A cyber-criminal group claiming to have hacked the FBI has posted that it possesses highly sensitive medical data on thousands of special agents and agency staff. BBC News saw samples of stolen medical fitness-for-work examinations.
The stolen examinations contain data such as blood and urine test results and clinical notes mentioning conditions including shellfish and banana allergies. The records also include agents' full names and addresses, as well as references to health problems including blood in urine and high cholesterol. Samples shared with journalists appear authentic and include names, addresses, phone numbers, badge numbers, work locations and spouse details. The records appear to concern thousands of agents, including senior officials such as deputy directors.
Experts warn the breach could leave agents vulnerable to fraud, extortion and targeted attacks, and could help criminals impersonate law enforcement officers. Etay Maor, vice president of threat intelligence at Cato Networks, said the list links thousands of agents with their medical and fitness records. "Passwords can be reset if stolen, but medical records cannot. Once that data is out, it stays compromised forever," Maor said.
The FBI is investigating the breach, and an agency spokesperson did not respond to requests for comment. On Wednesday the FBI acknowledged the intrusion and said it was "aggressively investigating" how it occurred. In a post on X, the FBI said it was still trying to determine whether the hackers directly breached its systems or compromised a third-party service provider. The agency said it was actively and aggressively investigating the case and was working closely with third-party service providers supporting FBIJobs.gov to mitigate any risk.
Cyber-criminal group ShinyHunters claims it breached FBI systems on Monday and later posted details of the attack on its dark web site. The group shared samples of the allegedly stolen data with journalists alongside an extortion demand. The hackers are not seeking money but the withdrawal of an FBI notice published in May which they claim "insulted" them. They communicate with journalists in English via Telegram and say they will publish the entire dataset in five days if the FBI does not meet their demands.
Reuters reports that some of the data includes information on agents involved in investigations linked to Russia, China and drug cartels. Reporting by 404 Media suggests that data on a previously little-known FBI hacking unit may also have been exposed. It was initially believed the breach affected 38,000 current FBI employees, but the hackers now claim the number could be significantly higher. The group says it underestimated the scale of the data theft and now claims to hold sensitive information on about 60,000 current and former FBI employees.
Jamie Akhtar, chief executive and co-founder of CyberSmart, said the hackers' claims should be treated with caution, but the breach appears extremely concerning. Such data could be used for highly convincing phishing, impersonation, identity theft, extortion or even operations targeting police officers, he said.
ShinyHunters is an international hacking collective active since 2019, linked to a series of high-profile cyber attacks, including incidents affecting Rockstar Games and the educational platform Canvas. The group says it exploited a vulnerability in Oracle's cloud storage system used by the FBI and gained access to a range of platforms, including FBIJobs, FBI BEAST, FBI MedLink and FBI BICS. FBI BEAST is used for background checks on employees and candidates, FBI MedLink stores medical records, and FBI BICS contains investigative information.
Professor Ciaran Martin, former head of the UK's National Cyber Security Centre, described this breach, if confirmed, as "the most serious thing that can happen when it comes to data leaks".










