Skip to content

Security1 publisher2 min readPublished

ShinyHunters threatens to publish FBI agents' medical records unless the bureau retracts a May advisory

ShinyHunters claims it holds fitness-for-work medical records, including blood and urine results, on about 60,000 current and former FBI staff. Test results and home addresses cannot be reset like a password, so containment now depends on the files staying unpublished.

The Watch · Security desk

Photograph accompanying ShinyHunters threatens to publish FBI agents' medical records unless the bureau retracts a May advisory
Photo: yahoo.com

What happened

  • The group is asking for no money, only that the FBI retract the May advisory it says "offended" it, and says the full dataset goes public in five days otherwise.
  • Samples shown to the BBC carry names, home addresses, phone numbers, badge numbers, job titles and spouse details, and cover senior officials up to deputy directors.
  • ShinyHunters says a flaw in an Oracle cloud storage system used by the FBI got it into FBIJobs, the BEAST background-check system, MedLink and the BICS investigative system.
  • In a statement on X, the FBI said it has not yet determined whether the attackers got into its own systems or came through a third-party provider.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A record pairing a badge number and job title with spouse details gives a fraudster what is needed to pose as a named agent or approach that agent's family.
  • decision The FBI has to decide, against a five-day clock, whether to withdraw published guidance under threat; a retraction would show other crews that a leak can edit a government advisory.
  • exposure BEAST holds background checks on applicants as well as employees, so if the access claim holds, people who never joined the bureau are in the dataset too.

The count has moved once already. Early reporting assumed the breach touched the FBI's 38,000 current employees [3]. The group now says it underestimated the haul and holds data on around 60,000 current and former staff [2]. That leaves roughly 22,000 people outside today's workforce [1], and puts the claimed total at about 1.6 times the current headcount [2]. Every figure in the claim concerns FBI personnel [2][8]. "The list maps thousands of agents against their medical and fitness records," said Etay Maor, vice-president of threat intelligence at Cato Networks [12].

The medical content in the samples is ordinary. Doctors' notes mention a "shellfish and banana allergy" [4], blood in the urine and high cholesterol [5]. Maor's case rests on how long those facts stay true. "Passwords can be reset if stolen, but medical records cannot, so once this data is out, it stays compromised for good. That permanence, applied across an entire workforce, is what makes this leak so serious," he said [13].

Most of the scope rests on the attackers' word. ShinyHunters says it got in on Monday and later posted details on its darknet site [1]. It shared samples with reporters along with its extortion demand [18], and the BBC said those samples appear genuine [7]. Ciaran Martin, former head of the UK's National Cyber Security Centre, described the hack, if confirmed, "as serious as it gets when it comes to data breaches" [14]. Jamie Akhtar, chief executive of CyberSmart, said the claims should be treated with caution [15].

The FBI's account is narrower than the group's. Its claim covers four systems [9]. The bureau's statement mentions only the contractors behind its jobs portal. "We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk," the statement said [11].

The crew has been active since 2019 and has been linked to incidents at Rockstar Games and the education platform Canvas [16]. It deals with reporters in English over Telegram [17].

What to watch

  • Whether the full dataset appears on ShinyHunters' darknet site when the five-day deadline lapses, and whether it contains MedLink and BICS material.
  • Whether the FBI names the Oracle storage flaw or the third-party provider behind FBIJobs.gov.
  • Whether the FBI answers the demand to retract its May advisory.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories