FBI Agents' Sensitive Medical Data Allegedly Stolen in ShinyHunters Breach
Extortion group ShinyHunters claims to have breached the FBI, allegedly stealing sensitive medical records of agents, including blood test results and doctors' notes, and is demanding the FBI retract an advisory.

The FBI is investigating a data breach that has reportedly exposed the highly sensitive medical records of its agents, including detailed fitness-for-work reports, blood test results, and doctors' notes. The extortion group ShinyHunters has claimed responsibility for the attack, stating it was a retaliatory measure against the FBI for an advisory the group deemed false and defamatory.
BBC News has reportedly seen samples of the stolen data, which include personal details such as names, addresses, phone numbers, badge numbers, and job titles. More alarmingly, the samples allegedly contain intimate medical information, such as results from blood and urine tests, and notes detailing conditions like high cholesterol, blood in the urine, and even allergies. This type of information, unlike a compromised password, cannot be changed, leaving affected individuals vulnerable long-term.
ShinyHunters claims to have accessed multiple FBI systems, including FBI MedLink, which is believed to store medical records, and FBI BEAST, a system used for background checks. While the FBI has confirmed an incident affecting systems related to FBIJobs, it has not yet confirmed the specific systems compromised or the full extent of the data exfiltrated.
The group's demands are non-financial. ShinyHunters is calling for the FBI to retract or remove a May advisory that the group claims is false and damaging to its reputation. The attackers have set a deadline, threatening to release the sensitive data on approximately 60,000 current and former FBI staff if their demands are not met within five days.
This incident marks a significant escalation in the tactics of groups like ShinyHunters, moving beyond financial extortion to leverage highly personal data for leverage. The potential impact on the affected agents and their families is profound, raising concerns about privacy, personal security, and the potential for future misuse of this sensitive information.
The FBI has advised individuals who may be affected—current or former employees, their relatives, or applicants—to monitor FBI.gov for official updates and guidance. Recommended actions include changing passwords for any FBI Jobs accounts and reusing them elsewhere, enabling two-factor authentication (preferably with a FIDO2-compliant hardware key), and remaining vigilant against potential impersonation attempts or phishing scams.
Furthermore, the FBI is urging individuals to consider setting up identity monitoring services. These services can alert individuals if their personal information appears on the dark web or is being traded illegally, and can assist in recovery efforts should identity theft occur. The breach underscores the persistent threat posed by sophisticated threat actors and the critical need for robust cybersecurity measures and ongoing vigilance.