A hacker reached an FBI server holding digital evidence from the Jeffrey Epstein investigation in February 2023, spent time inside files tied specifically to that case, and left behind a text file announcing the intrusion. The FBI has publicly confirmed the event only in the broadest terms, telling ABC News in a written statement that "following the 2023 cyber incident, the FBI contained the affected network and determined the incident to be an isolated one," that it "restricted access to the malicious actor and rectified the network," and that the investigation "remains ongoing." Everything more granular than that comes from a sworn declaration by the FBI special agent who discovered the compromise, a document that reached the public only because the Epstein Files Transparency Act forced the Justice Department to release the material it was buried in. Three years passed between the intrusion and the first public word of it.
What Happened
The compromised machine was not ordinary bureau infrastructure. According to the Eastern Herald's account of the declaration, it sat inside the Child Exploitation Forensic Lab known internally as the C-20 lab, the repository for digital evidence from the FBI's most sensitive child exploitation casework. ABC News, working from the same released documents, describes the affected system as a server "related to the FBI's New York Child Exploitation and Human Trafficking Task Force." Those descriptions are compatible: one names the lab, the other names the operational unit it supports, both place it in the New York Field Office.
The discovery was blunt. Special Agent Aaron Spivack found a text file on the machine that he had not put there, reading "your network has been compromised." The DOJ material reviewed by ABC News indicates the intruder accessed "certain files pertaining to the Epstein investigation."
Reuters reported the story on March 11, 2026, citing a source familiar with the matter alongside the newly published Justice Department documents, and characterized the intruder as a foreign hacker. That framing is worth holding at arm's length. As TechBloat's summary of the Reuters reporting notes explicitly, the reporting does not identify the hacker, does not establish the hacker's country, and does not show that any foreign government directed the operation. "Foreign" in this context is an attribution claim carried by a single unnamed source, not a confirmed finding.
The disclosure path matters as much as the intrusion. No press release was issued in 2023. No congressional briefing followed. Spivack gave sworn testimony to the FBI's Inspection Division on January 26, 2024 and again on August 8, 2024, and those declarations sat in government files until a transparency statute pulled them out. Per the Eastern Herald, the Justice Department released roughly 3.5 million pages of Epstein material on September 18, 2026, including more than 2,000 videos and 180,000 images, and the declaration arrived inside that dump. Separately, PBS reporting cited by EpsteinScan puts the DOJ review population at more than 5.2 million files. Those two figures measure different things, pages released versus files under review, and should not be treated as competing counts of the same set.
What Was Taken
This is where the record is thinnest and where the temptation to overstate is strongest.
The FBI's own position is that the incident was isolated and the network was contained. It has not said what the intruder read, whether anything left the building, or how long the access lasted.
The Eastern Herald reports that the hacker swept through roughly 500 terabytes of stored material. That figure appears in one OTHER-tier source and nowhere else in the available reporting, so treat it as a claim attributed to that outlet rather than an established volume. Note also that "swept through" is not "exfiltrated." Even taken at face value, it describes reach, not theft.
The Reuters-derived account is more conservative and, on current evidence, more defensible: some files related to the Epstein investigation were accessed, and the evidence does not show that files were downloaded, published, leaked, or taken by a foreign government. EpsteinScan's write-up of the ABC7 Bay Area report says flatly that the reporting does not specify what files were accessed, how the breach occurred, or whether material was removed.
What sat on systems of this class is documented independently. The released FBI evidence inventory, catalogued at epstein-data.com, lists physical evidence items 1B1 through 1B146 in the trafficking case collected between 2006 and 2022, a June 2020 warrant application scheduling two devices seized from Epstein's person, 33 seized at 9 East 71st Street on July 11, 2019, and 27 seized at Little Saint James on or about August 12, 2019, plus a digital evidence master copy serialized as NYC025654. Whether any of that specific material lived on the compromised host is not established by any source here. It is the category of data the C-20 lab exists to hold, and the category includes child sexual abuse material and victim identities.
Accounts That Do Not Line Up
Three points of divergence deserve to be stated plainly rather than smoothed over.
The date. ABC News puts the hack on February 12, 2023, Super Bowl Sunday. The Eastern Herald describes Spivack finding the intruder's file on the morning of February 13, the day after Super Bowl LVII. These are most likely the intrusion date and the discovery date respectively, but the sources do not reconcile them, and no source gives a dwell time.
The attribution. Reuters says foreign hacker. The FBI's public statement says only "malicious actor." Nothing in the public record bridges that gap.
The cause. Spivack's declaration, as reported, describes leaving the C-20 lab computer with remote internet access enabled, a configuration he attributes to conflicting guidance within the FBI's IT structure, and says bureau policy had not clearly prohibited it. He told the Inspection Division he was made "a scapegoat" for what he characterized as a systems-level failure. That is one participant's account of fault, given under oath and with an obvious personal stake. The FBI has not publicly contested or endorsed it.
