FBI investigates breach allegedly exposing agents’ personal data

The FBI says it is investigating a cyber breach after hackers claimed to have stolen databases containing agents’ personal and medical information. Current and former staff told BBC News they fear harassment, scams, physical attacks and possible national-security risks.
The FBI is investigating a cyber breach that hackers claim exposed personal and sensitive information belonging to the agency’s workforce, according to the FBI and accounts reported by BBC News. The group ShinyHunters has threatened to publish stolen databases and documents within four days unless the FBI meets its demand to retract an advisory issued in May. The group has not demanded money, according to the report.
Samples shared with reporters appear to include names, addresses, phone numbers, badge numbers, job titles and details about spouses. BBC News also saw alleged “fitness-for-work” medical records containing test results and doctors’ notes. Current and former FBI employees said the information could be used for phishing attacks, scams, blackmail or harassment.
One former agent expressed particular concern for undercover personnel, while others feared criminals could target agents involved in investigations. Michael McPherson, a former FBI agent and security executive at ReliaQuest, described the reported exposure of home addresses and contact details as a threat to agents and their families. Cynthia Kaiser, formerly the FBI’s deputy director of cyber, said some data might already be circulating among online cyber-research groups.
The FBI acknowledged the breach on Wednesday, saying it was “aggressively investigating” how it occurred. The agency has not responded to requests for comment about the hackers’ claims. The incident has also raised concerns about possible recruitment efforts by hostile intelligence services.
Former agents quoted by the BBC expressed anger over what they described as inadequate security and said staff had been advised to use a service that helps remove personal information from data-broker websites. The report says ShinyHunters has previously been linked to other extortion attacks, including incidents involving Rockstar Games and Canvas.
This independently written report is based on information supplied by the named publisher. Vertrix News has not independently verified the source report.