Cybercriminals who breached the FBI’s systems claim to have obtained highly sensitive medical data belonging to thousands of the agency’s special agents.

BBC News has reviewed samples of the stolen “fitness-for-work” medical examinations, which include detailed blood and urine test results alongside doctors’ notes referencing specific conditions, such as a shellfish and banana allergy.

The compromised records contain agents’ full names, home addresses, and references to various medical concerns, including hematuria (blood in the urine) and elevated cholesterol levels.

Security experts warn that this breach could expose agents to severe risks, including targeted scams, blackmail, and physical or digital attacks, while also providing criminals with the tools needed to impersonate law enforcement officers.

Etay Maor, vice president of threat intelligence at Cato Networks, explained that the leaked data effectively maps thousands of agents directly to their personal medical and fitness records.

Unlike passwords, which can be reset after a compromise, medical records cannot be undone. This permanent exposure, affecting an entire law enforcement workforce, is what makes the leak exceptionally severe.

The FBI has not responded to requests for comment, but the agency acknowledged the breach on Wednesday, stating that it is “aggressively investigating” the incident.

The cybercriminal group ShinyHunters claims to have breached FBI systems on Monday, subsequently publishing details of the attack on its darknet portal.

The group also shared samples of the purported stolen data with journalists, alongside an extortion demand.

In an unusual twist, the hackers are not demanding a financial ransom. Instead, they are demanding the retraction of an FBI advisory published in May, which they claim offended them.

The samples shared with journalists appear to be authentic, containing highly sensitive personal details such as names, addresses, phone numbers, badge numbers, job titles, and information regarding the agents’ spouses.

These records reportedly span thousands of agents, including high-ranking officials such as deputy directors.

Professor Ciaran Martin, the former head of the UK’s National Cyber Security Centre, described the hack—as confirmed—as “as serious as it gets when it comes to data breaches.”

Source link

Exit mobile version