
Hackers say they grabbed FBI agents’ medical and psych records, including blood and urine test results, and reporters say the samples look real.
Story Snapshot
- Hackers claim data from the FBI’s jobs portal included sensitive medical files.
- BBC says it reviewed fitness-for-work exam samples with lab results and doctors’ notes.
- The FBI says it is investigating and has not confirmed the medical record theft.
- The breach vector and scope remain under investigation amid rising agent safety concerns.
What hackers say they took, and what reporters saw
ShinyHunters, a known cyber extortion group, says it stole data on thousands of FBI agents and job applicants. The group claims the files include psychiatric evaluations and medical records. Reuters reporters reviewed documents the hackers provided and described the records as containing sensitive details.
BBC reporters say they saw samples from “fitness-for-work” files with blood and urine test results and doctor notes about health conditions. If accurate, these details raise real risks of blackmail or harassment against agents.
The claims center on the FBI’s hiring portal. Reports tie the breach to FBIJobs.gov and possibly linked systems used for human resources and medical screening. The alleged trove would include names, contact data, and spousal information along with some medical data, according to press reports.
That mix is dangerous. It ties home addresses to potential health issues. That gives criminals a playbook for pressure, scams, or social engineering. It also puts agents’ families in the crosshairs.
What the FBI confirms, and what it does not
The Federal Bureau of Investigation says it is aware of a claim that its jobs portal was compromised. The bureau says it is investigating and working with third-party providers to find and fix the issue. The FBI has not confirmed that it stole medical records.
It also says the breach point is still unknown and may involve a third-party system rather than core FBI infrastructure. That measured stance is standard during an active probe, but it leaves a gap that others are eager to fill.
The lack of immediate confirmation does not clear the risk. In cyber cases, attackers often publish small samples to prove access and drive fear.
Reporters then assess those samples. Officials, meanwhile, work to validate scope, cut off access, and notify those affected. That timeline can take weeks.
During that time, the best judge is the quality of the samples and the outlets vetting them. Reuters and BBC say they saw sensitive content. That raises this above pure rumor.
EXCLUSIVE: ShinyHunters hackers say they stole psychiatric and medical records of FBI staff https://t.co/WSSfhtSPFy https://t.co/WSSfhtSPFy
— Reuters (@Reuters) September 25, 2026
Why medical data raises the stakes for agents and for national security
Medical details can reveal conditions, medications, and stress markers. For law enforcement, that information can be used to shame, distract, or coerce.
Add home addresses and family links, and the pressure multiplies. Foreign spies and gangs look for leverage. Health data offers it on a silver platter. This is not about embarrassment. It is about decision-making under duress and operational safety.
An alleged hack of FBI personnel files includes "extremely sensitive medical data for thousands of its special agents," and "blood and urine test results" are among the stolen records, according to a report from BBC News. https://t.co/4pX2kTPN8r
— ABC News (@ABC) September 27, 2026
The reported source systems tell a story, too. Hiring portals, background checks, and medical screening tools often sit with vendors. That can create seams. If a people system falls out of date, a single flaw can open doors across linked services.
Public reporting ties the breach to the jobs portal and mentions other services by name in attacker claims and coverage. If true, this points to third-party risk and the need for tight vendor controls and rapid patch paths. We have seen this movie before.
What should happen next to protect agents and fix the system
First, notify and protect potential victims. Offer rapid credit monitoring, home address shielding where allowed, and fast device checks for targeted agents.
Second, lock down all connected human resources and medical systems. Force password resets and rotate keys. Third, assume the samples are real until proven false and plan for doxxing waves.
Fourth, publish a clear timeline of what is known and when. Sunlight beats rumor mills. The FBI has started the right process; now it needs speed and steady updates.
Congress and the executive branch should treat this as a lesson about essential services. Law enforcement depends on secure hiring, vetting, and health care workflows. Those must meet higher standards than typical office apps.
That means strict vendor audits, zero-trust designs, and segmented data stores, so a jobs site cannot unlock medical histories. The price of delay is paid by the agent on a doorstep with kids behind them. The fix is not exotic. It is discipline, budgets, and accountability.
What to watch as the investigation unfolds
Watch for confirmed counts of affected files, not just headcount. Watch whether the medical records in samples match current employees. Watch for signs of extortion or targeted phishing against field offices.
If the bureau confirms medical data loss at scale, expect a long tail of harassment and influence attempts. If it does not, vetted samples still call for a hard reset of access and a frank public briefing. Either way, tighten the seams now.
Sources:
abcnews.com, reuters.com, bbc.com, nytimes.com














