WASHINGTON — A cyber intrusion reported on 25 September 2026 is alleged to have stolen blood and urine test results, as well as spouse information, belonging to U.S. Federal Bureau of Investigation special agents, according to multiple media outlets.
Alleged scope of the breach
BBC News cited an anonymous source claiming that the stolen data includes routine medical screenings required for agents’ fitness assessments. The report added that the breach also exposed personal identifiers such as names of spouses and next‑of‑kin details.
AlterNet echoed the claim, noting that the stolen files were posted on a dark‑web forum shortly after the intrusion was detected. The outlet said the forum listed the data as “FBI medical records” and offered it for sale to interested parties.
Operativ Məlumat Mərkəzi, an Azerbaijani investigative site, provided a timeline indicating that the hack was discovered on 23 September 2026, when the FBI’s internal security team flagged anomalous network activity. The site reported that the agency isolated the affected servers and launched a forensic review, but did not disclose the number of agents affected.
FBI response and investigation
The FBI has not issued a public statement confirming the breach. A spokesperson for the agency’s Office of the Chief Information Officer declined to comment when contacted by Reuters on 24 September, citing ongoing investigative procedures.
According to the FBI’s internal policies, medical records of personnel are stored in a secure, encrypted database separate from operational systems. The agency’s privacy guidelines require that any unauthorized disclosure be reported to the Department of Justice’s Office of the Inspector General, which is tasked with overseeing the investigation.
Potential impact and precedent
Data breaches involving personal health information have drawn heightened scrutiny in recent years, especially after the 2020 breach of the Department of Health and Human Services that exposed millions of patient records. While the FBI has previously reported cyber incidents targeting its email systems and network infrastructure, this is the first public allegation of a breach involving agents’ medical data.
Cybersecurity experts note that health‑related data is particularly valuable on underground markets because it can be used for identity theft, blackmail or targeted phishing attacks. The inclusion of spouse details could increase the risk of social engineering attempts against agents’ families.
Law enforcement and legal considerations
Under the Health Insurance Portability and Accountability Act (HIPAA), the unauthorized disclosure of protected health information can result in civil penalties of up to $50,000 per violation, with a maximum annual cap of $1.5 million. However, the FBI’s internal medical records are governed by separate federal personnel privacy statutes, which may invoke additional penalties under the Federal Information Security Modernization Act (FISMA).
The Department of Justice’s Computer Fraud and Abuse Act (CFAA) provides criminal penalties for unauthorized access to protected computers, with maximum sentences of up to 20 years imprisonment for aggravated offenses.
International dimension
Operativ Məlumat Mərkəzi suggested that the hackers may be linked to a known cyber‑crime group operating out of Eastern Europe, though no attribution has been confirmed by U.S. authorities. The group, identified in previous reports as “ShadowFox,” has previously targeted government and defense networks for financial gain.
U.S. cyber‑defense officials have warned allied nations that state‑sponsored actors continue to probe American intelligence infrastructure, emphasizing the need for coordinated security measures across the Five Eyes partnership.