Drooid Logo
Back to story perspectives

Full Breakdown

FBI Medical Records Breach Exposes Thousands of Agents

By Drooid · · How we work

The breach and its scope

Cyber-criminal group ShinyHunters announced that it infiltrated FBI systems in early 2024, claiming to have extracted “fitness-for-work” medical examinations for roughly 60,000 current and former staff. The stolen files contain agents’ full names, addresses, badge numbers, job titles, spouses’ details, and doctors’ notes on conditions such as a “shellfish and banana allergy,” blood in the urine, and high cholesterol. Samples provided to journalists show records for senior officials, including deputy directors.

How the intrusion occurred

ShinyHunters says it exploited a vulnerability in an Oracle cloud storage platform used by the FBI. The breach allegedly gave the group access to multiple internal services: FBIJobs, the background-check system FBI BEAST, the medical-records repository FBI MedLink, and the investigative database FBI BICS. The hackers posted details of the attack on a darknet site and communicated via Telegram, warning they will release the full dataset in five days unless the FBI retracts a May advisory the group says offended them.

Potential impact

Experts warn that medical records cannot be changed like passwords, meaning the information may remain compromised indefinitely. The exposure could facilitate targeted scams, blackmail, and impersonation of law-enforcement officers, especially given that some of the data reportedly includes agents involved in investigations of Russia, China, and drug cartels.

Verbatim quotes

  • “The list maps thousands of agents against their medical and fitness records,” — Etay Maor, vice-president of threat intelligence at Cato Networks — Etay Maor, vice-president of threat intelligence at Cato Networks.