#FBI
What is the connection between the ShinyHunters FBI Hack 2026 (September 21 – 23) and demotion of agents Michael Burgwald and Courtland Rae (September 25)?There is no direct connection between the ShinyHunters cyberattack and the demotion of FBI agents Michael Burgwald and Courtland Rae; their timing in late September 2026 is coincidental. [1, 2, 3]
Both events represent entirely separate matters handled by different units within federal law enforcement:
The ShinyHunters CyberattackNature of the Incident: Cybercrime group ShinyHunters claimed to have breached systems associated with the FBI (specifically targeting the FBIjobs.gov portal via an Oracle PeopleSoft vulnerability), alleging theft of employee personally identifiable information and medical records. [1, 4, 5]
Motive & Handling: The group stated the attack was retaliatory—demanding the FBI retract an advisory issued in May—rather than financially motivated. The incident is being handled by the bureau’s cyber and counterintelligence divisions. [1, 4, 6, 7]The Reassignment of Michael Burgwald and Courtland Rae
Nature of the Action: Special Agent in Charge Michael Burgwald and his deputy Courtland Rae, who led the counterterrorism division at the FBI’s Washington Field Office, were reassigned to FBI headquarters on September 25, 2026. [8, 9]
Underlying Cause: According to reports from Bloomberg Law and CNN, the reassignments followed internal friction over the handling of alleged harassing calls made to Katie Miller, wife of White House deputy chief of staff Stephen Miller. Their team determined the calls did not meet the necessary threshold or have a nexus to terrorism, leading FBI leadership and field office management to make personnel changes over the pace and handling of that specific domestic threat probe. [3, 9, 10, 11]Neither the FBI, the Department of Justice, nor public reporting has linked the internal personnel decisions at the Washington Field Office to the external ShinyHunters breach. [1, 2, 3]
[1] reuters.com
[2] cbs12.com
[3] cnn.com
[4] theregister.com
[5] washingtonpost.com
[6] nytimes.com
[7] lawfaremedia.org
[8] independent.co.uk
[9] kpax.com
[10] news.bloomberglaw.com
[11] cbs12.com– Google Search google.com/search?q=What+is+…
— Michael Novakhov (@mikenov) Sep 28, 2026
What is the connection between the shinyHunters FBI Hack 2026 (September 21 – 23) and demotion of agents Michael Burgwald and Courtland Rae (September 25)? – Google Search google.com/search?q=What+is+…
— Michael Novakhov (@mikenov) Sep 28, 2026
Dates of shinyHunters FBI Hack 2026 – Google Search google.com/search?q=Dates+of…
— Michael Novakhov (@mikenov) Sep 28, 2026
When were FBI Agents Burgwald and Rae demoted and transferred? – Google Search google.com/search?q=When+wer…
— Michael Novakhov (@mikenov) Sep 28, 2026
A group of eight Marines was injured when an Iranian missile struck a ship they were operating on in the Strait of Hormuz, it has been revealed. thedailybeast.com/hushed-up-…
— @thedailybeast Sep 28, 2026
shinyHunters FBI Hack 2026 – Google Search google.com/search?q=shinyHun…
— Michael Novakhov (@mikenov) Sep 28, 2026
shinyHunters FBI Hack 2026 – Google Search google.com/search?q=shinyHun…
— Michael Novakhov (@mikenov) Sep 28, 2026
🇮🇱🇦🇪 BUSTED: Netanyahu reportedly snuck off to the UAE to beg for a cover-up after ignoring Oct 7 warnings…
According to reports, the PM directly asked President Sheikh Mohammed bin Zayed to issue a public denial that he warned Israel before the attack.
Cornered over his security failures, Netanyahu’s now pleading with foreign leaders to lie for him to cover his liability associated with Oct 7…
One month to go until elections.
