Hackers are selling a database of the FBI's threat information sharing program InfraGard, containing its 80K+ members' contact details, posted on December 10
Brian Krebs / Krebs on Security :
Context & Ripple Effects
The sale fits a decade-long pattern of law-enforcement partner networks leaking their own rosters: hackers dumped names and contact details for over 9K DHS staff back in 2016 (claimed DOJ would be next), and in 2019 made off with roughly 4K personnel records from sites tied to the FBI National Academy Association (while claiming data from 1K+ more hacked sites). InfraGard is the same kind of asset — a trusted membership list — but bigger and more valuable, since its 80K+ members are the private-sector operators the FBI relies on for threat information sharing.
That value is exactly what makes the leak consequential: a verified directory of who talks to the FBI about threats is a targeting map for anyone who wants to intercept, impersonate, or compromise that channel.
First-order effects
- More than 80,000 InfraGard members — largely critical-infrastructure and security professionals — now have their contact details circulating for sale, exposing them to targeted phishing and impersonation attempts that exploit their FBI affiliation.
- The FBI's threat-sharing program itself is compromised as a trusted channel: recipients of InfraGard alerts can no longer assume outreach referencing the program is legitimate.
Second-order effects
- Member organizations must re-examine how their staff are enrolled and listed in InfraGard, shifting scrutiny onto the program's vetting and data-handling practices rather than just the breach itself.
- The sale venue matters as much as the data: marketplaces like BreachForums have been the default outlet for this trade, which is why the FBI's later seizure of BreachForums and its Telegram channel reads as a direct strike at the distribution layer for leaks like this one.
Third-order effects
- If the pattern holds — DHS in 2016, FBI-affiliated academies in 2019, InfraGard now — government-convened trust networks will be treated by attackers as first-class reconnaissance targets, forcing agencies to treat membership directories as sensitive infrastructure rather than administrative records.
- Each high-profile leak raises the cost of the information-sharing model itself: private-sector participants weigh the targeting risk of enrollment against the intelligence benefit, which could thin participation in exactly the programs meant to harden critical infrastructure.
The trend: Law-enforcement information-sharing programs keep leaking their own membership rolls, turning trusted-partner networks into a recurring attack surface and pushing the FBI toward seizing the forums where that data is sold.