THE BBC has seen samples of medical records allegedly stolen during a breach involving the FBI. The “fitness-for-work” reports reportedly identify agents by name and address and contain phone numbers, badge numbers, job titles, information about spouses, blood and urine test results, and doctors’ notes. Examples mention high cholesterol, blood in the urine, and shellfish and banana allergies.
ShinyHunters, the extortion group claiming responsibility, shared the samples with journalists as evidence and now says it holds information on about 60,000 current and former FBI staff.
ShinyHunters claims it accessed several FBI systems, including FBI MedLink, which stores medical records, and FBI BEAST, used for employee and applicant background checks. However, the FBI has not confirmed those claims. It has acknowledged an incident affecting FBIJobs-related systems and said it is investigating whether its own environment or a third-party provider was compromised.
The group says the attack was intended to pressure the FBI into retracting or removing a May advisory it considers false and defamatory, threatening to release the data within five days if its demands are not met.
The FBI has not confirmed what information was accessed or who was affected. Current and former employees, relatives and job applicants are advised to follow updates on FBI.gov, change any reused FBI Jobs passwords, enable two-factor authentication, be alert to impersonation attempts and consider identity monitoring.