Fast Track Bootcamps
 Crafted For Career-Ready Skills

CyberWatch Weekly: A Federal Agency Under Extortion, Fake Job Offers, and a $16 Million Breach Bill

A Federal Agency Under Extortion, Fake Job Offers, and a $16 Million Breach Bill

This week’s incidents run from an audacious claim against a federal agency to the final invoice for a breach that happened over a year ago. A cyber extortion group says it holds data on almost every FBI employee and wants a public warning retracted rather than a payment. Agencies across four countries jointly named a North Korean operation that turns hiring processes into malware delivery. And Columbia University agreed to pay $16.1 million for a 2025 intrusion. Here’s a closer look at this week’s top cybersecurity headlines.

ShinyHunters Claims FBI Breach and Demands a Retraction Instead of a Ransom

The cyber extortion group ShinyHunters claimed on Tuesday that it had compromised the FBI and holds sensitive data on almost all FBI agents and job applicants. The group says the affected services include Criminal Justice, HR, Medlink, PEGA, FBIJOBS, and PHIRE, and told The Hacker News the haul runs to around 2TB, describing the Medlink records as containing medical information, prescriptions, diagnoses, and clinic visits. A spokesperson told The Register the group exploited a new Oracle PeopleSoft zero day to gain remote code execution and deface the bureau’s jobs site, which now displays a maintenance notice. No such vulnerability has been documented, though ShinyHunters weaponised a similar PeopleSoft flaw, CVE-2026-35273, in June. The attack was framed as retaliation for a 15 May IC3 public service announcement detailing the group’s methods, and the demand is retraction, not money. The FBI has confirmed only that it is investigating, stating the point of breach remains undetermined.

Experts advise treating the scope claims with care, since the FBI’s own May advisory warned that this group exaggerates access. The broader lesson, as Cato Networks noted, is that the group’s playbook targets identity paths and third party trust relationships rather than the technical perimeter.

Source: The Hacker News, Reuters, 404 Media, FBI IC3

WaterPlum Turns Hiring Into Malware Delivery, Infecting 30,000 Devices

A joint advisory issued on 18 September by agencies in Japan, the United States, Australia, and Germany named the North Korean group WaterPlum, also tracked as Contagious Interview, behind a campaign that compromised at least 30,000 devices across more than 100 countries and took funds or credentials from over 7,000 cryptocurrency wallets between December 2025 and July 2026. At least $10.71 million was transferred to North Korea. The campaign worked because the malware arrives inside an expected file: operators pose as recruiters, often impersonating real AI, crypto, or NFT companies, then ask candidates to run a coding test or fix a video call error. Opening the file installs remote access tools and information stealers that persist long after the interview, harvesting credentials, keystrokes, wallet information, identity documents, and proprietary files. Japan’s NPA and the FBI assess that WaterPlum and some North Korean IT workers both operate under the 313 General Bureau of the Munitions Industry Department.

Experts recommend treating any code received during hiring as untrusted and running it only in an isolated sandbox or virtual machine, never on a device holding personal data or crypto assets. Recruiters should be verified through contact details located independently of the approach itself.

Source: TechSpot, Infosecurity Magazine, CyberScoop

Columbia University Agrees to $16.1 Million Settlement Over 2025 Breach

Columbia University has agreed to pay more than $16.1 million to settle a proposed class action alleging it negligently failed to protect personal information belonging to applicants, students, and employees. The settlement follows a June 2025 cyberattack that exposed the data of nearly 870,000 applicants and University affiliates, and which caused a dayslong IT outage across university systems. A motion for preliminary settlement approval was filed on 18 September in the US District Court for the Southern District of New York. Under the proposed terms, class members are eligible for up to $8,500 in reimbursement for out of pocket costs, or an alternative cash payment of around $100. The figure puts a number on something higher education has been circling for two years, as universities hold dense records on populations far exceeding their current student bodies, including every applicant never admitted.

Experts note that settlement exposure scales with retained records, not active users, making retention policy a direct financial control. Organisations should audit what applicant and former affiliate data they still hold, and whether any business case justifies keeping it.

Source: Bloomberg Law, Columbia Daily Spectator

Conclusion

The week’s thread is what attackers want and what defenders owe. ShinyHunters asked for a retraction rather than a payment, WaterPlum wanted the trust a job candidate extends to a recruiter, and Columbia’s bill arrived fifteen months after the intrusion that caused it. The value being extracted is rarely just the data, and the cost is rarely settled when the incident closes.

Stay vigilant and informed, tune in next week for more updates in InfosecTrain’s CyberWatch Weekly!

TOP