Guest Post: Why are the FBI hackers so obsessed with their reputation? 

By Stefanie Schappert

For most ransomware and extortion gangs, the end goal has always been pretty simple: money.

Steal enough sensitive data, threaten to leak it, and hope the victim decides paying millions of dollars is better than dealing with the fallout.

But what happens when money is no longer the ransom?

This week, the notorious ShinyHunters hacker group announced it had breached multiple FBI systems, claiming it made off with sensitive data belonging to “almost all” FBI agents, employees, and even job applicants.

The FBI has said it is investigating the alleged breach.

The thing is, in this case, the hackers aren’t asking the FBI for millions of dollars – they’re asking the FBI to take back what the group says are “false allegations” about how they operate. 

ShinyHunters gave the FBI seven days to remove or correct statements it made in a May cyber advisory that the group says falsely accused it of exaggerating hacking claims, threatening victims and their families, engaging in swatting, and falsely claiming to possess compromising material. 

Seemingly insulted by the suggestion, ShinyHunters also took the time to “unequivocally” declare they are “NOT SEXTORTIONISTS” and “unequivocally” unrelated to the nihilistic hacking collective known as The Com.

The hackers also “unequivocally” (they used the word unequivocally a lot) insist the attack has nothing to do with money.

So why would a cybercriminal group go to such extraordinary lengths to defend its reputation?

Because in the world of cyber extortion, reputation is just another form of currency.

Honor among thieves

Extortion only works if the victim believes the threat.

If hackers threaten to dump sensitive information if a victim refuses to pay, there has to be some reason for that company to believe they will. 


If companies begin to suspect a hacker group is bluffing, the threat loses its power, the ransomware gang loses leverage over its victims, and the well runs dry, so to speak.

That’s why an FBI warning suggesting ShinyHunters may exaggerate its claims isn’t simply an insult. 

From the hackers’ perspective, it potentially damages the very credibility their business model depends on.

And ShinyHunters isn’t the first cybercrime group I’ve seen fiercely protective of its public image.

Last year, another fine group of extortionists – known as the Qilin gang – contacted my newsroom after taking issue with how I characterized the ransomware group in an article, politely requesting I correct it. 

Rather than get on the bad side of one of the most active gangs for nearly two years running, I kindly obliged. 

And it appears ShinyHunters has joined the quest, publicly taking issue with how journalists are covering the FBI story, in an obvious attempt to control the narrative.  

ShinyHunters also slammed journalists for mishandling the proof samples it so graciously provided, essentially “ruining the experience for everyone.” 

Citing the inappropriate sharing of highly sensitive data (yes, the irony is not lost here), the hackers – who clearly have a reputation to uphold – simply decided they would no longer engage with media for this faux pas. 

Cash is king – or is it?

For organizations negotiating with these groups, this raises a much bigger question.

As hackers accumulate increasingly sensitive information capable of destroying careers, exposing trade secrets, or putting people’s physical safety at risk, organizations may face demands that have nothing to do with money.

Think of all the highly sensitive data out there potentially at risk.  

Medical records, trade secrets, proprietary technology, private communications, customer databases, information about executives – or, in the FBI’s case, home addresses, phone numbers, family information, and other personal details of highly specialized federal agents.

Furthermore, with ransomware attacks, the public may eventually learn that an organization was breached, but rarely sees everything that happens behind the scenes: the negotiations, whether a ransom is paid, or how much.

In the past few years at least, we’ve become accustomed to hackers demanding tens of millions of dollars from their victims in exchange for stolen data.

But stolen information, as we’ve now witnessed, can be leveraged for much more than money, and the more damaging the information, the greater the leverage. 

From a simple retraction or public statement to a forced change in corporate behavior – or potentially a demand we haven’t even seen or thought of yet – many cyber insiders believe the stakes are evolving. 

The question we must ask isn’t simply how much a victim is willing to pay to protect its data, but what else it would be willing to do to protect it.

ABOUT THE EXPERT

Stefanie Schappert is a Senior Journalist at Cybernews covering cybersecurity, AI, national security, cyber policy, critical infrastructure, data privacy, and the human impact of technology. Based in New York, she is the first American journalist at Cybernews and a broadcast news veteran previously at Fox News, NY1 News, and Verizon FiOS 1. She holds a Master’s degree in Cybersecurity and is ISC2 Certified in Cybersecurity (CC). A guest commentator on TV, radio, and podcasts, including CBS News, iHeartMedia, and KTLA, Schappert explores how technology and cyber risk shape society, from ransomware attacks and hacker groups to emerging technologies and digital policy. She has been published in Fortune and cited by the US Senate, FCC, HHS, Henry Jackson Society, academic institutions, and other leading technology publications.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading