ShinyHunters Hackers Steal Sensitive FBI Medical and Psychiatric Records
FBI personnel data recently stolen by the ShinyHunters hackers includes sensitive psychiatric and medical evaluation records, according to hackers and documents reviewed by Reuters. The intrusion into bureau systems has rattled the bureau and threatens to turn into a serious counterintelligence risk, according to a former FBI operative.
- Stolen files from the FBI breach include sensitive psychiatric evaluations, electrocardiogram results, and physical fitness records detailing individual health histories.
- The FBI stated it is aggressively investigating the reported breach after hackers claimed to have exfiltrated several terabytes of data from internal applicant screening systems.
Counterintelligence Risks Raised by Stolen Medical Data
The presence of granular medical and psychiatric records within the stolen data trove has elevated concerns about the breach’s long-term security implications. Eric O’Neill, a former FBI operative who founded the cybersecurity consultancy Nexasure AI, noted that the inclusion of health data suggests the incident approaches the magnitude of the 2015 Office of Personnel Management intrusion. O’Neill stated that the medical records would act as a powerful magnet for hostile foreign intelligence services.
“I would be shocked if Russian intelligence isn’t knocking on their door and saying, ‘We want that stuff, hand it over,'” O’Neill said regarding the value of the compromised information.

The breach follows ShinyHunters’ claim on Tuesday that they had compromised the FBIjobs.gov site and exfiltrated between two and three terabytes of data. The hacking crew asserted that the stolen trove contains very sensitive information, including medical disclosures, prescriptions, clinical visits, and health issues affecting bureau agents.
While the BBC reported earlier that a blood and urine test document was part of the sample, the broader existence of mental health evaluations and other records had not been previously documented. Reuters partially authenticated a half-dozen files by matching Social Security numbers against credit bureau data, verifying employment dates against professional profiles, and confirming the names of listed psychiatrists.
Granular Medical Details Exposed in the Breach
The documents reviewed by Reuters exhibit varying degrees of clinical sensitivity. One record from a prospective employee’s fitness-for-duty examination noted a daily aspirin regimen alongside common environmental allergies to dust and cats. Another file indicated that a potential employee experienced symptoms of depression during high school, while a third document contained an electrocardiogram result.
It remains undetermined whether the small sample of reviewed documents represents the broader contents of the data held by ShinyHunters. An advisory released by the bureau in May noted that the hacking group has previously exaggerated its level of access in attempts to extort victims.
The hackers alleged that they successfully compromised several internal services, including the background and employee applicant screening system known as FBI MedLink, which houses personnel medical records, as well as the Background Investigation Contract Services unit. The FBI has declined to comment on the specific records while maintaining that an aggressive investigation into the security event is underway.