Feed aggregator
FBI agents’ blood tests and doctors’ notes surface after breach
BBC News reports it has seen samples of stolen FBI agents’ medical examinations. The “fitness-for-work” reports identify FBI agents by name and address, and reveal even more personal details. They include blood and urine test results and doctors’ notes mentioning high cholesterol, blood in the urine, and even a shellfish and banana allergy.
As we reported last week, extortion group ShinyHunters claims to have breached the FBI. After reportedly taking over ransomware group Clop’s leak site, ShinyHunters says it attacked the FBI to punish the agency for spreading what it calls false information about the group.
The BBC’s findings raise the stakes: The alleged theft includes highly sensitive medical records, not just staff identity and contact data. ShinyHunters shared samples with journalists as proof of its claims.
The BBC states:
“The samples shared with journalists appear genuine and include names, addresses, phone numbers, badge numbers, job titles and information about spouses.”
ShinyHunters claims it accessed several systems, including FBI MedLink, which stores medical records, and FBI BEAST, which handles background checks on employees and applicants, but the FBI has not confirmed these claims. The FBI has acknowledged an incident affecting FBIJobs-related systems and says it is investigating whether its own environment or a third-party provider was compromised.
The group’s stated demand remains non-financial: It wants the FBI to retract or remove a May advisory that ShinyHunters calls false and defamatory. It says it will release the data within five days if its demands are not met.
The cybercriminals also raised the number of affected people. ShinyHunters nows claims to hold sensitive information on around 60,000 current and former FBI staff. Medical histories could make affected people vulnerable long after the immediate incident: Unlike a stolen password, a medical record cannot be changed.
What to do if you’re affectedThe FBI has not yet confirmed what information was accessed or who was affected. If you are a current or former FBI employee, a relative of one, or have applied for an FBI job:
- Check the FBI’s advice. Every breach is different, so check FBI.gov for updates and follow any specific advice it offers.
- Change your password. If you have an FBI Jobs account and reuse its password elsewhere, change it on those other accounts. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
- Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password, but 2FA that relies on a FIDO2 device can’t be phished.
- Watch out for impersonators. Cybercriminals may contact you posing as the FBI, another government agency, or someone you know. Verify the identity of anyone who contacts you.
- Take your time. Phishing attacks often impersonate people or brands you know and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
- Set up identity monitoring. This can alert you if your personal information is found being traded illegally online and help you recover afterward.
Let’s face it, an incognito window can only do so much.
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.
Three Days in August: What a DDoS Attack Exposed in Our Network
Article URL: https://nine.ch/en/blog/ddos-attack-august-2026-postmortem/
Comments URL: https://news.ycombinator.com/item?id=49875401
Points: 1
# Comments: 0
Large Scale Threat Actor Attribution from Infostealer Logs
Article URL: https://blog.glazer.ee/posts/large-scale-threat-actor-attribution-from-infostealer-logs/
Comments URL: https://news.ycombinator.com/item?id=49875388
Points: 2
# Comments: 0
Google: AI-Assisted Rewrites of C/C++ Dependencies to Rust
Article URL: https://bughunters.google.com/blog/scaling-memory-safety
Comments URL: https://news.ycombinator.com/item?id=49875362
Points: 2
# Comments: 0
Personal Continuity Plans (Digital Legacy)
Article URL: https://ripe92.ripe.net/programme/meeting-plan/sessions/103/7PEF7V/#robert-kisteleki
Comments URL: https://news.ycombinator.com/item?id=49875357
Points: 1
# Comments: 0
Big AI's content problem: Take the work, keep the money
Article URL: https://www.theregister.com/columnists/2026/09/27/big-ais-content-problem-take-the-work-keep-the-money/5299007
Comments URL: https://news.ycombinator.com/item?id=49875347
Points: 1
# Comments: 0
LLMs in Professional Software Engineering
Article URL: https://knorpelsenf.me/posts/semantic-translation
Comments URL: https://news.ycombinator.com/item?id=49875344
Points: 2
# Comments: 0
Can Life Be Explained by Physics? (Featuring Prof. Brian Cox) [video]
Article URL: https://www.youtube.com/watch?v=k-vm3ZWnMWk
Comments URL: https://news.ycombinator.com/item?id=49875334
Points: 1
# Comments: 0
ETH Computer Science enrolment saw a 15 percent decline
Article URL: https://ethz.ch/en/news-and-events/eth-news/news/2026/09/viel-interesse-am-eth-studium.html
Comments URL: https://news.ycombinator.com/item?id=49875331
Points: 2
# Comments: 0
Unified U.S. Site Blocking Bill Targets ISPs and DNS Resolvers but Spares VPNs
Article URL: https://torrentfreak.com/unified-u-s-site-blocking-bill-targets-isps-and-dns-resolvers-but-spares-vpns/
Comments URL: https://news.ycombinator.com/item?id=49875322
Points: 2
# Comments: 0
Show HN: Free alternative to graphics design giants
A webassembly web based app that help editing raster and vector on browser without any subscription or signups
Comments URL: https://news.ycombinator.com/item?id=49875308
Points: 2
# Comments: 0
Are Big Tech bonds crowding out the US Treasury?
Article URL: https://www.ft.com/content/6354c1ec-286a-4251-bac8-ca0cd4ac7eac
Comments URL: https://news.ycombinator.com/item?id=49875304
Points: 1
# Comments: 1
The Risks of Ignoring API Security During Mobile App Security Testing
Mobile applications rely heavily on APIs to connect users, backends, and third-party services. Yet API security is often overlooked during Mobile Application Security Testing. This can expose sensitive data, authentication mechanisms, and business logic to attackers. A comprehensive mobile security assessment must therefore test both the application and its APIs to identify vulnerabilities and strengthen the overall security posture. Read Full Blog Here https://kratikal.com/blog/hidden-risks-of-ignoring-api-security-during-mobile-application-security-testing/?utm_source=bsbm&utm_medium=news.ycombinator
Comments URL: https://news.ycombinator.com/item?id=49875297
Points: 1
# Comments: 0
How I Use "AI" (2024)
Article URL: https://nicholas.carlini.com/writing/2024/how-i-use-ai.html
Comments URL: https://news.ycombinator.com/item?id=49875295
Points: 1
# Comments: 0
Show HN: Redthread – autonomous LLM pentesting with proof-of-concept exploits
Article URL: https://millenniums.ai/docs
Comments URL: https://news.ycombinator.com/item?id=49875292
Points: 2
# Comments: 0
Pixi adds non-Python deps to Python notebooks
Article URL: https://marimo.io/blog/pixi-sandboxes
Comments URL: https://news.ycombinator.com/item?id=49875282
Points: 1
# Comments: 0
Show HN: Impressive hand detection AI algorithm
Article URL: https://github.com/aryafarkhondeh/cp_hand_demo
Comments URL: https://news.ycombinator.com/item?id=49875270
Points: 1
# Comments: 1
The Cybersecurity Siege Economy
Article URL: https://dntls.substack.com/p/the-cybersecurity-siege-economy-part
Comments URL: https://news.ycombinator.com/item?id=49875231
Points: 1
# Comments: 0
European industry is doing better than you may think
Article URL: https://www.economist.com/business/2026/09/27/european-industry-is-doing-better-than-you-may-think
Comments URL: https://news.ycombinator.com/item?id=49875215
Points: 2
# Comments: 0
