Group that hacked CIA director's email allegedly breach law enforcement portal containing arrest records and other sensitive data
CIA Email Hackers Return With Major Law Enforcement Breach — This time the group, which goes by the name Crackas With Attitude, says it gained access …
Context & Ripple Effects
Crackas With Attitude's run began as an embarrassment for individual officials: the group took over John Brennan's AOL account, then moved on to Director of National Intelligence James Clapper's personal phone, Internet, and email. What changes here is the target class — instead of a cabinet secretary's personal inbox, the group claims access to a law enforcement portal holding arrest records, which means bulk data on people who were never the intended audience of any one account.
The claim lands between two bookends in this coverage arc: the group's alleged ringleader was later identified and arrested by UK police, and years later other crews kept mining the same soft targets, including the ~4K personnel records taken from sites tied to the FBI National Academy Association.
First-order effects
- Arrest records and other sensitive portal data are now allegedly exposed, putting law enforcement subjects and the officers who generated those records at risk of identification and harassment.
- Crackas With Attitude escalates from compromising named officials' personal accounts to claiming access inside an institutional system, raising the stakes from embarrassment to operational exposure for the portal's operator.
Second-order effects
- Agencies running similar external-facing portals — association sites, vendor logins, record-sharing gateways — face immediate pressure to audit credentials and access controls, since the later FBI National Academy Association breach shows these periphery systems stayed attractive targets long after this incident.
- Personal accounts of senior intelligence and law enforcement figures get treated as perimeter assets rather than private property, forcing security reviews around how officials' home email, phones, and ISP accounts authenticate to anything work-related.
Third-order effects
- If the pattern holds through to crews like the [[a:891457|Scattered LAPSUS$ Hunters posting alleged names and addresses of hundreds of DHS, ICE, FBI, and DOJ officials on Telegram]], doxxing of US security personnel shifts from one-off stunts to a persistent, low-skill threat that no clearance process addresses.
- The structural lesson across this decade of incidents is that government data security extends well past classified networks: arrest records and personnel rosters held in ordinary web portals become the cheapest route to harming both institutions and individuals, likely pushing agencies to consolidate or harden every externally accessible datastore.
The trend: A decade-long arc runs from teenage hackers pranking intelligence chiefs' personal accounts to routine mass doxxing of US law enforcement and intelligence personnel, with unclassified portals and personal identities as the recurring weak point.