Skip to main content

ShinyHunters hackers breach FBI and steal sensitive medical data

Cyber-criminal group ShinyHunters claims to have stolen medical records and blood test results of 60,000 FBI agents, demanding an advisory retraction.

AI-written
Inewgen
Live26 Sep 2026Source: BBC World4 min read (0 views)
Share
ShinyHunters hackers breach FBI and steal sensitive medical data

Stock photo for illustration only, not from the actual event

Font size
  • ShinyHunters group claims to have hacked FBI systems and stolen medical data of 60,000 agents.
  • Hackers are not asking for money but demand the retraction of an FBI advisory published in May.
  • Leaked details reportedly include agents' names, addresses, phone numbers, and spouse information.
  • The FBI has acknowledged the breach and is actively investigating how the security incident occurred.

A major cybersecurity breach has unfolded after an international hacking collective known as ShinyHunters claimed responsibility for infiltrating the Federal Bureau of Investigation. The group asserted they managed to obtain highly sensitive medical information, including blood and urine test results belonging to numerous special agents. This leaked database maps thousands of agents directly against their physical fitness and medical records, raising serious alarms among security experts regarding potential targeted threats and scams.

Etay Maor, vice-president of threat intelligence at Cato Networks, highlighted the severe permanence of the breach. Passwords can easily be reset if compromised, but medical records cannot be altered, meaning once this information is exposed, it remains permanently vulnerable across an entire workforce.

While the FBI has not officially responded to direct interview requests, the federal agency acknowledged the cyber incident and stated it is aggressively investigating the origin of the breach. ShinyHunters stated they breached FBI networks earlier in the week, subsequently publishing attack details on their darknet site and sharing data samples with journalists along with an extortion demand.

cyber security digital data server room network

Stock photo for illustration only, not from the actual event

60,000Current and former FBI staff whose data was reportedly stolen

Unusually, the hackers are bypassing monetary demands entirely. Instead, they are demanding a formal retraction of an FBI security advisory published back in May, which the collective claims offended them. The distributed data samples appear legitimate, containing names, residential addresses, telephone numbers, badge numbers, job titles, and details concerning agents' spouses, including senior officials and personnel involved in high-profile investigations regarding China, Russia, and drug cartels.

Never miss the latest news?

Subscribe to get news summaries by email - not often enough to be annoying.

โฆษณา

"Passwords can be reset if stolen, but medical records cannot, so once this data is out, it stays compromised for good."

Etay Maor, Vice-President of Threat Intelligence at Cato Networks

This high-profile breach against a premier law enforcement agency illustrates a tactical shift among modern threat actors, moving beyond traditional financial extortion toward gathering high-value intelligence for political leverage and psychological warfare. By prioritizing a demand for public policy retraction over monetary ransom, the attackers underscore a motivation driven by notoriety and institutional defiance, presenting a far more complex challenge for cybersecurity negotiators and federal investigators alike.

Reuters reported that portions of the compromised data also involve agents connected to foreign investigations. Initial estimates suggested the breach impacted 38,000 current employees, but the hackers later revised their claims, stating they underestimated the scale and now hold sensitive information on approximately 60,000 current and former staff members.

Jamie Akhtar, chief executive and co-founder of CyberSmart, advised treating the hackers' claims with caution while acknowledging the extreme severity of the situation. Such data could enable convincing phishing attacks, identity fraud, blackmail, or direct operations against law enforcement personnel. ShinyHunters has remained active since 2019, previously linking to high-profile breaches involving corporate entities like Rockstar Games, and reportedly exploited a vulnerability within an Oracle cloud storage system utilized by the bureau.

Source: BBC World

Comments

Leave a Comment
0/2000

Found something wrong in this article? Report an issue with this article