Cyber-criminals who hacked the FBI say they’ve extraordinarily delicate medical knowledge for hundreds of its particular brokers.
BBC Information has seen samples of the stolen “fitness-for-work” medical examinations, which include data reminiscent of blood and urine check outcomes, and medical doctors’ notes mentioning situations reminiscent of a “shellfish and banana allergy”.
The data embody brokers’ full names and addresses, in addition to references to medical considerations together with ‘blood within the urine’ and ‘excessive ldl cholesterol’.
Specialists say the hack – which the FBI is investigating – may go away brokers weak to scams, blackmail and focused assaults, in addition to assist criminals impersonate legislation enforcement officers.
“The listing maps hundreds of brokers towards their medical and health data,” mentioned Etay Maor, vice-president of risk intelligence at Cato Networks.
“Passwords may be reset if stolen, however medical data can not, so as soon as this knowledge is out, it stays compromised for good. That permanence, utilized throughout a complete workforce, is what makes this leak so severe.”
The FBI has not responded to requests for remark. Nonetheless, on Wednesday it acknowledged the breach and mentioned it was “aggressively investigating” the way it occurred.
The cyber-criminal group ShinyHunters claims it breached FBI techniques on Monday, and later posted particulars of the assault on its darknet web site.
The group additionally shared samples of the alleged stolen knowledge with reporters, together with an extortion demand.
Unusually, the hackers aren’t demanding cash. As an alternative, they’re in search of a retraction of an FBI advisory revealed in Might, which they declare “offended” them.
The samples shared with journalists seem real and embody names, addresses, cellphone numbers, badge numbers, job titles and details about spouses.
The data seem to narrate to hundreds of brokers, together with senior officers reminiscent of deputy administrators.
Professor Ciaran Martin, the previous head of the UK’s Nationwide Cyber Safety Centre, has described the hack – if confirmed – “as severe because it will get in relation to knowledge breaches.”
