The allergy was the proof. Hackers who claim they hold medical files on thousands of FBI staff showed reporters blood tests and doctors’ notes this week, including a shellfish and banana allergy that no press release would invent. If you still think cybersecurity is the SOC’s problem and HR’s files are a different team’s problem, this is your week to stop.

FBI personnel at work, representing staff whose medical files were exposed to reporters
Clinical trivia from FBI staff files reached reporters this week, including blood work and allergy notes.

The Chart Beat Every Official Statement

A dump becomes real when it contains the boring parts. Blood panels. Provider notes. An allergy that would only matter in a cafeteria or an ER. That is the kind of detail a journalist can check against a person, and the kind of detail a hostile service can use for targeting, blackmail, or a convincing pretext call to a helpdesk. You already train staff not to give out badge numbers. You rarely train them that their last CBC sits in a tenant nobody on the SOC floor can name.

Malwarebytes reported that the operators showed those clinical records to reporters and claimed a haul covering thousands of FBI employees. You can run the rest of the week without a finished attribution note. Personnel medicine gets filed as a benefits problem. Benefits problems get a vendor. Vendors get a portal. Portals get a password. Then the file that can ruin a covert career is the file that never had an on-call owner.

This is a bad look for any shop that spends six figures on edge blocking and still cannot name the system of record for occupational health. The FBI is the loud example this week. Your company is running a quieter copy of the same architecture: a clinic login, an EAP form, a workers-comp upload, a background-check exporter. Someone in HR loves that it just works. Someone in threat detection has never seen the export log.

Your Cybersecurity Stack Never Watched Occupational Health

Walk your SOC’s coverage map. The VPN, the firewall, the identity provider, and maybe a mail gateway already have owners. Occupational-health SaaS usually appears after a compliance auditor forces the question. Defense in depth on paper still means stacked controls on the paths you already understand. The clinic path is usually a browser, a contractor IdP, and an export button.

Brute-force lockouts on the corporate VPN stay on the corporate VPN. The benefits portal may still take a standalone password, email OTP, or a shared HR service account. Threat detection tuned for malware and impossible travel will stay quiet while someone paginates through 4,000 employee charts. Your cyber security program can look mature on laptops and still be amateur on the file that lists who is pregnant, who has a psych note, and who is allergic to shellfish.

LinkedIn is testing the other face of personnel data this week: verified members confirming that they worked or studied with a connection, enough nods for a verification badge, with an opt-out. The company calls it peer-backed credibility. That is a public identity product. The FBI leak is a private identity product that escaped. Same class of record. Opposite controls. One is a reputation widget. The other is a targeting packet.

LinkedIn logo representing peer verification of work and education history
LinkedIn is testing coworker confirmation of jobs and schools while stolen clinic files show how personnel data actually travels.

Pull the Clinic Portal Onto the Same On-Call

Do the ugly inventory first. Today, not next quarter. List every system that stores employee medical, EAP, disability, drug-screen, or workers-comp data, including vendors that only process claims. For each one, write the internet exposure, the identity source, who can export, and where logs go. Those four answers are the vendor relationship. A missing answer means you are running an unmonitored data store with a purchase order.

Immediate work is exposure and identity, not a new dashboard. Pull any of those portals off the public internet if the vendor will support a VPN, reverse proxy, or IP allowlist. Force SSO from your IdP and kill local passwords. Remove standing admin accounts you cannot name. Confirm phishing-resistant MFA for HR and clinic admins; SMS for the intern who helps with benefits is a gift. Turn on export and bulk-search audit logs and ship them to the same place your identity logs already live. Hunt those logs for volume anomalies the way you hunt mailbox forwarding. If a vendor cannot produce export telemetry, treat that as a failed control.

Rotate the secrets HR tools quietly keep: service accounts, API keys, SFTP drops, the ancient file share that still receives nightly eligibility CSVs. Those files are the real backup of your workforce’s medical life. Security hardening here is boring on purpose. Least privilege on export roles. No shared inboxes for clinic alerts. No contractor laptop with a saved password to the TPA.

Ongoing work belongs in incident response, not a lunch-and-learn. Write a personnel-data playbook that names legal, HR, occupational health, and the SOC in the first hour. Practice a bulk-export alert. Practice notifying staff when a chart may have left, because waiting for a journalist to describe someone’s banana allergy is a communications failure you already watched. Tabletop the vendor: who cuts their access, who preserves evidence, who talks to the carrier. Put those hosts in the same vulnerability and access-review cycle as your identity provider. If your threat-protection stack cannot inspect that traffic, lock down who can reach it and who can dump it.

You will hear that this is a privacy problem. Fine. Privacy teams cannot page at 2 a.m. You can. The reporter who read an agent’s lab work used a PDF. Your firewall rule name stayed in a ticket nobody opened. Make the PDF harder to take, and make the taking loud.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.