Special agents' blood and urine test results stolen in FBI hack
ByJoe Tidy World Service Cyber Correspondent.
ByJoe Tidy World Service Cyber Correspondent.
Article outline
- What happened
- Background
- Official response
- Why it matters
- The details
- The bottom line
Key points
- "The list maps thousands of agents against their medical and fitness records, " remarked Etay Maor, vice-president of threat intelligence at Cato Networks.
- Reporting by 404 Media suggests details of a previously little-known FBI hacking unit may additionally have been exposed, external.
- It was initially thought the breach affected the FBI's 38, 000 current employees, but the hackers now claim the number could be far higher.
- The cyber-criminal group ShinyHunters claims it breached FBI systems on Monday, and afterwards posted details of the attack on its darknet site.
- The news agency Reuters reports that some of the data includes information on agents, external involved in investigations relating to Russia, China and drug cartels.
Cyber-criminals who hacked the FBI say they have extremely sensitive medical data for thousands of its special agents.
BBC News has seen samples of the stolen "fitness-for-work" medical examinations. It contain information such as blood and urine test results, and doctors' notes mentioning conditions such as a "shellfish and banana allergy".
As well as references to medical reservations including 'blood in the urine' and 'high cholesterol', the records include agents' full names and addresses.
As well as support criminals impersonate law enforcement officers, experts say the hack – which the FBI is investigating – could leave agents vulnerable to scams, blackmail and targeted attacks.
"Passwords can be reset if stolen, but medical records cannot, so once this data is out, it stays compromised for good. That permanence, applied throughout an entire workforce, is what makes this leak so serious."
For context, the FBI has not responded to requests for comment. Nevertheless, on Wednesday it acknowledged the breach and stated it was "aggressively investigating" how it happened.
Notably, the cyber-criminal group ShinyHunters claims it breached FBI systems on Monday, and afterwards posted details of the attack on its darknet site.
Notably, the group additionally shared samples of the alleged stolen data with reporters, along with an extortion demand.
Unusually, the hackers are not demanding funds. Instead, they are seeking a retraction of an FBI advisory published in May. It they claim "offended" them.
Notably, the samples shared with journalists appear genuine and include names, addresses, phone numbers, badge numbers, job titles and information regarding spouses.
Meanwhile, the records appear to relate to thousands of agents, including senior authorities such as deputy directors.
Professor Ciaran Martin, the former head of the UK's National Cyber Security Centre, has described the hack – if confirmed – "as serious as it gets when it comes to data breaches." 'Phishing, impersonation, identity fraud'.
In practice, the news agency Reuters reports that some of the data includes information on agents, external involved in investigations relating to Russia, China and drug cartels.
For context, the group notes it underestimated the scale of the data theft and now claims to hold sensitive information on around 60, 000 current and former FBI staff.
Jamie Akhtar, chief executive and co-founder of CyberSmart, remarked the hackers' claims should be treated with caution but that the breach appeared to be extremely concerning.
"Such data could be used for highly convincing phishing, impersonation, identity fraud, blackmail or even operations targeting law-enforcement personnel, making the potential implications particularly serious, " he remarked.
Meanwhile, the hackers, who communicate with reporters in English via the messaging service, Telegram, say they will publish the full dataset in five days unless the FBI meets their demands.
ShinyHunters is an international hacking collective that has been active since 2019 and has been linked to a number of high-profile cyber-attacks, including incidents affecting Rockstar Games and the education platform Canvas.
Meanwhile, the group claims it exploited a vulnerability in an Oracle cloud storage system applied by the FBI, gaining access to multiple platforms including FBIJobs, FBI BEAST. It handles background checks on employees and applicants, FBI MedLink, which stores medical records, and FBI BICS, which contains investigative information.
In an official note posted on X, the FBI remarked it was still trying to determine whether the hackers had breached its systems directly or compromised a third-party provider.
"We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk, " the statement remarked. FBI investigating claim hackers have stolen details of all its agents. International cyber attack disrupts swathe of universities and schools. GTA-maker Rockstar Games hacked again but downplays impact.
In short, special agents' blood and urine test results stolen in FBI hack is the central thread here, and readers can expect follow-up reporting as the picture becomes clearer.




