
Hackers say they grabbed FBI agents’ medical and psychiatric records, and early samples back them up.
Story Snapshot
- Hackers called ShinyHunters claim they stole FBI personnel files, including medical exams.
- BBC says it reviewed agents’ blood and urine results and doctor notes from the breach.
- The FBI confirms it is investigating a claimed hit on its jobs portal but has not verified the medical leak.
- The mix of hacker leaks and official caution fits the usual early stage of big cyber cases.
Hackers claim trove includes agents’ most private health data
Reuters reported that the group known as ShinyHunters says it stole psychiatric and medical evaluation records tied to FBI personnel. The outlet said it reviewed documents that support that claim. BBC coverage goes further.
Reporters there say they saw “fitness-for-work” files with blood and urine test results and doctor notes for thousands of special agents. The hackers say the data came from systems linked to the FBI’s hiring portal, a tempting target that holds identity, background, and health screens.
EXCLUSIVE: ShinyHunters hackers say they stole psychiatric and medical records of FBI staff https://t.co/WSSfhtSPFy https://t.co/WSSfhtSPFy
— Reuters (@Reuters) September 25, 2026
The New York Times said the haul allegedly includes names, home addresses, phone numbers, spouse details, and some medical information for current and former officials and applicants.
Claims like these often arrive first from criminals, who share samples to gain leverage. Newsrooms then verify pieces of the cache.
The fuller picture usually follows weeks later as forensics teams dig through logs and vendors check their own systems. That lag does not mean nothing happened; it means real investigations take time.
FBI confirms probe but withholds judgment on medical files
The Federal Bureau of Investigation said it is aware of a cyber-criminal group claiming it hit the FBIJobs.gov portal and affected personally identifiable information. The bureau said the breach point is still unknown and could involve a third-party provider.
It added that agents are “actively and aggressively” investigating and working with those providers to reduce risk. Reuters noted the FBI declined to comment on the specific records while the probe continues.
That stance tracks with standard practice. When a breach may span multiple contractors and cloud services, public agencies avoid early technical claims that could mislead victims and help attackers adjust.
The basic play is simple: freeze access, pull logs, rotate credentials, and verify what moved and when. The FBI’s measured line keeps the focus on containment while evidence firms up. It can frustrate readers, but it protects cases and victims.
Why medical records raise the stakes for agents and cases
Medical files carry details that criminals use to pressure or profile targets. Blood tests, prescriptions, and mental health notes can fuel blackmail attempts or tailored social engineering. For agents who work undercover or handle informants, that risk multiplies. Doctor notes can hint at stress, travel, or limits that expose patterns.
Even basic lab metadata can confirm identity links across databases. If spies or cartels obtained such data, they could map weaknesses and family touchpoints at scale.
An alleged hack of FBI personnel files includes "extremely sensitive medical data for thousands of its special agents," and "blood and urine test results" are among the stolen records, according to a report from BBC News. https://t.co/4pX2kTPN8r
— ABC News (@ABC) September 27, 2026
This is not just a privacy mess; it is a counterintelligence problem. If criminals hold medical screens on thousands of armed federal officers, the threat touches jury trials, arrests, and informant safety. Criminals will exaggerate scope to drive clicks and ransom.
Still, when reputable outlets validate samples, leaders should assume compromise and move. That means fast notifications, credit and medical monitoring, and strict access reviews for all sensitive systems named in the claims.
What likely happened and what should happen next
Early reports point to a pathway that begins at the hiring systems and may fan out to related human resources and medical services. Attackers often enter through a web application flaw or a weak third-party integration, then move laterally.
If the jobs portal is hosted or linked to medical screens, the jump is clear. The fix is not a press release. The fix is patching known flaws, enforcing multi-factor logins for vendors, signing and encrypting every medical file, and shrinking who can ever open it.
Policy should follow the pain. Congress should mandate immediate breach reporting timelines for any federal system that touches health data, even through a contractor. Agencies should separate medical screening networks from everything else, with one-way data flow and hardware keys for access.
Every applicant deserves plain-language notice on what gets stored, where, for how long, and how to opt out of retention once cleared or rejected. Sunlight and strict limits beat wishful thinking every time.
Bottom line: assume exposure, act with urgency
The public record today shows credible samples of FBI medical screens in criminal hands and a live federal probe into a jobs-portal compromise. That pairing should end any debate about urgency.
The bureau must treat every named dataset as exposed until proven otherwise, and its contractors should too. Hackers brag. Institutions hedge. The truth sits in the logs. Until the final report lands, protect people first, then perfect the timeline.
Sources:
abcnews.com, reuters.com, bbc.com, nytimes.com

















