The FBI dealt with an incident over the weekend, with fake emails being sent to agency partners.

See also: FBI: Iranian hackers trying to buy stolen data from US organizations
The federal agency has blamed an incident on a misconfiguration in the Law Enforcement Enterprise Portal (LEEP)that allowed emails to be sent from the ic.fbi.gov.
“LEEP is the FBI’s IT infrastructure used to communicate with state and local law enforcement partners,” he said.
“While the illicit email originated from a server operated by the FBI, that server was dedicated to forwarding LEEP notifications and was not part of the FBI's corporate email service. No malicious actor was able to access or compromise any data or PII on the FBI network.“
See also: FBI: HelloKitty ransomware adds DDoS to extortion tactics

The FBI said it initially quickly took the “affected hardware” offline and later said it immediately remediated the “software vulnerability” as well as confirmed the integrity of network .
Spamhaus said it detected two waves of emails being sent.
Brain Krebs reported that the email sender found that he was able to send emails because the FBI was generating a client-side one-time code to register for a new LEEP account and it was sent along with a subject and body of the email as a POST to the FBI servers. Manipulation of the request parameters allowed the emails to be sent, and a script was used to automate the sending process.
See also: Phishing emails infect victims with MirCop ransomware
It appears that all of the so-called incorrect parameters and software vulnerabilities had to do with the way the FBI had set up its gateway, culminating in the way it exposed and funneled user data to a mail server.
