FBI Investigates Major Cyber Breach Claim Involving Special Agents' Sensitive Data

FBI Investigates Major Cyber Breach Claim Involving Special Agents' Sensitive Data

The Federal Bureau of Investigation is aggressively investigating a cyber attack after a hacker group claimed to have compromised its systems and stolen sensitive personal and medical data belonging to thousands of special agents. The cyber-criminal collective known as ShinyHunters claimed responsibility for the breach on Monday, subsequently posting details on its darknet website and sharing samples of the stolen material with reporters along with an extortion demand.

The stolen files reportedly include "fitness-for-work" medical examinations, detailing blood and urine test results, high cholesterol, specific conditions like food allergies, and various physicians' notes. In addition to medical background, the leaked records allegedly contain agents' full names, physical addresses, phone numbers, badge numbers, job titles, and information regarding their spouses. The records involve thousands of personnel, including high-ranking officials such as deputy directors, as well as agents involved in investigations concerning Russia, China, and drug cartels. Reports also indicate that details regarding a little-known FBI hacking unit may have been exposed.

Extortion Demands and Scope of the Breach

Rather than demanding a financial ransom, ShinyHunters is demanding that the FBI retract a public advisory issued in May, which the group claimed was offensive. The hackers, communicating via Telegram, stated they will release the entire dataset in five days if their demand is not met. While initial reports suggested the breach impacted the FBI's 38,000 current employees, the group later claimed to hold sensitive data on approximately 60,000 current and former staff members.

ShinyHunters claims it gained access by exploiting a vulnerability in an Oracle cloud storage system utilized by the FBI. According to the collective, this allowed them to access several platforms, including FBIJobs, FBI MedLink, FBI BEAST—which processes background checks for staff and applicants—and FBI BICS, an investigative information database.

Official Response and Security Concerns

In a statement published on X, the FBI acknowledged the security incident and confirmed an active investigation. The bureau stated it is working to determine whether its internal systems were breached directly or if a third-party vendor was compromised. The FBI noted it is collaborating closely with third-party providers supporting FBIJobs.gov to mitigate potential risks.

Cybersecurity experts warn that the exposure of permanent medical records and personal details poses severe long-term risks. Threat intelligence professionals noted that unlike passwords, medical records cannot be reset once leaked. Experts cautioned that the exposed data could enable targeted phishing schemes, blackmail, identity fraud, impersonation of law enforcement officers, or direct physical targeting of personnel. ShinyHunters, active since 2019, has previously been linked to high-profile cyber incidents affecting organizations such as Rockstar Games and Canvas.

0 YORUMLAR

    Bu KONUYA henüz yorum yapılmamış. İlk yorumu sen yaz...
YORUM YAZ