The Federal Bureau of Investigation has concluded the preliminary phase of its internal investigation into last month’s security breach of its employment portal, determining that a third-party contractor’s failure to implement basic security measures enabled the attack.

Brett Leatherman, Assistant Director of the FBI’s Cyber Division, issued a statement Tuesday confirming that the incident resulted from “a security failure of a platform managed by a third-party organization.” The contractor, whose identity the Bureau has not disclosed, failed to apply a security patch that had been explicitly provided to protect the system from such vulnerabilities.

The FBI has terminated its relationship with the contractor and implemented additional security protocols to safeguard its workforce and prevent further compromise. According to Leatherman’s statement, multiple arrests have already been made as the investigation progresses.

The breach of FBIJobs.gov occurred late last month. ShinyHunters, a known cyber-extortion organization, claimed responsibility for the attack. A representative from the criminal group asserted they had exploited the jobs portal to access other agency systems, allegedly extracting between two and three terabytes of files. The full extent of these claims remains unverified at this time.

Leatherman’s statement appeared to confirm the Bureau’s assessment that ShinyHunters orchestrated the attack. “The FBI will aggressively investigate this cyber incident involving FBIjobs.gov and the cyber-criminal group ShinyHunters with all available resources,” he stated.

FBI Director Kash Patel announced last week that authorities had arrested an alleged member of the organization. The arrest occurred on September 15, one week before ShinyHunters publicly claimed credit for the attack on the FBI system.

“This morning our partners the Dutch National Police are announcing the arrest of one of the alleged leaders of ShinyHunters,” Patel wrote in a social media post. He described the organization as “a global cybercrime and threat actor group linked to cyberattacks in the United States, the Netherlands, and around the world.”

Patel indicated that FBI teams continue working with international partners to develop additional leads stemming from the arrest and the ongoing investigation.

The incident has raised concerns within the Bureau about internal communications. Some FBI employees expressed frustration at learning about the security breach through news reports rather than through official agency channels. Sources familiar with the matter indicated that staff believed the agency’s response and internal notification process moved too slowly.

In response to these concerns, the FBI maintained in an earlier statement that it remains “in regular communication with anyone who may be impacted” and emphasized that the agency “treats the security of its information and the safety of its workforce as top priorities.”

ShinyHunters operates as a loosely organized criminal enterprise with members distributed across multiple countries. The group’s standard methodology involves infiltrating corporate and government systems to steal sensitive data, which they then threaten to publish on the dark web unless their extortion demands are met.

This breach represents a significant security lapse for an agency tasked with protecting the nation from cyber threats. The reliance on third-party contractors for critical security functions has once again proven to be a vulnerable point in federal information technology infrastructure. As the investigation continues, the full scope of the damage and the effectiveness of the FBI’s response will become clearer in the weeks ahead.

Related: Former Deputy Attorney General Sally Yates to Lead Independent Review at Cornell