/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hackers are selling a database of the FBI's threat information sharing program InfraGard, containing its 80K+ members' contact details, posted on December 10

Brian Krebs / Krebs on Security :

Krebs on Security Brian Krebs

Context & Ripple Effects

The sale fits a decade-long pattern of law-enforcement partner networks leaking their own rosters: hackers dumped names and contact details for over 9K DHS staff back in 2016 (claimed DOJ would be next), and in 2019 made off with roughly 4K personnel records from sites tied to the FBI National Academy Association (while claiming data from 1K+ more hacked sites). InfraGard is the same kind of asset — a trusted membership list — but bigger and more valuable, since its 80K+ members are the private-sector operators the FBI relies on for threat information sharing.

That value is exactly what makes the leak consequential: a verified directory of who talks to the FBI about threats is a targeting map for anyone who wants to intercept, impersonate, or compromise that channel.

First-order effects

  • More than 80,000 InfraGard members — largely critical-infrastructure and security professionals — now have their contact details circulating for sale, exposing them to targeted phishing and impersonation attempts that exploit their FBI affiliation.
  • The FBI's threat-sharing program itself is compromised as a trusted channel: recipients of InfraGard alerts can no longer assume outreach referencing the program is legitimate.

Second-order effects

  • Member organizations must re-examine how their staff are enrolled and listed in InfraGard, shifting scrutiny onto the program's vetting and data-handling practices rather than just the breach itself.
  • The sale venue matters as much as the data: marketplaces like BreachForums have been the default outlet for this trade, which is why the FBI's later seizure of BreachForums and its Telegram channel reads as a direct strike at the distribution layer for leaks like this one.

Third-order effects

  • If the pattern holds — DHS in 2016, FBI-affiliated academies in 2019, InfraGard now — government-convened trust networks will be treated by attackers as first-class reconnaissance targets, forcing agencies to treat membership directories as sensitive infrastructure rather than administrative records.
  • Each high-profile leak raises the cost of the information-sharing model itself: private-sector participants weigh the targeting risk of enrollment against the intelligence benefit, which could thin participation in exactly the programs meant to harden critical infrastructure.

The trend: Law-enforcement information-sharing programs keep leaking their own membership rolls, turning trusted-partner networks into a recurring attack surface and pushing the FBI toward seizing the forums where that data is sold.

Discussion

  • @arekfurt @arekfurt on x
    This seems to be a less significant event than some people are interpreting it as. The vetting process described here could perhaps use some refinement and improvement, depending on how it is determined the impostor got in. But the scraped database seems of little value. https://…
  • @tom_winter Tom Winter on x
    A potentially significant story in the CISO - law enforcement world: https://twitter.com/...
  • @briankrebs @briankrebs on x
    Also, heard from the financial corporation CEO whose identity was used to secure an imposter account at InfraGard. The CEO said they were never contacted by the FBI. That's even though the hackers gave the FBI the CEO's real mobile number as part of the vetting.
  • @briankrebs @briankrebs on x
    A few updates: The FBI confirms my reporting, says it's aware of a potential false account associated with the InfraGard Portal, that it is actively looking into the matter. “This is an ongoing situation, and we are not able to provide any additional information at this time.”