ShinyHunters claims FBI staff medical records in breach

Published

The extortion group ShinyHunters says it holds sensitive records on around 60,000 current and former FBI employees, and the samples it has circulated go well beyond names and email addresses. According to Malwarebytes Labs, the material the group shared with journalists includes fitness-for-work medical examinations that identify agents by name and address, with blood and urine test results and doctors' notes.

The FBI has not confirmed that. It has acknowledged an incident affecting FBIJobs-related systems and says it is investigating whether its own environment or a third-party provider was compromised. Check Point Research's weekly report records that the bureau confirmed unauthorized activity affecting FBIjobs.gov after ShinyHunters defaced the site.

What the group says it took

Every figure here is the attacker's claim unless the FBI says otherwise. ShinyHunters says it reached several internal systems, including FBI MedLink, which it describes as holding medical records, and FBI BEAST, which it says handles background checks on employees and applicants. The FBI has not confirmed either claim.

The samples reportedly include names, addresses, phone numbers, badge numbers, job titles and information about spouses. The group has also raised its own tally since first announcing the breach, and now puts the number of affected people at about 60,000.

A demand that is not about money

Unusually for an extortion crew, ShinyHunters is not asking for a ransom. Malwarebytes reports that the group wants the FBI to retract or remove an advisory from May that it calls false and defamatory, and says it attacked the bureau to punish it for what it calls false information about the group. It has threatened to release the data within five days if the demand is not met. The group has also reportedly taken over the leak site previously run by the Clop ransomware operation.

This is the same crew IntelFusions reported last week slipping past web application firewall rules to break into unpatched Oracle PeopleSoft systems, and it has a long record of large data-theft claims against US organizations, including McKesson last month.

Why medical records change the stakes

A stolen password can be reset. A medical history cannot. For people who work in law enforcement and intelligence, a leaked combination of home address, family details and health conditions is also a ready-made kit for targeting, coercion and convincing impersonation, well beyond ordinary identity theft.

If you have ever applied to or worked for the FBI

The FBI has not said who is affected, so Malwarebytes' advice applies broadly to current and former staff, their relatives and anyone who has applied through FBI Jobs:

Whether the five-day deadline produces a leak or a quiet extension, the harm from this kind of data does not expire with the news cycle, and the people named in it will be managing the fallout for years.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Detection coverage

Read the full analysis on IntelFusions