메뉴
BL
404 Media • 2일 전

FBI 해킹 사건, FBI 자체 해킹 부대원 신원까지 노출

IMP
8/10
핵심 요약

수천 명의 FBI 직원 개인정보(주소, 전화번호, 배우자 정보 포함)를 유출한 해킹 사건에서 FBI의 비밀 해킹 부대인 '원격 작전 부대(ROU)' 소속 요원들의 신원도 포함된 것으로 확인됐습니다. ShinyHunters가 유출한 5,000명 명단에는 직급·소속 팀 정보가 담려 있어 범죄자나 외국 정보기관에 극도로 유용한 정보가 될 수 있습니다.

번역된 본문

최소 수천 명의 FBI 직원에 대한 재앙적 해킹 사건에서 유출된 개인정보(주소, 전화번호, 심지어 배우자 정보 포함)에 FBI의 비밀 해킹 팀 소속 요원들이 포함되어 있어, 해당 부대에 정확히 누가 속해 있는지 드러날 가능성이 있다고 404 Media가 확인했습니다. 이번 발견은 유출된 데이터가 얼마나 민감한지, 그리고 범죄자나 외국 정보기관에게 얼마나 가치 있을 수 있는지를 다시 한번 부각시킵니다. FBI 해킹 부대가 수행하는 작전, 사용하는 도구, 소속 요원이 누구인지에 대한 공개 정보는 거의 없습니다.

💡 FBI에 근무하시나요? 이 해킹에 대해 알고 계신 것이 있나요? 제보를 환영합니다. 업무용 기기가 아닌 개인 기기에서 Signal(joseph.404)로 안전하게 메시지를 보내거나 joseph@404media.co로 이메일을 보내주세요.

FBI는 성명에서 "FBIJobs.gov 포털 침해 및 FBI 직원 개인식별정보(PII) 유출 주장을 하는 사이버 범죄 조직을 인지하고 있다. 침해 지점이 제3자인지 FBI 시스템인지는 아직 확인되지 않았으나, 적극적으로 조사를 진행 중이며 FBIJobs.gov를 지원하는 제3자 제공업체와 긴밀히 협력하여 모든 위험을 최소화하고 있다"고 밝혔습니다.

404 Media는 화요일에 이 침해 사건을 처음 보도했습니다. 이 사건의 배후인 ShinyHunters는 5,000명의 FBI 직원으로 추정되는 명단을 404 Media에 공유했습니다. 404 Media는 OSINT Industries라는 조사 도구의 공개 자료 및 사이버보안 회사 District 4가 만든 도구 Darkside의 과거 유출 데이터와 교차 검증하여 데이터의 일부를 확인했습니다.

직원들의 개인정보 외에도 5,000명 명단에는 각자의 직급이나 소속 팀이 포함되어 있습니다. 여기에는 특별요원(Special Agent), 위협 접수 심사관(Threat Intake Examiner), 주요 사이버범죄 부대(Major Cyber Crimes Unit) 같은 직급이 포함됩니다. 로이터는 수요일에 일부 직급에 중국이나 러시아 관련 수사 업무가 포함되어 있다고 보도했습니다.

404 Media는 데이터에서 '원격 작전 부대(remote operations unit)'를 명시적으로 언급하는 항목 3건을 발견했습니다. 원격 작전 부대(ROU)는 FBI의 해킹 부대입니다. 감찰관실(OIG)의 2020년 보고서에 따르면 지난 10년 대부분 동안 ROU는 다크웹을 수사하는 도구를 개발·배치하는 데 집중했습니다. ROU는 네트워크 수사 기법(network investigative technique, NIT) — FBI식 표현으로 해킹 도구 — 을 개발하는 데 '결정적인 역할'을 했으며, 이 도구는 사이트 방문자를 식별하기 위해 FBI가 2주간 운영했던 다크웹 아동학대 사이트에 배치되었습니다. 예산 삭감 이후 그 초점은 국가안보 수사용 도구로 옮겨갔다고 보고서는 전합니다. 해당 보고서에서 ROU를 다루는 나머지 대부분의 내용은 편집(비공개 처리)되어 있습니다.

ROU와 관련된 유출 데이터에는 각 인물의 주소, 전화번호 목록, 경우에 따라 배우자의 이름과 전화번호까지 포함되어 있습니다. 404 Media는 ROU 요원 중 한 명의 전화번호를 Darkside에서 검색한 결과, 과거 비밀경호국(Secret Service)에서 근무했음을 나타내는 기존 유출 데이터를 발견했습니다. 데이터에는 '학생 워크포스 트레이니(student workforce trainee)'로 묘사된, 학생으로 보이는 인물도 포함되어 있습니다.

ROU는 과거 일반 형사 수사에서도 기밀 해킹 도구를 사용한 바 있어, 피고인들이 자신에 대한 증거가 어떻게 수집되었는지 검증할 수 있었는지에 대한 의문이 제기된 바 있습니다.

저자 소개: Joseph는 영향력 있는 보도에 집중하는 수상 경력의 조사 저널리스트입니다. 그의 보도는 수억 달러의 벌금을 이끌어냈고 기술 기업을 폐업시키는 등의 성과를 낳았습니다.

원문 보기
원문 보기 (영어)
The catastrophic hack of at least thousands of FBI officials’ personal data, including their addresses, phone numbers, and even their spouses, includes members of the FBI’s secretive hacking team, potentially revealing who exactly is in that unit, 404 Media has found. The findings further highlight how sensitive the stolen data is, and how valuable it may be to criminals or to foreign intelligence agencies. There is very little public information about the FBI’s hacking unit, including the operations it conducts, the tools it uses, or which agents are part of it. 💡 Do you work at the FBI? Do you know anything else about this hack? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co. The FBI said in a statement it “is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII). While the point of breach is still undetermined — whether a third-party or the FBI’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.” 404 Media first broke news of the breach on Tuesday. The group responsible, ShinyHunters, shared a list of 5,000 alleged FBI officials with 404 Media. 404 Media verified parts of the data by cross-referencing it with open source records available in the research tool OSINT Industries, and previously compromised data in Darkside, a tool made by cybersecurity company District 4. As well as the officials’ personal information, the list of 5,000 officials includes each person’s job title or team. Those include titles such as Special Agent, Threat Intake Examiner, and Major Cyber Crimes Unit. Reuters reported on Wednesday some of the job titles include those related to investigating China or Russia. 404 Media found three of the entries in the data specifically mention “remote operations units.” The Remote Operations Unit, or ROU, is the FBI’s hacking unit. For much of the previous decade, the ROU was focused on making and deploying tools to investigate the dark web, according to a 2020 report from the Office of the Inspector General. The ROU was “instrumental” in developing the network investigative technique (NIT) — the FBI’s parlance for a hacking tool — the agency deployed on a dark web child abuse site the FBI ran for two weeks in order to identify site visitors. After budget decreases, its focus has shifted to tools for national security investigations, the report says. Much of the rest of that report discussing the ROU is redacted. The parts of the hacked data related to the ROU expose each person’s address, a list of phone numbers for them, and in some cases the name of their spouses and their phone numbers. 404 Media searched one of the ROU official’s phone numbers in Darkside, and found previously breached data indicating they used to work for the Secret Service. One person in the data also appears to be a student, with the data describing them as a “student workforce trainee.” The ROU has previously used classified hacking tools in ordinary criminal investigations, raising questions over whether defendants were able to scrutinize how evidence against them was collected. About the author Joseph is an award-winning investigative journalist focused on generating impact. His work has triggered hundreds of millions of dollars worth of fines, shut down tech companies, and much more. More from Joseph Cox