Security1 publisher2 min readPublished
ShinyHunters' leak samples expose named FBI agents' medical exams
ShinyHunters has shown journalists FBI medical exams that name agents and their addresses, from a set it says covers about 60,000 current and former staff. The FBI has so far confirmed only an incident in FBIJobs-related systems, and the group is threatening to publish within five days.
The Watch · Security desk

What happened
- The fitness-for-work files include blood and urine test results and doctors' notes citing high cholesterol, blood in the urine and a shellfish and banana allergy.
- ShinyHunters says it reached FBI MedLink, which stores medical records, and FBI BEAST, which runs background checks on staff and applicants; the FBI has not confirmed either.
- The FBI says it is investigating whether its own environment or a third-party provider was compromised.
- ShinyHunters, which reportedly took over the Clop ransomware group's leak site, says it attacked the FBI to punish it for spreading what the group calls false information.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint A medical history cannot be rotated like a credential, so affected staff stay exposed long after the incident, and their only defence is checking who contacts them.
- contradiction The bureau's acknowledged scope and the group's claimed scope are different, and until they are reconciled neither staff nor applicants can tell which of their records are out.
- precedent Any change to the May advisory made under a leak threat would show other groups that a published FBI finding can be bargained over.
The BBC wrote: "The samples shared with journalists appear genuine and include names, addresses, phone numbers, badge numbers, job titles and information about spouses." [6] With those fields, a caller can pose as the bureau to an agent's spouse or find an agent at the listed address. The medical notes give whoever holds the set private detail to use for pressure [3]. Malwarebytes expects impersonation. It warns that criminals may pose as the FBI, another government agency, or someone the target knows [17].
There is evidence behind the medical exposure. The vetting exposure so far rests on the group's word. The BBC has seen samples of the exams [1]. The samples described are fitness-for-work reports and personnel details, and Malwarebytes' account of the BBC findings does not describe a background-check file among them [18]. The FBI has not confirmed what information was accessed or who was affected [14].
Both the claimed and the confirmed systems reach applicants. According to ShinyHunters, BEAST handles background checks on applicants as well as employees [7]. The incident the FBI has acknowledged is in FBIJobs-related systems [8]. Malwarebytes aims its advice at anyone who has applied for an FBI job, as well as current and former staff and their relatives [19].
ShinyHunters is an extortion group, but its stated demand is non-financial. It wants the FBI to retract or remove a May advisory that the group calls false and defamatory [10]. It has since raised its count of affected people [12]. The public record shows a single retaliation campaign against the agency that published about the group [10].
Credentials are the cheap part to fix. Malwarebytes advises people who reused their FBI Jobs password on other accounts to change it there [16]. It also recommends a FIDO2 device as the second factor. Some forms of 2FA can be phished as easily as a password, it says, while 2FA that relies on a FIDO2 device cannot [15].
What to watch
- Whether the FBI confirms or rules out access to MedLink or BEAST, or names a third-party provider as the entry point.
- Whether ShinyHunters publishes when its five-day window closes, and whether any released set contains background-check files.
- Whether the FBI amends or withdraws the May advisory the group wants removed.