By Stefanie Schappert
For most ransomware and extortion gangs, the end goal has always been pretty simple: money.
Steal enough sensitive data, threaten to leak it, and hope the victim decides paying millions of dollars is better than dealing with the fallout.
But what happens when money is no longer the ransom?
This week, the notorious ShinyHunters hacker group announced it had breached multiple FBI systems, claiming it made off with sensitive data belonging to “almost all” FBI agents, employees, and even job applicants.
The FBI has said it is investigating the alleged breach.
The thing is, in this case, the hackers aren’t asking the FBI for millions of dollars – they’re asking the FBI to take back what the group says are “false allegations” about how they operate.
ShinyHunters gave the FBI seven days to remove or correct statements it made in a May cyber advisory that the group says falsely accused it of exaggerating hacking claims, threatening victims and their families, engaging in swatting, and falsely claiming to possess compromising material.
Seemingly insulted by the suggestion, ShinyHunters also took the time to “unequivocally” declare they are “NOT SEXTORTIONISTS” and “unequivocally” unrelated to the nihilistic hacking collective known as The Com.
The hackers also “unequivocally” (they used the word unequivocally a lot) insist the attack has nothing to do with money.
So why would a cybercriminal group go to such extraordinary lengths to defend its reputation?
Because in the world of cyber extortion, reputation is just another form of currency.
Honor among thieves
Extortion only works if the victim believes the threat.
If hackers threaten to dump sensitive information if a victim refuses to pay, there has to be some reason for that company to believe they will.
If companies begin to suspect a hacker group is bluffing, the threat loses its power, the ransomware gang loses leverage over its victims, and the well runs dry, so to speak.
That’s why an FBI warning suggesting ShinyHunters may exaggerate its claims isn’t simply an insult.
From the hackers’ perspective, it potentially damages the very credibility their business model depends on.
And ShinyHunters isn’t the first cybercrime group I’ve seen fiercely protective of its public image.
Last year, another fine group of extortionists – known as the Qilin gang – contacted my newsroom after taking issue with how I characterized the ransomware group in an article, politely requesting I correct it.
Rather than get on the bad side of one of the most active gangs for nearly two years running, I kindly obliged.
And it appears ShinyHunters has joined the quest, publicly taking issue with how journalists are covering the FBI story, in an obvious attempt to control the narrative.
ShinyHunters also slammed journalists for mishandling the proof samples it so graciously provided, essentially “ruining the experience for everyone.”
Citing the inappropriate sharing of highly sensitive data (yes, the irony is not lost here), the hackers – who clearly have a reputation to uphold – simply decided they would no longer engage with media for this faux pas.
Cash is king – or is it?
For organizations negotiating with these groups, this raises a much bigger question.
As hackers accumulate increasingly sensitive information capable of destroying careers, exposing trade secrets, or putting people’s physical safety at risk, organizations may face demands that have nothing to do with money.
Think of all the highly sensitive data out there potentially at risk.
Medical records, trade secrets, proprietary technology, private communications, customer databases, information about executives – or, in the FBI’s case, home addresses, phone numbers, family information, and other personal details of highly specialized federal agents.
Furthermore, with ransomware attacks, the public may eventually learn that an organization was breached, but rarely sees everything that happens behind the scenes: the negotiations, whether a ransom is paid, or how much.
In the past few years at least, we’ve become accustomed to hackers demanding tens of millions of dollars from their victims in exchange for stolen data.
But stolen information, as we’ve now witnessed, can be leveraged for much more than money, and the more damaging the information, the greater the leverage.
From a simple retraction or public statement to a forced change in corporate behavior – or potentially a demand we haven’t even seen or thought of yet – many cyber insiders believe the stakes are evolving.
The question we must ask isn’t simply how much a victim is willing to pay to protect its data, but what else it would be willing to do to protect it.
ABOUT THE EXPERT
Stefanie Schappert is a Senior Journalist at Cybernews covering cybersecurity, AI, national security, cyber policy, critical infrastructure, data privacy, and the human impact of technology. Based in New York, she is the first American journalist at Cybernews and a broadcast news veteran previously at Fox News, NY1 News, and Verizon FiOS 1. She holds a Master’s degree in Cybersecurity and is ISC2 Certified in Cybersecurity (CC). A guest commentator on TV, radio, and podcasts, including CBS News, iHeartMedia, and KTLA, Schappert explores how technology and cyber risk shape society, from ransomware attacks and hacker groups to emerging technologies and digital policy. She has been published in Fortune and cited by the US Senate, FCC, HHS, Henry Jackson Society, academic institutions, and other leading technology publications.
OpenAI agents went beyond instructions to access U.S. government websites – Sigh….
Posted in Commentary with tags OpenAI on September 28, 2026 by itnerdAccording to a Wall Street Journal report, OpenAI agents tasked with retrieving information from U.S. government websites took actions they were not instructed or authorized to perform. In one case involving the Securities and Exchange Commission, agents retrieved public SEC information and then posted it to an online forum without being asked to do so.
Other agents went beyond normal data collection by using credentials found online to access Census Bureau data, while independent researchers identified an unsuccessful attempt involving a Department of Education website. OpenAI said there is no indication the SEC incident involved access to nonpublic information or changes to SEC systems.
The incidents come amid a much broader investigation into rogue agent behavior. Axios reports that OpenAI, Anthropic and security researchers are investigating tens of thousands of incidents in which frontier models took potentially problematic actions, including bypassing guardrails,
Ryan McCurdy, Field CTO, Liquibase:
“We have enough examples now to stop assuming AI agents will always behave exactly as intended.
“That should change how enterprises build around them. Trying to anticipate every decision an agent might make won’t scale. Putting a human in front of every action won’t either.
“An agent may need permission to access a database, infrastructure, or a deployment system to do its job. Having that permission shouldn’t give it the authority to decide that every action is safe.
“This is where governance needs to sit. Let the agent reason, create, and move quickly. Before its decision becomes a production change, it still has to meet policies and controls that exist outside the agent.
“AI makes decisions based on probabilities. We can’t let those decisions automatically become production actions.
“We need to build the AI SDLC so agents can move quickly but the controls around critical systems remain deterministic.”
John Strand, Owner, Black Hills Information Security:
“I think a lot of people waffle back and forth on this, but I’m just going to say it. It’s time to shut it down. There needs to be a full moratorium, full stop, on advanced frontier AI security research until these companies can demonstrate that they can actually secure the environments where this work is being done.
“And there needs to be accountability. If laws were broken, including the Computer Fraud and Abuse Act, that needs to be investigated and charges should be considered where the evidence supports them. Somebody was responsible for securing these environments, and clearly something failed.
“I’m getting really tired of watching these incidents come out piecemeal, incrementally, frog in a frying pan, again and again. If everything we’ve learned came out at once as a single news story, I think most people would be stunned by it, and there would be immediate calls to get this under control.
“We would not tolerate this from a third-party penetration testing company. We should not have a different standard simply because the companies involved have enormous valuations and tremendous influence. Being a massive, powerful company should not exempt you from the same security, legal, and accountability standards everyone else is expected to follow.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“OpenAI has admitted that its agents took actions they were not instructed or authorized to perform on U.S. government websites. The Wall Street Journal reports that one agent retrieved public Securities and Exchange Commission information and posted it to an online forum. Other agents used credentials found online to access Census Bureau data and attempted to hack a Department of Education website.
“The SEC incident may not, by itself, establish a Computer Fraud and Abuse Act violation because the information was public and OpenAI says there is no indication the agents accessed nonpublic data or changed SEC systems. The other reported conduct demands a criminal investigation. Using credentials found online to access a government system and attempting to compromise another system are the kinds of acts covered by existing computer-crime laws.
“The Axios report that OpenAI, Anthropic and security researchers are investigating tens of thousands of rogue-agent incidents makes the need for enforcement more urgent. This is the same pattern seen in earlier cases involving Anthropic’s Claude, OpenAI’s Hugging Face agent and the UK AI Security Institute’s Mythos 5 testing. Frontier models have repeatedly crossed boundaries, accessed real systems and pursued objectives through unauthorized methods.
“The White House already gave the Justice Department its instruction. Executive Order 14409 directs the attorney general to prioritize enforcement of the Computer Fraud and Abuse Act, 18 U.S.C. § 1030, and other federal criminal laws against people who use artificial intelligence to access or damage computers without authorization. Section 4 specifically names AI agents that unlawfully access data.
“OpenAI has admitted the conduct. The question is whether prosecutors will charge the people who authorized, configured and operated these systems under the law as written. Frontier labs calling for new AI regulation is a deflection from that criminal question. We do not need new laws. We need the Justice Department to enforce the laws already on the books, or admit that those laws are too broad to apply equally. A two-tier policing system where ordinary people are prosecuted for computer crimes while frontier labs escape accountability is unacceptable.”
At this point, it’s safe to say that OpenAI and Sam Altman cannot be trusted. The real question is when real legislation will come down the pipe to restrict OpenAI in ways that make it less dangerous.
Leave a comment »