FBI hack: special agents' blood and urine test results stolen
Hackers claiming the FBI breach shared samples with journalists showing special agents' medical exams, including blood and urine test results.
ShinyHunters, described as an international hacking collective active since 2019 and linked to attacks on Rockstar Games and the education platform Canvas, claims it breached FBI systems on Monday by exploiting a vulnerability in an Oracle cloud storage system used by the bureau, the BBC reports. The group says it accessed FBIJobs, FBI BEAST (background checks), FBI MedLink (medical records) and FBI BICS (investigative information), and claims to hold sensitive information on around 60,000 current and former staff — initially thought to be 38,000 current employees.
The FBI acknowledged the breach on Wednesday, saying: “We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.” The FBIJobs site remained offline as of Wednesday afternoon.
BBC News says it has seen samples of the stolen “fitness-for-work” medical examinations containing blood and urine test results, doctors’ notes mentioning a “shellfish and banana allergy”, plus references to “blood in the urine” and “high cholesterol”. The records include agents’ full names and addresses and appear genuine.
Unusually, the hackers are not demanding money. They seek a retraction of an FBI advisory published in May which they claim “offended” them, and say they will publish the full dataset in five days unless the FBI meets their demand. The claims could not immediately be verified, and the FBI has not responded to requests for comment beyond its Wednesday acknowledgment.
Reuters reports some of the data includes information on agents involved in investigations relating to Russia, China and drug cartels; 404 Media suggests details of a previously little-known FBI hacking unit may also have been exposed.
Professor Ciaran Martin, former head of the UK’s National Cyber Security Centre, described the hack — if confirmed — “as serious as it gets when it comes to data breaches”. Jamie Akhtar, chief executive and co-founder of CyberSmart, said the claims should be treated with caution but that “Such data could be used for highly convincing phishing, impersonation, identity fraud, blackmail or even operations targeting law-enforcement personnel, making the potential implications particularly serious”.
Sources
- BBC (verbatim mirror): https://owspakistan.com/cw62me2vlj07oat_mediumrssat_campaignrss/
- Bloomberg via NDTV Profit: https://www.ndtvprofit.com/world/fbi-agent-homes-job-titles-in-data-hackers-claim-to-have-stolen-12095248
- AP via Barchart: https://www.barchart.com/story/news/4758192/fbi-investigates-apparent-breach-of-its-jobs-website-hackers-claim-to-have-sensitive-employee-data
- Tribune/Reuters: https://tribune.com.pk/story/2631214/hacked-fbi-data-has-sensitive-information-about-employees-intelligence-roles
More on this topic: all Technology stories