A foreign, unidentified hacker breached the FBI’s New York Field Office in 2023 and accessed files tied to the bureau’s investigation of Jeffrey Epstein, according to Reuters reporting based on a source familiar with the incident and Justice Department/court documents. The intrusion reportedly stemmed from a server at the Child Exploitation Forensic Lab that was inadvertently left vulnerable by an FBI special agent working the case; a court document described the actor as having “combed through” certain Epstein-related files.
The FBI said it contained the affected network, assessed the incident as isolated, restricted the actor’s access, and remediated the exposed network, while noting the investigation remains ongoing. Additional reporting identified the agent as Aaron Spivack and cited a timeline indicating the break-in occurred on February 12, 2023; Reuters also reported the hacker allegedly did not realize they had accessed FBI systems until agents contacted them and requested a video call where they displayed their credentials.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Reuters reported on March 11, 2026, that a foreign hacker had compromised Epstein-related FBI files during the 2023 intrusion, citing a source familiar with the matter and court or Justice Department documents. Other outlets subsequently matched the reporting and noted the FBI investigation remains ongoing.
Documents released earlier in 2026 under the Epstein Transparency Act included an FBI timeline stating the break-in occurred on February 12, 2023, bringing the incident's details into the public record.
The day after the breach, an FBI agent identified suspicious activity from two IP addresses following a network compromise alert. The bureau said it isolated the affected network, restricted the actor's access, and remediated the system.
On February 12, 2023, an unidentified foreign hacker reportedly broke into an FBI New York Field Office server used by the Child Exploitation and Human Trafficking Task Force and accessed files tied to the Jeffrey Epstein investigation.
A server at the FBI New York Field Office's Child Exploitation Forensic Lab was reportedly inadvertently left vulnerable by Special Agent Aaron Spivack while handling digital-evidence procedures, creating the conditions for later unauthorized access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetechcrunch.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.