INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
FBI agents' blood tests and doctors' notes compromised in breach
| 2026-09-28 09:28 CRITICAL MEDIUM DATA BREACH
Executive Summary
AI-generated
On 2026-09-28, cybercriminals claiming to be the FBI or someone known to the victim contacted individuals posing as government agencies or friends and family members. The attackers, ShinyHunters, allegedly breached the FBI's systems, including MedLink and BEAST, which store medical records and background checks, respectively. They claim to have accessed sensitive information on approximately 60,000 current and former FBI staff, including highly personal details such as blood test results and doctors' notes. The attackers are demanding that the FBI retract a May advisory they consider false and defamatory; if not met within five days, they will release the data.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
Global Scope
governmentgovernment
healthhealth
Incident Timeline
2026/09/21
ShinyHunters claimed to have breached the FBI, but no further details were provided in this snippet.
Click on any entity below to view its context and source!
attribution
FBI
As
we reported
last week, extortion group ShinyHunters claims to have breached the FBI.
tactic
Extortion
As
we reported
last week, extortion group ShinyHunters claims to have breached the FBI.
threat_actor
ShinyHunters
As
we reported
last week, extortion group ShinyHunters claims to have breached the FBI.
2026/09/28
ShinyHunters claims to have accessed several systems, including FBI MedLink and BEAST, storing medical records of around 60,000 current and former FBI staff.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
After
reportedly taking over ransomware group Clop’s leak site
, ShinyHunters says it attacked the FBI to punish the agency for spreading what it calls false information about the group.
The BBC states:
“The samples shared with journalists appear genuine and include names, addresses, phone numbers, badge numbers, job titles and information about spouses.”
ShinyHunters claims it accessed several systems, including FBI MedLink, which stores medical records, and FBI BEAST, which handles background checks on employees and applicants, but the FBI has not confirmed these claims.
The group’s stated demand remains non-financial: It wants the FBI to retract or remove a May advisory that ShinyHunters calls false and defamatory.
ShinyHunters nows claims to hold sensitive information on around 60,000 current and former FBI staff.
ShinyHunters shared samples with journalists as proof of its claims.
organisation
BBC
The BBC’s findings raise the stakes: The alleged theft includes highly sensitive medical records, not just staff identity and contact data.
organisation
FIDO2
If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor.
organisation
Identity Theft Protection
Malwarebytes Identity Theft Protection
monitors for all of it, alerts you fast, and comes with identity theft insurance.
Intelligence Sources
Malware Bytes
2026-09-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:49
Comprehensive Tactical Telemetry
Highly Correlated Entities
4x
tactic
Cyber Operation Type
Extortion
tactic
3x
attribution
Attributing Entity
FBI
authority
3x
organisation
Identified Entity
BBC
entity
Contextual Telemetry
Context Block
5 METRICS
industry
Targeted Sector
Government
sector
timeline
Temporal Reference
2026/09/21
date
threat actor
APT Group
ShinyHunters
actor
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
general metric
Current Former Fbi Staff
60,000
current former fbi staff
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.