One further point of hygiene: a parallel "Epstein files hacked" storyline circulating since mid-2026 concerns faulty PDF redactions in the public DOJ Epstein Library, where black boxes concealed text on screen while the underlying content remained extractable, with examples reported by the Associated Press. That is a publishing failure in a separate repository and has no established connection to the 2023 network intrusion. Conflating the two inflates both.
Why It Matters
The defensive lesson here is not about a novel exploit. It is about where the crown jewels actually live.
Forensic labs and evidence-processing environments are, by design, the highest-sensitivity data concentration in any investigative organization. They aggregate material that is deliberately excluded from general enterprise systems. They are also frequently run as specialist workstations by specialist staff, sitting in the organizational seam between the security team that owns the network and the unit that owns the mission. That seam is exactly where the reported misconfiguration lived.
The second lesson is disclosure latency. Three years elapsed between compromise and public knowledge, and the trigger was not an internal decision but a statute. The FBI Vault collection documenting the review of Epstein investigative holdings runs to eight PDFs exceeding 75 million bytes, with extensive redactions and deleted-page notices, and the pre-2025 access path ran through FOIA exemptions including (b)(7)(A), (b)(7)(C), (b)(7)(D) and (b)(7)(E). An institution with a legitimate and lawful apparatus for withholding information will, absent external forcing, tend to route breach facts into that apparatus. Any organization with strong confidentiality obligations should assume the same gravity applies to it and build the counterweight deliberately.
Third: the victims. Material in a child exploitation forensic lab is not a record count. The downstream harm of exposure is not measured in credit monitoring.
The Attack Technique
There is no exploit chain in the public record, no malware family, no indicators of compromise, and no named actor.
What the reporting does describe is an access path, and it is an unglamorous one. Per the declaration as reported by the Eastern Herald, a forensic lab computer was left with remote internet access enabled, in an environment where internal IT guidance was contradictory and policy did not clearly forbid the configuration. That is an exposure created by process ambiguity, not by adversary sophistication.
The intruder's parting text file is its own small signal. Planting a taunt on the host is inconsistent with a patient intelligence operation trying to preserve long-term access, and more consistent with an opportunistic actor, a hacktivist, or someone deliberately manufacturing an incident. It is not evidence of state direction. It is arguably evidence against it. But this is inference from one reported detail, not a finding.
What Organizations Should Do
-
Inventory your highest-sensitivity processing environments by name. Forensic labs, legal hold repositories, incident response staging, HR investigation systems, clinical research stores. Produce a written list of every host in each. If a system holding your most sensitive material is not on an explicit inventory with a named owner, it is not being monitored.
-
Assert egress control from the network layer, not the endpoint. The reported failure was a workstation configuration. A default-deny egress policy at the segment boundary makes an individual machine's settings irrelevant. High-sensitivity enclaves should have no default path to the internet, with exceptions granted per destination, per host, logged and reviewed.
-
Kill the policy ambiguity before the audit finds it. The declaration's core claim is that IT guidance was contradictory and the prohibition was not explicit. Go read your own policy for these environments. If a competent engineer could read it and conclude that a remote-access path is permitted, the policy is the vulnerability. Fix the text, then enforce it with configuration management rather than expecting compliance from busy specialists.
-
Continuously validate exposure from outside your perimeter. Scan your own address space on a schedule and diff the results. A host in a forensic enclave appearing in external scan results should page someone within minutes, not surface in a declaration three years later.
-
Write the disclosure decision rule now, while nothing is burning. Define in advance what triggers notification, who decides, who must be told regardless of the decision, and what the maximum permitted delay is. The single most useful control is a standing deadline that expires without needing anyone to act. Institutions do not conceal incidents by resolving to conceal them, they conceal them by never reaching a decision.
-
Separate the blame question from the remediation question, structurally. An investigation that pursues individual fault and an investigation that pursues systemic cause cannot be the same process, because the first one teaches everyone to stop reporting. Whatever the merits of Spivack's "scapegoat" characterization, the fact that a discovering agent came to hold it is a finding about the institution in its own right.
Sources: The FBI's Epstein Server Was Hacked on Super Bowl Sunday. Washingto... | Hacker accessed FBI server that included Epstein files in 2023, fil... | Epstein Files Compromised by Foreign Hacker Who Breached FBI? What... | DOJ Processes 5.2 Million Files While Hacker Breached Server, Repor... | Epstein Files Hacked? What Actually Happened With the Redactions | FBI VAULT: FBI Review of Investigative Holdings Related to Jeffrey... | FOIA exemptions in the FBI's Epstein records | FBI Evidence Inventory in the Epstein Investigation