Special agents' blood and urine test results stolen in FBI hack
Experts say the hack could leave agents vulnerable to scams, blackmail and targeted attacks.

Special agents’ blood and urine test results stolen in FBI hack
Cyber-criminals who breached the FBI say they have highly sensitive medical information on thousands of its special agents.
BBC News has reviewed samples of the stolen “fitness-for-work” medical exams, which include details such as blood and urine test results, along with doctors’ notes referring to conditions including a “shellfish and banana allergy”.
The files contain agents’ full names and addresses, as well as references to medical issues such as “blood in the urine” and “high cholesterol”.
Experts say the hack — which the FBI is investigating — could expose agents to scams, blackmail and targeted attacks, while also helping criminals pose as law enforcement officers.
“The list maps thousands of agents against their medical and fitness records,” said Etay Maor, vice-president of threat intelligence at Cato Networks.
“Passwords can be reset if stolen, but medical records cannot, so once this data is out, it stays compromised for good. That permanence, applied across an entire workforce, is what makes this leak so serious.”
The FBI has not replied to requests for comment. But on Wednesday it confirmed the breach and said it was “aggressively investigating” how it occurred.
The cyber-criminal group ShinyHunters says it broke into FBI systems on Monday, then posted details of the attack on its darknet site.
The group also sent reporters samples of the alleged stolen data, together with an extortion demand.
Unusually, the hackers are not asking for money. Instead, they want the FBI to retract an advisory published in May, which they say “offended” them.
The samples shared with journalists appear authentic and include names, addresses, phone numbers, badge numbers, job titles and information about spouses.
The records appear to cover thousands of agents, including senior officials such as deputy directors.
Professor Ciaran Martin, the former head of the UK’s National Cyber Security Centre, has called the hack — if confirmed — “as serious as it gets when it comes to data breaches.”
Reuters reports that some of the data includes information on agents involved in investigations linked to Russia, China and drug cartels.
Reporting by 404 Media suggests that details of a previously little-known FBI hacking unit may also have been exposed.
It was first believed the breach affected the FBI’s 38,000 current employees, but the hackers now say the number may be much larger.
The group says it underestimated the scale of the theft and now claims to possess sensitive information on about 60,000 current and former FBI staff.
Jamie Akhtar, chief executive and co-founder of CyberSmart, said the hackers’ claims should be treated cautiously, but added that the breach appeared extremely worrying.
“Such data could be used for highly convincing phishing, impersonation, identity fraud, blackmail or even operations targeting law-enforcement personnel, making the potential implications particularly serious,” he said.
The hackers, who speak to reporters in English through Telegram, say they will release the full dataset in five days unless the FBI agrees to their demands.
ShinyHunters is an international hacking collective active since 2019 and linked to several major cyber-attacks, including incidents involving Rockstar Games and the education platform Canvas.
The group says it exploited a vulnerability in an Oracle cloud storage system used by the FBI, gaining access to several platforms including FBIJobs, FBI BEAST, which handles background checks on employees and applicants, FBI MedLink, which stores medical records, and FBI BICS, which contains investigative information.
In a statement posted on X, the FBI said it was still trying to determine whether the hackers had directly breached its systems or compromised a third-party provider.
“We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk,” the statement said.

