(New York Times) The F.B.I. has arrested a man in Pennsylvania on suspicion of carrying out the computer hack that stole sensitive information about thousands of F.B.I. employees, according to two people familiar with the matter.
The theft of reams of personal data last month by a criminal hacking group left the nation’s premier law enforcement agency racing to respond as both the investigators and the victims of one of the worst breaches of government data in recent years.
The arrested man is a Canadian citizen and considered to be a primary co-conspirator in carrying out the intrusion, the people said.
Kash Patel, the F.B.I. director, confirmed on Friday that an arrest had been made as part of the bureau’s effort to dismantle the international hacking group. “We will continue to work closely with our partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate,” he said.
Officials did not immediately release the man’s name or the specific charges against him.
The breach was announced by a hacking group that called itself ShinyHunters, saying it had pilfered intimate details about F.B.I. personnel from the agency’s jobs portal. ShinyHunters threatened more consequences — which many officials and cybersecurity experts interpreted as a plan to release the data publicly — if the F.B.I. did not rescind an advisory warning the public of the group’s cyberattacks, but later backed off.
In the wake of the breach, the F.B.I. vowed to pursue the group’s members, who are believed by security researchers to comprise a loose collective of young English-speaking hackers in several countries across the globe. The group has been active for years and been responsible for some of the most serious corporate data breaches in recent years, often extorting victims for millions of dollars in exchange for promises to not publish stolen private material.
The F.B.I. hack scooped up home addresses, Social Security numbers, sensitive job assignments, details about employees’ family members and more, according to a New York Times analysis of some of the records that was shared by the hacking group. In an internal memo to its workforce after the hack was disclosed late last month, the F.B.I. said it was operating under the assumption that all employees had been compromised in the hack.
Brett Leatherman, the assistant director for the F.B.I.’s cyber division, said this week that a review had determined that the hack was “the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform.” That contractor worked for Accenture, Reuters earlier reported.
The bureau has “removed the contractor and taken all necessary steps to both mitigate any further risk and protect our work force,” Mr. Leatherman said, adding that multiple arrests had already been made.
The arrest this week is the latest in a recent string of international law enforcement actions aimed at ShinyHunters. In September, seemingly before the F.B.I. hack, the authorities in the Netherlands arrested a 24-year-old suspected of being affiliated with ShinyHunters, though the group denied knowing him.
ShinyHunters is considered one of the most notorious and capable cybercriminal enterprises in the world. The group is believed to have breached more than 140 organizations and extorted $70 million since last year, Mr. Leatherman said, and has often targeted third-party vendors and cloud-based platforms.