WASHINGTON — The morning after Super Bowl LVII, FBI Special Agent Aaron Spivack arrived at his desk in the New York Field Office and found a text file he had not placed there. The message was brief and unambiguous: “your network has been compromised.”
The machine that had been accessed was not standard bureau infrastructure. It sat inside the Child Exploitation Forensic Lab, known internally as the C-20 lab, where the FBI stored digital evidence from the most sensitive child exploitation cases it handled, including the investigation into Jeffrey Epstein. A foreign hacker, according to Spivack’s own sworn declaration, had spent time reading through files specifically tied to that case.
That was February 13, 2023. For three years, the public learned nothing. No press release was issued. No member of Congress was briefed. The disclosure came quietly, embedded inside a sworn statement Spivack later gave to the FBI’s own Inspection Division, a document that surfaced only because a transparency statute dragged it out. On September 18, 2026, the Justice Department, acting under Donald Trump‘s direction, released roughly 3.5 million pages of Epstein-related material, including more than 2,000 videos and 180,000 images. Spivack’s declaration arrived inside that dump.
The account he gives is precise. He left the C-20 lab’s computer with remote internet access enabled, a configuration that arose, by his account, from conflicting guidance inside the FBI’s own IT structure. The bureau’s internal policies, he said, had not clearly prohibited what he had done. When the Inspection Division reviewed the breach afterward, Spivack described being made “a scapegoat” by an institution deflecting from a systems-level failure. He gave sworn testimony on January 26, 2024 and again on August 8, 2024. His declarations sat inside government files until the transparency statute pulled them out.

What complicates the picture is what the intruder apparently did not know. Based on the contents of Spivack’s declaration, the hacker did not initially appear to realize they had penetrated an FBI server. They encountered child sexual abuse material stored on C-20 lab drives, evidence from active federal investigations. The response, by Spivack’s account, was disgust. They left a note threatening to report the “owner” of the files to the FBI, not realizing the owner was the FBI. A foreign actor had walked into the most sensitive server the New York Field Office operated and did not recognize the building they were inside.
That detail does not diminish the exposure. A foreign actor, whatever their state of awareness, had accessed a federal law enforcement server containing evidence in one of the most politically consequential investigations in modern American history. The C-20 lab held materials touching Epstein’s network, individuals the Department of Justice had spent years building records around. The possibility that any of those files, or the metadata identifying who appeared in them, was exposed to a foreign intelligence service or a private actor has never been publicly assessed by the bureau.
The declaration entered the public record through an unlikely path. The Epstein Files Transparency Act, passed by Congress after years of sustained pressure from survivors’ advocates and oversight lawmakers, required the Justice Department to compile and release a comprehensive archive of Epstein-linked government records. The September 18 batch is the largest single disclosure yet. The Spivack declaration arrived inside it with no announcement, no press conference, no highlighted index entry. Finding it required working through a document set large enough to fill multiple commercial hard drives.

Spivack has not faced public disciplinary action. The Inspection Division reviewed him, took his sworn testimony twice, and the matter remained internal. His declaration frames the breach as institutional in origin as much as personal. He argues the bureau’s IT guidance was inconsistent, that the configuration error was not one he had been explicitly directed to avoid, and that the agency’s response treated him as the single point of failure for a problem that ran deeper. Whether the FBI audited what the hacker accessed, or notified any individual whose evidence sat on the C-20 lab server, is not addressed anywhere in the materials the Justice Department has released.
The September 18 release is not expected to be the final batch. Advocacy organizations tracking the disclosure process have said more material remains to be processed under the Transparency Act’s requirements. What the Justice Department will release next, and whether any of it will include an institutional assessment of the 2023 breach, is not known.

CBS News reported on the September 18 release, which included more than 2,000 videos and 180,000 images from the Justice Department’s Epstein archive.
