Two federal agencies were hacked within a single month, exposing sensitive personnel records in breaches that a senior U.S. cyber official said have handed attackers a trove of information about government employees.
Brett Leatherman, a director involved in the government's response, described the scope of what intruders obtained and delivered an unusually direct message to those responsible. "The longer you stay in this, the more we learn about you," he said. He followed with a warning aimed squarely at the attackers: "You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."
Department officials confirmed that "person records" were among the data compromised — a category that typically includes names, Social Security numbers, dates of birth, and employment histories. Such records are among the most valuable material for identity thieves because they cannot be changed the way a password or credit card number can.
The two breaches occurred weeks apart, according to accounts of the incidents, giving attackers repeated access to systems that hold information on federal workers. The back-to-back nature of the hacks has drawn scrutiny to whether agencies are sharing threat intelligence quickly enough to prevent one intrusion from informing the next.
Federal agencies hold personnel files on millions of current and former employees, contractors, and in some cases their family members. A single compromised database can expose decades of career records — security clearance levels, job evaluations, health benefits enrollment, and direct deposit information — all of which can be cross-referenced to build detailed profiles of individuals with access to sensitive government operations.
The breaches add to a pattern of cyber intrusions against U.S. government targets in recent years, including the 2015 Office of Personnel Management hack that exposed records on roughly 22 million people. That incident led to years of litigation, congressional hearings, and a broad restructuring of federal cybersecurity practices. The current cases have not yet been publicly attributed to a specific group or nation-state.
Leatherman's remarks suggest investigators are actively tracing the intruders rather than simply closing off access. His statement that "the longer you stay in this, the more we learn about you" implies authorities are monitoring attacker activity inside or around the compromised networks, a technique known as counter-surveillance that can reveal a hacking group's infrastructure, habits, and identity over time.
Officials have not disclosed how many individuals were affected, which specific systems were accessed, or whether the two breaches are connected. The affected agencies also have not publicly detailed what remediation steps are underway for employees whose records may have been stolen.
Federal employees whose data is confirmed compromised in a breach are typically offered credit monitoring services and identity theft protection, though those measures address the aftermath rather than the theft itself. Personnel records exposed in a breach remain in circulation on criminal marketplaces for years after the initial incident.