Medical records belonging to FBI personnel — including blood test results, doctors' notes, and details as granular as a shellfish and banana allergy — have been shown to reporters by hackers who claim to hold records on thousands of FBI staff. The attackers are operating on a classic extortion playbook: steal sensitive data, prove authenticity by leaking samples to journalists, and apply pressure for payment.
The details matter less than the pattern. This is not a nation-state espionage operation targeting classified material — it is the weaponization of deeply personal health information against a law enforcement workforce. If threat actors hold medical records on FBI employees, every organization that stores employee health data, occupational health records, or benefits information should treat this as a warning shot. The same attack path — likely a compromised third-party medical provider, occupational health vendor, or benefits administrator — exists in your environment too.
No CVE has been disclosed in connection with this breach. The offensive mechanics are almost certainly mundane: stolen credentials, an exposed cloud storage bucket, a vulnerable SaaS portal, or an under-monitored vendor with flat access to a trove of PHI. That is precisely the point — the highest-impact breaches in 2025 and 2026 continue to exploit identity and third-party trust gaps, not exotic zero-days.
Technical Analysis: How Attacks Like This Typically Unfold
The most probable attack chain
Based on the extortion methodology described, the intrusion likely followed one of these well-documented paths (mapped to MITRE ATT&CK):
- Initial Access (T1078 – Valid Accounts, T1190 – Exploit Public-Facing Application, or T1195 – Supply Chain Compromise): The actor gains access to a third-party occupational health provider, medical testing lab, or benefits platform holding FBI employee records. Government-adjacent healthcare vendors are persistently under-resourced relative to the sensitivity of the data they hold.
- Discovery & Collection (T1083, T1213, T1530): The actor identifies PHI repositories — EHR databases, file shares of scanned documents, or cloud object storage containing lab results and physician notes.
- Staging & Exfiltration (T1560 – Archive Collected Data, T1567 – Exfiltration to Cloud Storage): Records are bulk-compressed and exfiltrated to attacker-controlled cloud storage or VPS infrastructure.
- Impact & Extortion (T1657 – Financial Theft): The actor leaks samples to journalists to establish credibility and pressure the victim organization or government into payment.
Why PHI is the target
Medical data commands premium value on criminal markets and, critically for extortion, carries reputational and personal safety weight that ordinary PII does not. For law enforcement personnel, exposed health records — including psychological evaluations, fitness-for-duty documentation, and substance-related medical history — create coercion and targeting risks against individual agents. Defenders should understand: the actor's leverage is not the data itself but the consequence of disclosure.
Exploitation status
- Confirmed active leak: Sample records have been shown to journalists and verified as authentic-appearing.
- Scope unconfirmed: The claim of "thousands of FBI staff" records is the actor's assertion; treat unverified attacker claims cautiously but plan for the worst case.
- No CVE, no CISA KEV entry: There is no single patchable vulnerability here. This is an identity, access, and third-party governance failure — which makes it harder to remediate and easier to repeat.
Detection & Response
Because the intrusion vector is unconfirmed, detection content below targets the universal observable behaviors of mass PHI theft: bulk access to sensitive repositories, archive staging, and cloud exfiltration. These are the choke points every data-theft operation must pass through regardless of initial access method.
Sigma Rules
---
title: Mass Archive Creation in Sensitive Data Directories
id: 4f1a2b3c-8d7e-4f5a-9b6c-2d1e3f4a5b6c
status: experimental
description: Detects archive utilities compressing directories consistent with PHI/PII repositories, a common staging behavior before data exfiltration and extortion.
references:
- https://attack.mitre.org/techniques/T1560/001/
- https://www.malwarebytes.com/blog/data-breaches/2026/09/fbi-agents-blood-tests-and-doctors-notes-surface-after-breach
author: Security Arsenal
date: 2026/09/26
tags:
- attack.collection
- attack.t1560.001
logsource:
category: process_creation
product: windows
detection:
selection_tool:
Image|endswith:
- '\7z.exe'
- '\7za.exe'
- '\rar.exe'
- '\winrar.exe'
- '\tar.exe'
- '\bsdtar.exe'
selection_sensitive_path:
CommandLine|contains:
- 'medical'
- 'health'
- 'patient'
- 'records'
- 'HR'
- 'benefits'
- 'claims'
condition: selection_tool and selection_sensitive_path
falsepositives:
- Scheduled backup jobs compressing document management systems
- IT administrators archiving HR shares during migrations
level: high
---
title: Unsanctioned Cloud Exfiltration Tool Execution
id: 8c2d3e4f-5a6b-7c8d-9e0f-1a2b3c4d5e6f
status: experimental
description: Detects execution of rclone, MEGAcmd, or similar dual-use sync tools frequently abused for bulk data exfiltration in theft-and-extortion campaigns.
references:
- https://attack.mitre.org/techniques/T1567/002/
- https://www.malwarebytes.com/blog/data-breaches/2026/09/fbi-agents-blood-tests-and-doctors-notes-surface-after-breach
author: Security Arsenal
date: 2026/09/26
tags:
- attack.exfiltration
- attack.t1567.002
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\rclone.exe'
- '\megacmd.exe'
- '\MEGAsync.exe'
- '\pscp.exe'
- '\winscp.exe'
selection_args:
CommandLine|contains:
- 'copy'
- 'sync'
- 'move'
- '--transfers'
- '--bwlimit'
condition: selection_img and selection_args
falsepositives:
- Approved backup replication using rclone (allowlist by service account and destination)
level: high
---
title: Mass File Access on Shared Drives by Single User
id: 1b2c3d4e-6f7a-8b9c-0d1e-2f3a4b5c6d7e
status: experimental
description: Detects a single account accessing an anomalous volume of distinct files, consistent with bulk harvesting of document repositories prior to exfiltration. Requires file access auditing (SACL) on sensitive shares.
