An alarming breach of FBI data systems has resulted in the theft of highly sensitive medical information of thousands of special agents, according to cyber-criminals who claim responsibility for the hack.
Details of the Hack
BBC News has confirmed the authenticity of some of the stolen “fitness-for-work” medical assessments. These records include detailed information such as blood and urine test results, full names, addresses, and notes on specific medical conditions like allergies to shellfish and bananas. Additionally, there are references to medical issues such as ‘blood in the urine’ and ‘high cholesterol.’
According to cybersecurity expert Etay Maor from Cato Networks, this data breach poses a significant threat to the agents. “Medical records, once exposed, remain compromised permanently,” he explained, underscoring the potential for scams, blackmail, and other criminal activities.
FBI’s Response and Hackers’ Demands
The FBI has acknowledged the breach and is conducting a rigorous investigation to determine how it occurred. The hacking group, ShinyHunters, has claimed responsibility, stating they accessed the FBI’s systems on Monday. They have shared samples of the data and issued an unusual demand: a retraction of an FBI advisory from May, which they found offensive, rather than a monetary ransom.
The data shared with journalists appears to be authentic, containing personal details like badge numbers and job titles, as well as information about agents’ spouses. It reportedly includes the records of senior officials, such as deputy directors.
Extent of the Breach
Initial reports suggested the breach affected the FBI’s 38,000 current employees. However, the hackers now claim the scope is much broader, with sensitive information on approximately 60,000 current and former FBI personnel.
Jamie Akhtar, CEO of CyberSmart, warns of the serious implications of this breach, emphasizing the potential for phishing, impersonation, and identity fraud. The hackers have threatened to release the full dataset if their demands are not met within five days.
Method of Attack
The ShinyHunters group, active since 2019 and linked to other high-profile cyber incidents, claims to have exploited a vulnerability in an Oracle cloud storage system used by the FBI. This allowed them to access various platforms, including those handling employee background checks and medical records.
The FBI is still investigating whether its systems were directly breached or if a third-party provider was compromised, working closely with these providers to mitigate risks.
