident to prevent this from becoming a new norm or an acceptable target for cybercriminals.
Key Constraints to a U.S. Response
Two key hurdles stand between the U.S. government and retrieving the stolen data. The first is speed: The United States would need to have a strong enough intelligence picture or forensics clues to be able to locate the data, as well as technical capabilities that it could quickly tailor and deploy for the intended operational outcome. The second is whether the perpetrators made copies of the dataset. Whether sold to other actors, disseminated to the media, or stolen—or even altered or manipulated—by state actors, each copy undermines the U.S. government’s ability to contain the damage incurred, causing any response to descend into a whack-a-mole operation.
Additionally, any offensive cyber operation to retrieve the data would also need rapid coordination and deconfliction, both with domestic partners, to avoid colliding with existing intelligence or law enforcement operations by other U.S. agencies, and with international partners, particularly where the criminal infrastructure sits in an overseas jurisdiction. And any law enforcement investigation would also be reliant on partner nations’ capabilities to bring the cybercriminals to justice and extradite them into U.S. jurisdiction, which risks running into obstacles including lack of capacity, limited resources, legal barriers, or even permissive jurisdictions that keep cybercriminals out of the reach of U.S. law enforcement.
Conclusion
This incident goes beyond the bounds of traditional cybercrime and poses a clear and enduring threat to U.S. national security. Therefore, a robust response by the U.S. government is vital and should deploy U.S. offensive cyber capabilities appropriately: not to up the stakes with cybercriminals or to ignite “hack back” wars, but rather to mitigate a genuine and urgent national security threat to the United States. The key rests on executing a response with speed and precision that is tied to a longer-term campaign to degrade these actors and the wider cybercriminal ecosystem.
If done correctly, a U.S. government response could demonstrate how offensive cyber capabilities can be an effective and credible lever of statecraft when pointed at the right type of issue or problem set. Moreover, it could also show how offensive cyber operations do not preclude, but rather help to set the conditions for, a longer-term, sustained response against adversaries in cyberspace. Although the ShinyHunters incident offers a clear-cut use case, it also leaves open a longer-term discussion about norms in cyberspace: At what point is it right to go after stolen datasets when states steal them? This incident raises longer-term ramifications for intelligence gathering and disruption in cyberspace that the cyber policy community must address if the United States is to maintain strategic advantage relative to its adversaries.
Nikita Shah is senior fellow in the Intelligence, National Security, and Technology Program at the Center for Strategic and International Studies in Washington, D.C.