Source : INDIA TODAY NEWS
Sensitive medical and psychiatric records of FBI personnel were reportedly among data stolen in a recent cyberattack claimed by the ShinyHunters hacking group, raising concerns over a potentially serious counterintelligence threat.
The hackers first claimed on Tuesday that they had breached the FBI’s FBIjobs.gov website and stolen what they said was between 2 and 3 terabytes of data. Reuters had earlier reported that the stolen information included granular details about FBI employees, their assignments and sensitive operations involving Chinese spies, Russian intelligence and drug cartels.
advertisement
The latest disclosure indicates that the stolen material may also include highly sensitive medical information. Documents reviewed by Reuters included records from fitness-for-duty examinations, mental health evaluations, blood and urine tests and an electrocardiogram.
One medical record reviewed by Reuters said an applicant took aspirin daily and was allergic to dust and cats. Another stated that a prospective employee had exhibited symptoms of depression while in high school.
COUNTER-INTELLIGENCE CONCERNS
Eric O’Neill, a former FBI operative who now heads cybersecurity consultancy Nexasure AI, said the presence of medical information could significantly increase the intelligence value of the stolen data.
O’Neill compared the potential scale of the breach to the 2015 intrusion into the US Office of Personnel Management, which exposed sensitive information belonging to millions of Americans, including security-clearance data.
He said medical records could be particularly valuable to foreign intelligence services seeking information that could potentially be used to target or pressure intelligence personnel.
The FBI has not commented specifically on the medical records. In a statement on Wednesday, the bureau said it was “aggressively investigating” the reported breach.
REUTERS PARTIALLY AUTHENTICATES FILES
Reuters said it was able to partially authenticate several of the files through multiple checks. These included matching two Social Security numbers in the documents against credit-bureau data and comparing the date of a pre-employment mental health evaluation with the LinkedIn profile of a former FBI analyst.
Reuters also matched the name of an FBI psychiatrist listed in one document with a LinkedIn profile carrying the same name and job title.
A person familiar with the matter separately confirmed that a medical professional named in one of the documents had performed FBI evaluations at the time in question, though the person could not authenticate the entire file.
Reuters said it could not determine whether the small sample of documents it reviewed was representative of the wider trove allegedly obtained by ShinyHunters.
HACKERS’ CLAIMS NOT FULLY VERIFIED
ShinyHunters claimed it had accessed several internal FBI services, including systems used for employee and applicant background screening, FBI MedLink, which reportedly contains personnel medical records, and the Background Investigation Contract Services unit.
Reuters could not independently corroborate those specific claims.
The FBI had warned in a May advisory that ShinyHunters had previously exaggerated the extent of its access in attempts to pressure or extort victims.
The group nevertheless told Reuters that its stolen material included medical information, prescriptions, clinical visits, discharges and health issues involving FBI agents.
ShinyHunters initially threatened to withhold the data unless the FBI withdrew its May advisory. It later removed that demand from its website and said it would not comment on what action it might take if the bureau did not comply with its request.
– Ends
SOURCE :- TIMES OF INDIA




