ShinyHunters黑客称其窃取了FBI工作人员的精神科和医疗记录


2026-09-25T20:32:42.909Z / https://www.reuters.com/world/shinyhunters-hackers-say-they-stole-psychiatric-medical-records-fbi-staff-2026-09-25/

华盛顿9月25日路透电——据黑客团队及路透社审核的文件显示,近期被ShinyHunters黑客组织窃取的FBI人员数据包含敏感的精神科和医疗评估记录。

ShinyHunters是全球最臭名昭著、最爱博眼球的黑客团伙之一,该组织于本周二首次宣称已入侵FBI。路透社此前曾报道,此次入侵中该团伙获取了该局员工及其任务的详细细节,包括针对中国间谍、俄罗斯情报机构、贩毒集团等目标的敏感行动信息。

《错误信息监控》简报汇总国际错误信息叙事,每期都设有“真实还是虚假?”问答环节。点击此处订阅

此次入侵已令FBI陷入混乱,而如今更可能演变为严重的反情报风险,曾任职FBI探员、现任网络安全咨询公司Nexasure AI创始人埃里克·奥尼尔表示。

奥尼尔称,医疗数据的存在表明此次入侵规模可与2015年美国人事管理办公室遭入侵事件相提并论,当时数百万美国人的敏感安全许可信息被泄露,据称是被中国情报机构获取。

他补充道,这些数据将成为敌对间谍的强力目标。

“如果俄罗斯情报机构不找上门来索要这些资料,那我才会感到震惊,”奥尼尔说道。

FBI拒绝就这些记录置评。该局在周三发布的一份声明中表示,正“积极调查”此次被报道的入侵事件。

ShinyHunters在宣布入侵FBIjobs.gov网站并窃取了其声称的2至3太字节数据后,于本周早些时候将医疗文件分发给了一小部分记者。

BBC周五早些时候报道称,一份血液和尿液检测文件(打开新标签页)是样本之一,但包括心理健康评估和其他记录在内的其他敏感文件的存在此前并未被报道。

路透社通过多种方式部分核实了这六份左右文件中的部分内容,包括将文件中的两个社保号码与征信机构数据进行比对,以及将入职前心理健康评估的日期与一名前FBI分析师的领英档案进行匹配。路透社还将文件中一名FBI精神科医生的姓名与领英上同名且职位完全一致的档案进行了比对。

在一个案例中,路透社得以向一名知情人士确认,文件中列出的一名为FBI进行评估的医疗专业人员确实在当时从事相关工作,不过该人士无法核实整个文件的真实性。

该人士因未获授权讨论此事而要求匿名。

文件中提及的精神科医生和FBI员工要么未回复消息,要么拒绝置评。

文件包含医疗细节

路透社审核的文件敏感程度不一。其中一份医疗记录是针对潜在雇员的“任职资格体检”的一部分,记录显示一名申请人每日服用阿司匹林,且对灰尘和猫毛过敏。

另一份记录称,一名潜在雇员在高中时期曾表现出“抑郁症状”。第三份文件则包含心电图结果。

路透社无法确认所查看的少量文件是否能代表ShinyHunters所持有的全部数据,也无法确认是否存在其他文件。

FBI今年5月发布的一份公告称,该团伙过去曾夸大其入侵程度,以此向受害者勒索钱财。

ShinyHunters周二告诉路透社,其获取的数据“极其极其极其敏感”,包含医疗信息、出院记录、处方、临床就诊记录以及“探员的所有健康问题”。

黑客团伙称,他们已入侵该局的多个内部服务系统,包括FBI背景调查和员工求职者筛选系统、包含该局人员医疗记录的FBI医疗链接系统,以及FBI背景调查合同服务部门。路透社无法证实这些具体指控。

最初,该团伙表示会将数据作为人质,直到FBI撤回其5月发布的公告,并称他们对此表示反对。自那以后,ShinyHunters已从其网站上删除了这一挑衅性声明,并于周四表示,不会就“如果受害者不配合我们的善意要求”将采取何种行动置评。

本文在第10至15段补充了背景信息和更多细节并更新。

路透社华盛顿分社拉斐尔·萨特、底特律分社AJ·维伦斯报道;克里斯·桑德斯和大卫·加芬编辑

我们的报道准则:汤姆森路透社信任原则。

ShinyHunters hackers say they stole psychiatric and medical records of FBI staff

2026-09-25T20:32:42.909Z / https://www.reuters.com/world/shinyhunters-hackers-say-they-stole-psychiatric-medical-records-fbi-staff-2026-09-25/

WASHINGTON, Sept 25 (Reuters) – FBI personnel data recently stolen by the ShinyHunters hackers includes sensitive psychiatric and medical ​evaluation records, according to the hackers and documents reviewed by Reuters.

