Yovao News · The World, In Focus. From Local to Global, Never Miss a Beat

FBI confirms hack as cybercriminals steal medical data on thousands of agents

FBI confirms hack as cybercriminals steal medical data on thousands of agents

A cybercriminal group has claimed responsibility for breaching Federal Bureau of Investigation (FBI) systems, stealing highly sensitive medical and personal data belonging to thousands of special agents. The group, known as ShinyHunters, stated that it accessed the bureau’s infrastructure earlier this week and published samples of the illicitly obtained information on darknet forums.

Reports reviewed by BBC News indicate that the stolen files contain comprehensive “fitness-for-work” medical examinations. These documents include blood and urine test results, physician notes regarding conditions such as severe allergies to shellfish and bananas, and other health concerns like hematuria and high cholesterol. In addition to medical details, the data allegedly comprises full names, home addresses, phone numbers, badge numbers, job titles, and spouse information.

The FBI acknowledged the security breach on Wednesday, confirming it is conducting an aggressive investigation into the incident. While the bureau initially estimated the breach affected approximately 38,000 current employees, ShinyHunters has since revised its claim, suggesting the scale is much larger and that sensitive information on roughly 60,000 current and former staff members may be compromised.

Unlike typical data breaches that seek financial ransom, the hackers are demanding a retraction of a specific FBI advisory issued in May, which they stated was offensive. The group has warned that if their demands are not met within five days, they plan to release the entire dataset publicly. Communications with journalists were conducted in English via the messaging platform Telegram.

Security experts have raised alarms about the permanence of the leaked information. Etay Maor, vice-president of threat intelligence at Cato Networks, emphasized that while passwords can be changed, medical records remain compromised indefinitely. He noted that mapping thousands of agents against their private health records creates unique vulnerabilities compared to standard credential theft.

The potential consequences of the leak extend beyond privacy violations. Professor Ciaran Martin, former head of the UK’s National Cyber Security Centre, described the incident as among the most severe possible for data breaches. Jamie Akhtar, CEO of CyberSmart, added that the exposed data could facilitate sophisticated phishing campaigns, identity fraud, blackmail, and impersonation of law enforcement officers.

ShinyHunters alleges that the intrusion was facilitated by a vulnerability in an Oracle cloud storage system utilized by the FBI. The group claims to have gained access to several internal platforms, including FBIJobs, which handles employment; FBI BEAST, which manages background checks; FBI MedLink, for medical records; and FBI BICS, containing investigative data.

Reporting by Reuters indicates that some of the compromised individuals are involved in high-stakes investigations concerning Russia, China, and international drug cartels. Additionally, 404 Media suggested that details regarding a lesser-known FBI hacking unit may have been exposed in the breach.

In a statement posted on X, the FBI clarified that it is still determining whether the hackers accessed its systems directly or compromised a third-party provider supporting FBIJobs.gov. The bureau stated it is working closely with these providers to mitigate risks.

ShinyHunters, an international collective active since 2019, has been linked to previous high-profile attacks on entities such as Rockstar Games and the educational platform Canvas.

Leave a Reply

Your email address will not be published. Required fields are marked *