The recent hack of the F.B.I. was staggering. It potentially exposed information about tens of thousands of former and current employees, including home addresses, Social Security numbers, clandestine job assignments, family details and much more.
How did it happen? What were the ramifications? Were the hackers’ claims legitimate?
Dustin Volz, a New York Times reporter who covers the work of hackers and spies, set about finding answers. One idea: Email the group that had claimed responsibility. It worked.
Volz took some time from covering this ongoing story to discuss his email exchange and other elements of reporting on the breach. These are edited excerpts from our conversation.
Dustin, your job seems cool, maybe even a little dangerous. You report on how hackers and spies work to achieve geopolitical advantage. What does that involve?
I don’t view my job as really any different from what most of my colleagues do: I primarily spend my days talking to sources trying to learn something interesting. For me, that means people in and around spy agencies, cybersecurity researchers and, occasionally, nation-state or criminal hackers.
Walk us through this case briefly.
The hack was the handiwork of ShinyHunters, a notorious cybercriminal group that has extorted major companies for years. It was surprising they would target the F.B.I., which seemed to deviate from their normal business model. Once I saw them claim the hack, I began asking sources if this looked real and, if so, how bad it looked. The answer was universal: very bad.
As you shared with listeners of “The Daily,” you emailed the hackers directly. How did you find an email address for them? What did you expect to come of it?
The hackers included the email address in a statement announcing the F.B.I. hack to the world that they posted on their dark web page. Because the site was a place they have historically used to tout their latest scores, I knew whoever posted was almost certainly affiliated with the group. I reached out and was unsure if they would respond. But within 10 minutes they sent details about the hack and what they said was a sample of the stolen material.
Why would they do that? And what did you do next? What’s your goal once you have this supposed evidence?
These guys like publicity, as it can create more pressure on victims — which makes covering them harder, as I don’t want to amplify their actions unless they are of clear public interest.
Can you talk about our approach to the information we were sent?
Before reviewing the sample, I told my editor, who consulted our legal and standards teams. I didn’t know how or whether we wanted to touch this kind of stolen private information, though it seemed important for the public to know if what the hackers were claiming was true. We knew if we did review it we wanted to strictly limit access internally and use it to inform our understanding of the hack and verify the claims being made by ShinyHunters.
We were able to organize the data and assess it using information already online and quickly realized the whole thing looked pretty authentic. Confirming that led us to realize how significant the breach was and in turn to decide that we had to cover it.
Many of us have been notified of hacks in our own personal lives, whether a credit card account or medical information. It’s a part of modern life. But the stakes here are different. How does this breach put F.B.I. employees at risk?
Because of the granularity of data — home addresses; phone, Social Security and government ID numbers; family details; secretive job assignments; even private medical data — the full data set poses a multitude of risks. Many F.B.I. agents zealously guard their privacy, especially those working in areas like counterintelligence, cybercrime, counternarcotics and national security. Depending on who had access to it, the full data could be useful for foreign espionage or targeted harassment. Former officials told me they were especially worried about violent criminals seeking retribution against F.B.I. agents who put them or their associates in prison.
As someone who tries to shine a light on a murky world, you must have learned a thing or two about keeping your own information safe. Are you nervous about being hacked? What’s your advice for readers?
I’m always pretty nervous! I do what I can to protect myself and my sources, like using encrypted messaging tools, but some of the most basic things remain the most essential. Unique long passwords, multifactor authentication and device-based identity verification still goes a long way.
I also strive to keep truly sensitive things strictly offline, as that remains the best way to avoid having it compromised. A physical notebook and an in-person conversation goes a long way.
The post Our Reporter Emailed the F.B.I. Hackers. They Wrote Back. appeared first on New York Times.




