Cyber-criminals who claim to have breached the FBI say they stole highly sensitive medical information belonging to thousands of the agency’s special agents, according to the BBC.
Samples reviewed by the broadcaster appear to include “fitness-for-work” medical examinations, blood and urine test results, doctors’ notes and information about conditions such as allergies, blood in the urine and high cholesterol.
The records also reportedly contain agents’ full names, addresses, phone numbers, badge numbers, job titles and details about spouses. The exposed information is believed to involve thousands of employees, including senior officials.
FBI investigates alleged breach
The hacking group ShinyHunters said it breached FBI systems on Monday and later published details of the alleged attack on a darknet site. It also shared samples of the purportedly stolen data with journalists and issued demands to the agency.
Unlike many extortion attacks, the group is not seeking money. Instead, it wants the FBI to retract an advisory published in May, which the hackers say offended them.
In a statement posted on X, the FBI said it was determining whether its systems had been accessed directly or whether a third-party provider had been compromised.
“We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk,” the FBI said.
Potential risks for agents
Cybersecurity experts warned that the information could be used for phishing, impersonation, identity fraud, blackmail and targeted attacks against law-enforcement personnel.
“Passwords can be reset if stolen, but medical records cannot, so once this data is out, it stays compromised for good,” said Etay Maor, vice-president of threat intelligence at Cato Networks.
Jamie Akhtar, chief executive and co-founder of CyberSmart, said the hackers’ claims should be treated cautiously, while describing the reported breach as extremely concerning.
Former head of the UK’s National Cyber Security Centre Ciaran Martin said that, if confirmed, the incident would be “as serious as it gets when it comes to data breaches”.
Hackers claim wider data theft
It was initially thought that the breach could affect the FBI’s 38,000 current employees. ShinyHunters now claims it holds sensitive information on about 60,000 current and former staff members.
Reuters reported that some of the data allegedly relates to agents involved in investigations concerning Russia, China and drug cartels. Reporting by 404 Media also suggested that information about a previously little-known FBI hacking unit may have been exposed.
The group claims it exploited a vulnerability in an Oracle cloud storage system used by the FBI, gaining access to platforms including “FBIJobs”, “FBI BEAST”, “FBI MedLink” and “FBI BICS”. The FBI has not confirmed that account.
ShinyHunters said it would publish the full dataset in five days unless the agency met its demands. The international hacking collective has been active since 2019 and has been linked to cyber-attacks affecting “Rockstar Games” and the education platform “Canvas”.