Source: Times of Israel, CNN / Writer: Bri
— @MarioNawfal Sep 28, 2026
Katie Miller’s Diva Tantrum Got Top FBI Officials Demoted thedailybeast.com/katie-mill…
— Michael Novakhov (@mikenov) Sep 28, 2026
|
Michael_Novakhov shared this story . |
- Summary
- Hackers claim stolen data includes health information
- Reuters has partially authenticated some of the files
- FBI says it is ‘aggressively’ investigating reported breach
- ShinyHunters is a notorious hacking crew
WASHINGTON, Sept 25 (Reuters) – FBI personnel data recently stolen by the ShinyHunters hackers includes sensitive psychiatric and medical evaluation records, according to the hackers and documents reviewed by Reuters.
ShinyHunters, one of the world’s most notorious and attention-seeking hacking crews, first said it had breached the FBI on Tuesday. In the hack, the group obtained granular details about bureau employees and their assignments, Reuters previously reported, including sensitive work against Chinese spies, Russian intelligence, drug cartels and others.
The Misinformation Monitor newsletter rounds up international misinformation narratives, with a “Real or Fake?” quiz in every edition. Sign up here.
The breach has already rattled the bureau, but now threatens to turn into a serious counterintelligence risk, said Eric O’Neill, a former FBI operative who founded the cybersecurity consultancy Nexasure AI.
O’Neill said the presence of medical data was a sign that the hack was approaching the same kind of magnitude as the 2015 intrusion into the Office of Personnel Management, which exposed millions of Americans’ sensitive clearance information, allegedly to Chinese intelligence.
He added that the data would be a powerful magnet for hostile spies.
“I would be shocked if Russian intelligence isn’t knocking on their door and saying, ‘We want that stuff, hand it over,'” said O’Neill.
The FBI declined to comment on the records. In a statement issued Wednesday, the bureau said it was “aggressively investigating” the reported breach.
ShinyHunters circulated the medical files to a small circle of reporters earlier this week after announcing it had broken into the FBIjobs.gov site and stolen what it claimed was 2 to 3 terabytes of data.
The BBC earlier on Friday reported that
a blood and urine test document, opens new tab
was among the sample, but the presence of other sensitive files, including a mental health evaluation and other records, has not previously been reported.
Reuters was able to partially authenticate some of the half-dozen files in several ways, including running two social security numbers in them against credit bureau data, and lining up the date of a pre-employment mental health evaluation against a former FBI analyst’s LinkedIn profile. Reuters also matched the name of an FBI psychiatrist in the document to a LinkedIn profile with the same name and an identical job title.
In one case, Reuters was able to confirm with a person familiar with the matter that a medical professional listed in one of the documents as performing FBI evaluations was in fact doing so at the time, although the person could not authenticate the entire file.
The person spoke on condition of anonymity because they weren’t authorized to discuss the matter.
The psychiatrist and the FBI employees named in the data either did not return messages or declined comment.
DOCUMENTS INCLUDE MEDICAL SPECIFICS
The documents reviewed by Reuters range in sensitivity. One medical record, which was part of a “fitness for duty” exam given to prospective employees, noted that an applicant took aspirin daily and was allergic to dust and cats.
Another record said a potential employee exhibited “symptoms of depression” in high school. A third document carried an electrocardiogram result.
Reuters could not establish whether the limited number of documents viewed were representative of the rest of the data trove held by ShinyHunters, or whether there even were other documents.
An FBI advisory released in May said the group has in the past exaggerated its level of access in an attempt to extort its victims.
ShinyHunters told Reuters on Tuesday the data it had was “very very very sensitive” and included medical information, discharges, prescriptions, clinical visits, and “any health issues with Agents.”
The hackers said they had compromised several of the bureau’s internal services, including the FBI’s background and employee applicant screening system, FBI MedLink, which contains agency personnel medical records, and the FBI’s Background Investigation Contract Services unit. Reuters could not corroborate those specific allegations.
Initially, the group said it would hold the data hostage until the FBI retracted its May advisory, which it said it took exception to. Since then ShinyHunters has removed that defiant statement from its website, saying Thursday it would not comment on what it would do “if the victim does not comply with our kind request.”
Story updated with context and additional detail in paragraphs 10 through 15
Reporting by Raphael Satter in Washington and AJ Vicens in Detroit; editing by Chris Sanders and David Gaffen
Our Standards: The Thomson Reuters Trust Principles., opens new tab
