A data breach affecting the FBI has expanded significantly beyond the personal information first reported last week, with the hacking group ShinyHunters now claiming to possess psychiatric and medical evaluation records belonging to as many as 60,000 current and former bureau personnel.
The FBI has roughly 38,000 current employees, meaning the alleged haul would extend well beyond the active workforce to include former agents and staff. The bureau has not independently confirmed that figure.
ShinyHunters first claimed last week to have stolen between two and three terabytes of FBI data, including names, home addresses, phone numbers, dates of birth, and information about employees’ spouses. The group provided reporters with a sample of roughly 5,000 FBI employee records, some of which matched Justice Department personnel.
The FBI says it is now investigating the breach but has not determined, or has not disclosed, exactly how the hackers gained access. The bureau said investigators are examining whether the intrusion came through FBI systems directly or through a third-party provider that supports the FBIJobs.gov hiring website.
“While the point of breach is still undetermined — whether a third-party or the F.B.I.’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.”
Medical files verified
Documents provided by ShinyHunters include sensitive psychiatric and medical evaluation records tied to FBI personnel. Reuters checked two Social Security numbers found in the files against credit bureau data and matched the date of a pre-employment mental health evaluation to the employment history of a former FBI analyst. Other details in the documents were independently verified as well.
One file contained results from a fitness-for-duty examination, including blood and urine test results and doctors’ notes. Another referenced a prospective employee who had experienced symptoms of depression in high school. A third contained an electrocardiogram result. ShinyHunters claims the broader cache includes prescriptions, records of clinical visits, medical discharges and other health information — with each record listing the individual’s full name and home address alongside the medical details.
Etay Maor, vice president of threat intelligence at Cato Networks, said the nature of the exposed data makes this breach unusually damaging.
“Passwords can be reset if stolen, but medical records cannot, so once this data is out, it stays compromised for good. That permanence, applied across an entire workforce, is what makes this leak so serious.”
Sensitive assignments at risk
Some of the exposed records may involve personnel who worked on the bureau’s most sensitive cases. Information obtained in the breach reportedly includes details about FBI personnel and assignments tied to Chinese spies, Russian intelligence, and drug cartels, among other sensitive work.
Former FBI operative Eric O’Neill compared the potential scale of the breach to the 2015 Office of Personnel Management hack, which exposed millions of federal personnel records, and warned about foreign intelligence interest in the material.
“I would be shocked if Russian intelligence isn’t knocking on their door and saying, ‘We want that stuff, hand it over.'”
ShinyHunters says it accessed several FBI systems, including MedLink, which stores personnel medical records, as well as systems used for employee and applicant background investigations. Those specific access claims have not been independently corroborated.
The group initially threatened to publish the full dataset within days unless the FBI retracted a May advisory accusing ShinyHunters of using threatening and coercive tactics against victims. That ultimatum has since been removed from the group’s site, and ShinyHunters told Reuters it would not say what it plans to do if the FBI does not comply.
Reporters have authenticated portions of the stolen data, including medical test results. The FBI has not said when its investigation will conclude.
You must be logged in to post a comment Login