Cybercriminals claim to have stolen sensitive medical and personal data of thousands of FBI special agents, including blood and urine test results, medical conditions, and addresses. The FBI acknowledged the breach and is investigating, while experts warn of potential blackmail and impersonation risks.
The breach of sensitive medical and personal data of FBI agents poses significant risks, including potential blackmail, identity fraud, and impersonation, which could compromise law enforcement operations and national security.
Cyber-criminals claiming to be part of the group ShinyHunters have stated they breached FBI systems and obtained highly sensitive medical and personal data belonging to thousands of special agents. The stolen information reportedly includes blood and urine test results, details of medical conditions, full names, addresses, phone numbers, badge numbers, and job titles.
The FBI has acknowledged the breach and is conducting an aggressive investigation into how it occurred, including whether a third-party provider was compromised. Experts warn that the permanent nature of medical data means agents could be vulnerable to scams, blackmail, identity fraud, and impersonation for extended periods.
Unusually, the hackers are not demanding a financial ransom. Instead, they are seeking a retraction of an FBI advisory published in May, which they claim offended them. They have given the FBI five days to meet their demands before they release the full dataset, which they now claim includes information on approximately 60,000 current and former FBI staff.
The alleged exploit targeted a vulnerability in an Oracle cloud storage system used by the FBI, potentially affecting systems related to job applications, background checks, medical records, and investigative information. The samples shared with reporters appear to be genuine and include details on senior officials.
Pick the topics you care about. Get only what matters, on your cadence.