The post accompanying the leaked data claimed the attackers used a zero-day vulnerability in Java back in March (not the recent vulnerability disclosed and patched last week). If the post lied about the source of the leak, it may have lied about the methods used to generate this list. It's also not known at this time why the FBI would have this list in the first place (although the implications are frightening).