ShinyHunters, one of the world’s most notorious and attention-seeking hacking crews, first said ‌it had breached the FBI on Tuesday. In the hack, the group obtained granular details about bureau employees and their assignments, Reuters previously reported, including sensitive work against Chinese spies, Russian intelligence, drug cartels and others.

The Misinformation Monitor newsletter rounds up international misinformation narratives, with a “Real or Fake?” quiz in every edition. Sign up here.

The breach has already rattled the bureau, but now threatens to turn into a serious counterintelligence risk, said Eric O’Neill, a former FBI operative who founded the cybersecurity consultancy Nexasure AI.

O’Neill said the presence of ​medical data was a sign that the hack was approaching the same kind of magnitude as the 2015 intrusion into the Office of Personnel Management, which ​exposed millions of Americans’ sensitive clearance information, allegedly to Chinese intelligence.

He added that the data would be a powerful magnet for ⁠hostile spies.

“I would be shocked if Russian intelligence isn’t knocking on their door and saying, ‘We want that stuff, hand it over,’” said O’Neill.

The FBI declined to comment on the ​records. In a statement issued Wednesday, the bureau said it was “aggressively investigating” the reported breach.

ShinyHunters circulated the medical files to a small circle of reporters earlier this week after announcing ​it had broken into the FBIjobs.gov site and stolen what it claimed was 2 to 3 terabytes of data.

The BBC earlier on Friday reported that

a blood and urine test document, opens new tab
was among the sample, but the presence of other sensitive files, including a mental health evaluation and other records, has not previously been reported.

Reuters was able to partially authenticate some of the half-dozen files in several ways, ​including running two social security numbers in them against credit bureau data, and lining up the date of a pre-employment mental health evaluation against a former FBI analyst’s ​LinkedIn profile. Reuters also matched the name of an FBI psychiatrist in the document to a LinkedIn profile with the same name and an identical job title.

In one case, Reuters was able ‌to confirm with ⁠a person familiar with the matter that a medical professional listed in one of the documents as performing FBI evaluations was in fact doing so at the time, although the person could not authenticate the entire file.

The person spoke on condition of anonymity because they weren’t authorized to discuss the matter.

The psychiatrist and the FBI employees named in the data either did not return messages or declined comment.

DOCUMENTS INCLUDE MEDICAL SPECIFICS

The documents reviewed by Reuters range in sensitivity. One medical record, which was part of a “fitness for duty” ​exam given to prospective employees, noted that ​an applicant took aspirin daily and was ⁠allergic to dust and cats.

Another record said a potential employee exhibited “symptoms of depression” in high school. A third document carried an electrocardiogram result.

Reuters could not establish whether the limited number of documents viewed were representative of the rest of the data trove held ​by ShinyHunters, or whether there even were other documents.

An FBI advisory released in May said the group has in the past ​exaggerated its level of ⁠access in an attempt to extort its victims.

ShinyHunters told Reuters on Tuesday the data it had was “very very very sensitive” and included medical information, discharges, prescriptions, clinical visits, and “any health issues with Agents.”

The hackers said they had compromised several of the bureau’s internal services, including the FBI’s background and employee applicant screening system, FBI MedLink, which contains agency personnel medical records, and ⁠the FBI’s ​Background Investigation Contract Services unit. Reuters could not corroborate those specific allegations.

Initially, the group said it would ​hold the data hostage until the FBI retracted its May advisory, which it said it took exception to. Since then ShinyHunters has removed that defiant statement from its website, saying Thursday it would not comment on ​what it would do “if the victim does not comply with our kind request.”

Story updated with context and additional detail in paragraphs 10 through 15

Reporting by Raphael Satter in Washington and AJ Vicens in Detroit; editing by Chris Sanders and David Gaffen

Our Standards: The Thomson Reuters Trust Principles.

评论

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

湘ICP备2026001899号-2