The FBI says it is addressing a massive breach involving employees’ sensitive data and is seeking to identify and pursue whoever was responsible. The agency has therefore opened an investigation into the disturbing possibility that someone, somewhere, may have obtained information the FBI generally prefers to obtain about other people.
Officials are expected to begin with a careful review of all available files, passwords, access logs, access-log passwords, and the small laminated card explaining where the access-log passwords are stored. The review will proceed until investigators locate a person with enough personal information to merit concern, which is understood to be the agency’s customary threshold for beginning the paperwork.
The inquiry will reportedly consider several possibilities, including unauthorized access, insufficiently authorized access, and access that was technically authorized but later became embarrassing after being described in a meeting as “a systems matter.” Each possibility will be assigned a case number, a retention schedule, and a secure folder whose existence will be confirmed only after it has been misplaced.
Because the identity of those responsible and the full scope of the compromised data have not been established, the investigation will avoid premature conclusions. It will instead assemble a broad, methodical picture of events, then place that picture in a restricted database accessible to the precise number of people required for it to become a concern again.
The FBI’s response offers a rare demonstration of institutional symmetry: an organization built to follow sensitive information wherever it leads is now asking sensitive information, with appropriate urgency, whether it would be willing to come back.


