Hackers breached two U.S. federal agencies within a single month, extracting what Department officials described as "person records" — a haul of sensitive data that cybersecurity investigators are still working to fully quantify.
The intrusions mark the second confirmed federal compromise in roughly 30 days, a pace that has alarmed officials inside the agencies responsible for defending government networks. The stolen material includes personnel files, the kind of information that can be used for identity theft, targeted phishing, or intelligence gathering against government employees.
Brett Leatherman, a director involved in the response, addressed the attackers directly in remarks that signaled the government is actively tracking those responsible. "The longer you stay in this, the more we learn about you," Leatherman said.
He followed with an unusually pointed warning: "You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."
The tone of Leatherman's statement — part threat, part offer of negotiation — suggests federal investigators have gathered enough forensic evidence to identify at least some of the intruders. It also implies the government wants the hackers to come forward before formal charges or public attribution make that option disappear.
Personnel records are among the most valuable targets in a federal breach. Unlike classified documents, which are difficult to monetize, employee data — names, Social Security numbers, dates of birth, security clearance levels, and job histories — can be sold on criminal markets or used to impersonate trusted government workers in follow-on attacks.
The two agencies have not been publicly named, and officials have not disclosed how many individuals are affected or whether the breaches are connected. The one-month window between the two incidents raises the possibility of a coordinated campaign rather than two unrelated attacks, though investigators have not confirmed a link.
Federal cybersecurity efforts have faced mounting pressure in recent years as foreign governments and criminal groups have repeatedly targeted government systems. The breach of the Office of Personnel Management in 2015, which exposed the records of more than 21 million people, remains the benchmark for damage caused by stolen federal personnel data — a standard against which the current incidents will inevitably be measured.
Leatherman's public message to the hackers carries an implicit deadline. Federal attribution and indictments typically follow months of quiet investigation, and once charges are filed, the window for a negotiated resolution closes. Whether the attackers take the offer remains unknown, but the government's willingness to make it publicly suggests officials believe they hold leverage.
Investigators have not said whether the stolen records have surfaced on criminal forums or been transferred to a foreign state. The scope of the damage — how many records, which agencies, and what specific data fields were taken — remains under active review.