Invest1 publisher3 min readPublished
ShinyHunters says its FBI haul of up to three terabytes includes staff psychiatric records
ShinyHunters says the two to three terabytes it took from the FBI include psychiatric and medical evaluations of bureau staff. Beside a Reuters sample tying named staff to counterintelligence jobs, those files are exposure no password reset can fix.
The Investor · Invest desk

What happened
- ShinyHunters claims the data it stole from the FBI includes psychiatric and medical evaluation records of bureau personnel.
- Records reviewed by the BBC include blood and urine test results, doctors' observations and allergies, alongside agents' real names and addresses.
- Reuters examined a 5,000-line sample linking identified FBI employees to intelligence, surveillance and counterintelligence jobs, including operations in Russia and China.
- Instead of demanding money, the group asked the FBI to apologise for a May notice it said insulted it, and later withdrew that demand.
- The FBI said on Wednesday it was "actively and aggressively investigating" the matter, and the cause of the breach remains unclear.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Staff whose clinical histories and postings sit in one stash stay open to social-engineering and recruitment approaches for years, and O'Neill expects hostile services to go after the files.
- constraint With no ransom on the table, the FBI has no payment that could buy deletion or reveal what the group holds, so containment depends on the investigation alone.
- decision Agencies running personnel systems now have to decide whether hiring portals and health records get operational-grade controls, after GAO found the main background-check agency short on privacy controls post-OPM.
A stolen password stops being useful the day it is changed. Six documents Reuters reviewed turned up an electrocardiogram result, a daily aspirin habit and a note that an applicant showed "signs of depression" in high school [4]. Each of those stays true for the rest of the employee's career. Etay Maor, vice president of threat intelligence at Cato Networks, told the BBC: "Passwords can be reset if stolen, but medical records cannot." [8]
The medical files matter most when they sit next to other files. On their own they are an ordinary privacy breach. Next to a list tying named staff to counterintelligence postings [6], they show a hostile service which officers work on which country and which of them has a condition worth knowing about. Eric O'Neill, a former FBI agent who founded Nexasure AI, told Reuters the medical information puts the event on a level with the 2015 Office of Personnel Management breach and may draw the attention of hostile intelligence services [19]. He told Reuters: "I would be shocked if Russian intelligence isn't knocking on their door and saying, 'We want that stuff, hand it over.'" [18]
The deal terms, such as they are, cut against the group's history. Huntress describes ShinyHunters as a financially motivated operation, active since at least 2019, that steals SaaS and cloud data at scale and runs "pay or leak" extortion [10]. Asking for an apology, then dropping even that [11], leaves the FBI with nothing to buy. There is no ransom to weigh against the cost of a leak. There is also no negotiation in which the bureau could test what the group actually holds.
How large the exposure is depends on facts still open. The group says it also got into FBI MedLink and background-checking systems, a claim Reuters has not independently verified [12]. If the files came only from FBIJobs.gov, the exposure is mostly pre-employment assessments. If MedLink was reached, it probably covers the clinical history of the serving workforce. Entry is the second open question. FBIJobs.gov runs on Oracle PeopleSoft [13], and Mandiant has linked ShinyHunters to PeopleSoft hacks that exploited CVE-2026-35273, a flaw Oracle scored 9.8 out of 10 [14]. No public evidence connects that flaw to this breach [15]. Volume is the third. Reuters partially confirmed some records against credit bureau details, LinkedIn profiles and a person familiar with the FBI assessments [5], and a handful of checked documents says little about whether the group holds the two to three terabytes it claims [7].
The precedent favours the broad reading. The OPM breach exposed sensitive data on around 22 million federal employees and contractors, according to the GAO [16]. The GAO later found that the agency handling most federal background checks had not fully installed privacy controls in all the systems it examined [17]. In my view the FBI case supports giving hiring portals and occupational-health systems the controls agencies use on operational networks. FBIJobs.gov holds a wealth of information on applicants and employees [20], and personnel data is what tells an adversary whom to approach.
The counter-case is narrower and cheaper. Suppose the investigation traces entry to one unpatched PeopleSoft instance and finds MedLink and the background systems untouched. Then the fix is patching a 9.8-rated flaw on time. Reclassifying HR data wholesale would mean spending against a risk this breach did not demonstrate.
What to watch
- Whether Reuters or the FBI verifies the group's claim to have entered FBI MedLink and the background-checking systems.
- Whether the FBI, Oracle or Mandiant ties the breach to CVE-2026-35273 in PeopleSoft.
- Whether ShinyHunters publishes more than samples now that it has no outstanding demand.