references:
- https://attack.mitre.org/techniques/T1530/
- https://attack.mitre.org/techniques/T1213/
author: Security Arsenal
date: 2026/09/26
tags:
- attack.collection
- attack.t1530
logsource:
category: file_access
product: windows
detection:
selection:
ObjectType: 'File'
AccessList|contains:
- 'ReadData'
filter_known_backup_accounts:
SubjectUserName|endswith:
- '$'
condition: selection and not 1 of filter_*
falsepositives:
- Backup service accounts, DLP scanners, search indexers — baseline and exclude
level: medium
KQL Hunt — Microsoft Sentinel / Defender
This query hunts for the staging-and-exfil sequence: archive tool execution followed by high-volume outbound network activity from the same device. Run it against endpoints and servers hosting HR, benefits, or medical document stores.
// Hunt: archive staging followed by anomalous outbound transfer from same host
let archive_tools = dynamic(["7z.exe", "7za.exe", "rar.exe", "winrar.exe", "tar.exe", "bsdtar.exe"]);
let lookback = 7d;
let staging = DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where FileName in~ (archive_tools)
| where ProcessCommandLine has_any ("medical", "health", "patient", "records", "HR", "benefits", "a -t", " -mx9")
| summarize StagingCount=count(), FirstStaging=min(TimeGenerated) by DeviceName, AccountName;
DeviceNetworkEvents
| where TimeGenerated > ago(lookback)
| where RemoteIPType == "Public"
| summarize TotalOutboundEvents=count(), Destinations=dcount(RemoteIP), Ports=make_set(RemotePort) by DeviceName
| join kind=inner staging on DeviceName
| where Destinations < 5 // concentrated transfer to few external destinations
| project DeviceName, AccountName, StagingCount, FirstStaging, Destinations, Ports
| order by StagingCount desc;
// Companion hunt: unsanctioned exfil tools anywhere in the estate
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where FileName in~ ("rclone.exe", "megacmd.exe", "MEGAsync.exe", "winscp.exe", "pscp.exe")
| summarize Executions=count(), Devices=dcount(DeviceName), Cmdlines=make_set(ProcessCommandLine, 5)
by FileName, AccountName
| order by Executions desc;
Velociraptor VQL Hunt
For DFIR triage, this artifact identifies recently created large archives and active process execution of exfil-capable tooling across a fleet — the physical residue of theft-and-extortion staging.
-- Identify recently created large archives and live exfil tooling on endpoints
LET archives = SELECT FullPath, Size, Mtime
FROM glob(globs=['C:\Users\*\*.zip', 'C:\Users\*\*.7z', 'C:\Users\*\*.rar',
'C:\ProgramData\*.zip', 'C:\ProgramData\*.7z',
'C:\Windows\Temp\*.zip', 'C:\Windows\Temp\*.7z'])
WHERE Size > 50000000 -- >50 MB
AND Mtime > now() - (7 * 24 * 60 * 60)
SELECT * FROM archives
LET exfil_procs = SELECT Pid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Exe =~ '(rclone|megacmd|MEGAsync|winscp|pscp|7z|7za|rar)\.exe$'
SELECT * FROM exfil_procs
Remediation and Hardening
There is no patch to apply here. Remediation is architectural and procedural:
- Inventory your PHI/PII blast radius now. Enumerate every system and vendor holding employee medical, occupational health, psychological, or benefits data — including third-party labs, EAP providers, and insurance administrators. You cannot protect what you have not mapped.
- Contract and audit your third parties. Require HIPAA-grade safeguards, encryption at rest, MFA on all portals, and breach-notification SLAs from every vendor handling health data. Review their SOC 2 / HITRUST attestations this quarter, not at renewal.
- Constrain egress. Block outbound transfers to unsanctioned cloud storage (rclone destinations, Mega, personal Dropbox) at the proxy and firewall. Default-deny new SaaS destinations; allowlist by business justification.
- Deploy DLP on sensitive repositories. Tag and monitor documents containing health data; alert on bulk reads, bulk downloads, and copies to removable media.
- Enable file access auditing on HR/medical shares. Without SACLs, the third Sigma rule above and your IR team are both blind. Turn on object access auditing before you need it.
- Minimize and expire data. Medical records should not live indefinitely on file shares. Enforce retention schedules and purge what you no longer need — every record deleted is one that cannot be extorted.
- Prepare an extortion playbook. Pre-decide your posture on payment (FBI guidance: do not pay), notification obligations under HIPAA and state breach laws, employee support for affected staff, and law enforcement engagement. Organizations that improvise under extortion make worse decisions.
- Monitor for workforce targeting. Leaked health data on law enforcement or cleared personnel creates blackmail and spear-phishing risk against individuals. Brief affected staff and watch for targeted social engineering referencing medical details.
The lesson from this breach is not about the FBI's network — it is about the fragility of the vendor chain that surrounds every employer's health data. Assume your third parties are the soft underbelly, instrument the staging-and-exfiltration choke points, and rehearse your extortion response before a journalist calls your comms team.
Related Resources
Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.