Government security, Privacy, Data Security

A personnel file is a map: Why the FBI breach matters

The FBI logo is seen on its Washington headquarters

Eleven years ago, my wife and I learned that the federal government had lost control of some of the most personal information we had ever been required to provide.

We were among the 21.5 million people whose background-investigation records were compromised in the Office of Personnel Management data breach. Those records detailed where we lived and worked and our finances, relationships, and histories, along with information about people close to us.

We gave the government that information because our service required it.  The government held a remarkably detailed map of our lives. And now, someone else had stolen it.

That experience changed how I think about personnel data. A personnel file maps a public servant's life, family, career, network, and, in some cases, mission. At scale, those files can illuminate an organization: who its people are, what they do, how they are connected, and where specific expertise resides.

Two newly reported incidents involving the FBI and the Defense Department have brought that map back into view.

ShinyHunters says it stole more than two terabytes of FBI personnel and applicant data by exploiting Oracle PeopleSoft. Reuters reported that the exposed material included names of personnel in sensitive FBI units and medical and psychiatric records; the FBI is investigating the claims.

Since then, Google has warned that ShinyHunters has expanded its campaign against vulnerable PeopleSoft systems, exploiting a critical authentication flaw across government and other sectors.

Separately, the Defense Manpower Data Center disclosed that unauthorized users had accessed a Defense Department server containing unencrypted personal information for about nine months, including Social Security numbers and, for some service members, their military occupational specialties.

Personnel data becomes more valuable when combined with other datasets. In 2020, Foreign Policy reported that undercover CIA personnel traveling to Africa and Europe were being rapidly identified by Chinese intelligence. Former U.S. officials believed that Chinese services had learned to combine stolen government personnel records with travel, health, and other large datasets to identify American intelligence officers and track their activities.

The U.S. Cyberspace Solarium Commission report I helped write that year warned that major breaches could produce intelligence coups that threatened U.S. clandestine personnel.

Ahana Datta Fasel's new book, Full Stack Spies, offers a useful lens for understanding how that process unfolds. She describes an "upstairs," where governments and institutions set objectives, and a "downstairs," where hackers, analysts, and engineers translate those objectives into operations.

Personnel data can move through that full stack as a vulnerability creates access, collected records are linked to other datasets, and analysts turn those records into a picture of people, relationships, capabilities, and patterns. Each additional dataset can make the map more complete.

I spent years serving in and supporting the special operations community. The first of the Special Operations Forces (SOF) Truths is "Humans are more important than hardware."

I have seen that principle hold across government and military service. Capability resides in people — in their training, judgment, experience, relationships, and trust. Personnel systems record their histories, relationships, assignments, and qualifications in extraordinary detail. Protecting that information helps safeguard the people whose service requires its collection and the missions they support.

That responsibility goes hand in hand with the extraordinary level of investment the United States is making in military power. The administration's fiscal year 2027 budget, released earlier this year, proposed more than $1.5 trillion in total resources for national defense — a level that, if enacted, would represent the highest defense funding in a single fiscal year since World War II.

Fiscal year 2027 began Oct. 1 under a continuing resolution that funds federal agencies through Dec. 11 while Congress continues the annual appropriations process. The final defense topline remains for Congress to determine.

Ships, aircraft, munitions, artificial intelligence, industrial capacity, and readiness all depend on people. The systems that hold their identities, histories, relationships, assignments, and qualifications are part of the force those investments are intended to strengthen.

Federal agencies should design and operate personnel platforms with the assumption that the data they hold will be targeted. The standard should be demonstrated security performance under sustained attack.

The recent exploitation of Oracle PeopleSoft is instructive: Oracle disclosed a critical vulnerability that could be exploited remotely without authentication and issued a patch in June. Months later, Google observed ShinyHunters compromising organizations that remained unpatched, including some that had relied on web application firewall mitigations.

Procurement should evaluate security architecture, vendor response and patch velocity, identity and access controls, segmentation, monitoring, and the platform's operating history, while agencies maintain the discipline to patch and harden systems throughout their life cycle. The federal government should demand demonstrated security performance from systems that hold information about its workforce.

People who serve the United States disclose deeply personal information because their government requires it. That creates a corresponding obligation to protect it. My family learned 11 years ago what happens when that obligation fails.

A personnel file maps a life, a family, a career, a network, and sometimes a mission. The government should protect that map with the same seriousness it demands of the people whose service requires them to provide it.

Cory Simpson

Cory Simpson is founder and CEO of Gray Space Strategies and CEO of the Institute for Critical Infrastructure Technology. His background includes more than two decades of military service and senior staff work on the U.S. Cyberspace Solarium Commission, with a career spanning national security, cybersecurity, critical infrastructure and American competitiveness.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds