The FBI is currently investigating a significant cyberattack involving the theft of highly sensitive medical and personal data belonging to thousands of its personnel. The breach, which was acknowledged by the bureau on Wednesday, potentially compromises the private records of both current and former staff members. Including senior officials such as deputy directors, the records appear to relate to thousands of agents.
Samples of the stolen information, reviewed by journalists, include “fitness-for-work” medical evaluations. These documents contain detailed blood and urine test results, as well as physician notes regarding specific health conditions, such as severe food allergies, high cholesterol, and internal medical concerns. Beyond health data, the exposed files reportedly feature full names, residential addresses, phone numbers, badge numbers, job titles, and details concerning employees’ spouses. Along with an extortion demand, the group also shared samples of the alleged stolen data with reporters.
The criminal collective known as ShinyHunters has claimed responsibility for the breach. The group alleges it gained access to several FBI platforms—including FBIJobs, the FBI BEAST background check system, FBI MedLink, and the FBI BICS investigative portal—by exploiting a vulnerability within an Oracle cloud storage system. While the FBI initially examined whether 38,000 employees were affected, the hackers now assert that the compromised dataset contains information on approximately 60,000 individuals.
Etay Maor, vice-president of threat intelligence at Cato Networks, described the leak as particularly dangerous due to the nature of the data. Unlike stolen passwords, which can be changed, permanent medical history cannot be secured once it has been disseminated. The breach has also been linked to reports from Reuters and 404 Media, suggesting that information related to investigations involving drug cartels, China, and Russia, as well as details about a clandestine hacking unit, may have been exposed.
Unusually, the perpetrators are not seeking financial compensation. Instead, they are demanding the retraction of an FBI advisory published in May that they claim caused them offense. The hackers have threatened to publish the entire cache of stolen data within five days if their demands are not met. Applied across an entire workforce, is what makes this leak so serious, that permanence. The FBI has not responded to requests for comment.
Experts have expressed grave concern regarding the potential real-world impact of the incident. Jamie Akhtar, CEO and co-founder of CyberSmart, warned that the data could be weaponized for identity fraud, sophisticated phishing campaigns, impersonation, or direct blackmail against law enforcement personnel. Ciaran Martin, the former head of the UK’s National Cyber Security Centre, characterized the incident as being as serious as a data breach can possibly get. Blackmail and targeted attacks, as well as help criminals impersonate law enforcement officers, experts say the hack – which the FBI is investigating – could leave agents vulnerable to scams. According to jamie Akhtar, chief executive and co-founder of CyberSmart,, The hackers’ claims should be treated with caution but that the breach appeared to be extremely concerning.
In an official statement released via X, the FBI confirmed it is working with third-party providers involved in supporting the FBIJobs.gov portal. The bureau is conducting an aggressive investigation to determine whether its internal systems were directly accessed or if the breach occurred through a secondary provider. The FBI has yet to provide further updates on the status of the investigation. We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk,” the statement said.
ShinyHunters, an international hacking group active since 2019, has previously been associated with high-profile cyberattacks on entities such as Rockstar Games and the educational platform Canvas.
















