Threat actors have published personal data belonging to roughly 20,000 FBI employees and 9,000 Department of Homeland Security staff in a deliberately staged, two-part leak. The exposed records include names, email addresses, phone numbers, and job titles. The DHS tranche landed first, followed by the larger FBI dump, a sequencing choice that maximized media attention and signaled that the actors were holding material in reserve. Portions of the leaked data have been independently reviewed by journalists and assessed as authentic.
What Happened
The disclosure unfolded in stages rather than as a single dump. Attackers first released a file containing information on approximately 9,000 DHS personnel, then followed with a substantially larger set covering more than 20,000 FBI employees. Staged release is a pressure tactic: it establishes credibility with the first drop, then leverages that credibility to amplify the second while implying more material is still held.
Reporting from 404 Media documented a related and more targeted disclosure in which a hacking group published personal information on hundreds of federal officials across DHS, Immigration and Customs Enforcement, the FBI, and the Department of Justice. That set covered roughly 680 DHS staff, more than 190 DOJ officials, and email addresses for 170 FBI employees. It was posted to a Telegram channel and attributed to a group operating under the name The Com. Multiple journalists verified samples against known-good records and found them consistent.
The Telegram posts carried explicit threats of further releases. The actors have publicly suggested IRS officials could be targeted next. The same posts included unverified claims about cartel bounties on named individuals, which should be treated as intimidation messaging rather than as substantiated threat reporting until corroborated.
Federal workforce doxing is not new. In 2016, a group calling itself Crackas With Attitude published personal information on thousands of FBI and DHS personnel and compromised accounts belonging to senior intelligence officials. The current activity follows that template at larger scale and with a faster distribution channel.
What Was Taken
The two large tranches consist of directory-grade identity data: full names, work email addresses, phone numbers, and job titles. On its own, each field is low sensitivity. Aggregated across an entire agency roster, the combination is an org chart, a phishing target list, and a social engineering playbook in one file.
The smaller, more targeted set is materially more dangerous. It reportedly includes names, office locations, and apparent private residential addresses for personnel involved in immigration enforcement. Home address exposure moves the risk profile from account compromise to physical safety.
There is no indication in available reporting that classified material, case files, informant identities, or operational data were included. The exposure appears to be administrative and personnel data rather than mission systems. That distinction matters for response prioritization, but it does not reduce the personal risk to the individuals named.
Why It Matters
Full-roster exposure changes the economics of targeting. An adversary no longer has to identify who works where; the list does it for them. Job titles let attackers select for access, seniority, and function, which is exactly the input needed for business email compromise, credential phishing, and pretexted help desk calls against a specific agency.
Phone numbers enable smishing and vishing at scale, and they support SIM swap reconnaissance against personal accounts that may reuse credentials or serve as multi factor recovery paths. Work email addresses combined with titles allow an attacker to construct convincing internal correspondence without any prior access to the environment.
The residential address exposure in the targeted set creates a direct physical risk to law enforcement personnel and their families. Published home addresses paired with intimidation messaging invite harassment, surveillance, and worse from third parties who were never involved in the original intrusion. This is the intended effect: the leak is the attack, not a byproduct of one.
Finally, the actors' stated intent to expand to additional agencies indicates an ongoing campaign rather than a closed incident. Other federal bodies with public-facing enforcement roles should assume they are within scope.
The Attack Technique
The initial access vector has not been established in public reporting. Available evidence does not identify a specific exploited vulnerability, compromised vendor, or intrusion method, and no agency has confirmed a technical root cause. Anyone claiming certainty here is ahead of the evidence.
Several possibilities remain consistent with the data profile. Directory-grade information of this exact composition, name, email, phone, and title, is characteristic of an internal address book, HR system export, or contractor-held personnel database rather than a deep operational compromise. Historically, similar federal doxing incidents have originated from social engineering against help desks and IT support staff rather than from technical exploitation, with attackers talking their way into a portal and then pulling a bulk export.
The Com is a loosely organized, English-speaking cybercriminal ecosystem better known for social engineering, SIM swapping, and insider recruitment than for novel exploit development. That profile is consistent with credential theft, help desk manipulation, or an insider providing access, rather than with a sophisticated intrusion chain.
Distribution ran through Telegram, which offers the actors resilient hosting, a built-in audience, and a direct channel for follow-on threats without exposing infrastructure that defenders could seize.
What Organizations Should Do
Treat the exposed roster as a live phishing target list. Push tuned detection rules for inbound mail impersonating the named individuals and for lures referencing their specific job functions. Assume attackers know your org chart.
Harden the help desk against identity-based social engineering. Require out-of-band verification, ideally callback to a number of record or manager confirmation, before any password reset, MFA re-enrollment, or device registration. This is the single control that most often fails in incidents matching this profile.
Move exposed staff to phishing-resistant MFA. Deploy FIDO2 or hardware security keys for the affected population and eliminate SMS and voice-based factors, which are directly undermined by leaked phone numbers.
Audit bulk export capability across HR, directory, and identity systems. Identify every account and integration that can pull a full personnel roster, reduce that list aggressively, and alert on large directory reads. Review third-party and contractor access to the same data.
Stand up a personal-risk response track for named individuals. Offer credit monitoring, data broker removal services, guidance on locking down personal accounts, and a clear reporting path for harassment. For the subset with published home addresses, coordinate with physical security and local law enforcement.
Monitor for downstream reuse and follow-on releases. Track Telegram and adjacent channels for additional tranches, and correlate the leaked identifiers against credential stuffing attempts, account recovery requests, and inbound social engineering across your environment.
Sources: Hacker Posts Info Of 20K FBI Employees 9K DHS Staff