[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f13o74l1pyg5cg":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":20,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":30,"seoTitle":31,"seoTitleEn":8,"seoDescription":31,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":4,"isSpamList":34,"isMalware":34,"company":35},"6a7214adb1bf683704200859","InfraGard2022","InfraGard 2022 Data Breach","infragard-2022","infragard.fbi.gov","2022-12-01T00:00:00.000Z","2026-08-04T16:34:53.311Z","KrebsOnSecurity investigation and Associated Press reporting","https:\u002F\u002Fkrebsonsecurity.com\u002F2022\u002F12\u002Ffbis-vetted-info-sharing-network-infragard-hacked\u002F",[14,16,17,18,19],"https:\u002F\u002Fapnews.com\u002Farticle\u002Ftechnology-business-hacking-government-and-politics-4f2eeabfd6f3a998a374c1bca5c1fbc6","https:\u002F\u002Fwww.pcmag.com\u002Fnews\u002Ffbis-infragard-us-critical-infrastructure-intelligence-portal-hacked","https:\u002F\u002Fkrebsonsecurity.com\u002F2024\u002F10\u002Fbrazil-arrests-usdod-hacker-in-fbi-infragard-breach\u002F","https:\u002F\u002Finfragard.fbi.gov\u002F",null,"unknown","people","Unknown",[25,26,27,28,29],"Email addresses","Names","Organizational affiliations","Contact information","Professional information","\u003Cp>\u003Cstrong>The 2022 InfraGard data breach\u003C\u002Fstrong> occurred after an attacker used a corporate executive's identity to apply for access to the FBI-run InfraGard portal and then accessed its member directory through the approved account. The unauthorized account became active in early December 2022, and the database was offered for sale on a cybercrime forum on December 10.\u003C\u002Fp>\u003Cp>InfraGard shares security information with public- and private-sector professionals working across US critical-infrastructure industries. The professional affiliations and contact information involved in the incident therefore create a meaningful targeted-social-engineering risk.\u003C\u002Fp>\u003Ch2>How did the InfraGard breach happen?\u003C\u002Fh2>\u003Cp>According to investigations by KrebsOnSecurity and the Associated Press, the attacker created a fraudulent membership application using the real identity details of an executive at a major financial institution. The application was submitted in November 2022 and approved in early December.\u003C\u002Fp>\u003Cp>After signing in, the attacker said they used member-discovery features in the portal to collect the accessible directory. KrebsOnSecurity independently confirmed that a message sent by the attacker through the portal reached a genuine InfraGard member.\u003C\u002Fp>\u003Ch2>What information was exposed?\u003C\u002Fh2>\u003Cp>Reporting identifies member names, organizational or industry affiliations, and contact information. Although the database contained fields for Social Security numbers and dates of birth, those fields were reported to be largely empty.\u003C\u002Fp>\u003Cp>Public sources also make clear that not every member record contained the same fields. The catalog entry is therefore limited to categories consistently supported by independent reporting.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>Sources describe a directory containing records associated with more than 80,000 members, but no exact unique affected-person total was published. The approximate member or row figure is therefore not represented as an exact person count.\u003C\u002Fp>\u003Ch2>What risks can the incident create?\u003C\u002Fh2>\u003Cp>Professional affiliations involving critical infrastructure, law enforcement, information technology and corporate security can support executive impersonation, fake security notices and targeted information-gathering attempts. Accurate employer or role context can make fraudulent messages more convincing.\u003C\u002Fp>\u003Ch2>What should InfraGard members do?\u003C\u002Fh2>\u003Cp>Members should verify unexpected links, files and information requests through a separate organizational channel. A message claiming to come from InfraGard or the FBI should not be trusted solely because it contains accurate employer or role information.\u003C\u002Fp>\u003Cp>Work accounts should use app- or security-key-based multi-factor authentication, and any reused password should be replaced. Organizations should also monitor for targeted phishing directed at employees whose professional affiliations may have been exposed.\u003C\u002Fp>","","The 2022 InfraGard incident exposed its member directory. Review the confirmed access method, evidence boundaries and risks to critical-infrastructure…","\u002Fuploads\u002Flogo\u002Finfragard-2022.svg",false,{"name":36,"sector":37,"country":38,"website":19,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":20},"InfraGard","Government","United States"]