The FBI is still trying to work out the ramifications of the breach, which some former officials have described as a major blow to its operational security. FBI cyber chief Brett Leatherman said in a statement that a platform managed by a third-party organisation was compromised after a contractor failed to apply a security patch issued specifically to secure it. The FBI did not name the contractor or the platform.

The two sources said the platform was Oracle's PeopleSoft, a human resources system that the hacking group ShinyHunters said it exploited in September to break into the FBI's job site. In June, Google raised the alarm over a ShinyHunters linked hack and extort campaign aimed at organisations using PeopleSoft software.

The exposed information includes detailed descriptions of named employees' counterintelligence work, street addresses of human intelligence operatives, medical and psychiatric records of bureau staff. The breach has caused concern across the FBI and the wider intelligence community.