It has been a bad month for US federal cybersecurity. Two major incidents have spilled sensitive personnel files that criminal groups and foreign intelligence services alike could use — and the details now assembled by Ars Technica show why defenders are treating them as one problem.

The larger case is at the Pentagon, which is notifying more than 2 million current and former service members that their records were stolen in a months-long intrusion into a department network. The breach compromised records belonging to 2.8 million living individuals, according to the department; the files came from the Defense Manpower Data Center, which collates personnel records for the armed forces.

A notification letter posted to Reddit lists the exposed fields: names, Social Security numbers, addresses, sex, race — and occupational specialty. Security analysts flagged that last category as the most dangerous. A list that maps names to military job specialties is, in effect, a targeting guide for intelligence services looking for people with access to particular systems.

Hackers first gained entry last October, and the compromise went unnoticed for months inside a system the DMDC says handles more than 60 million DoD "person records", covering military, civilian, contractor, retiree and veteran personnel along with their family members. The department has not said how the attackers got in, whether it has had contact with them, or whether a ransom was demanded. Officials say the data has not been misused, but have not explained how they know.

The second case is at the FBI. In September the ransomware group ShinyHunters claimed it hacked bureau systems and stole records on thousands of current and former employees, some of them with job titles tied to investigating China or Russia, Reuters reported. ShinyHunters said it has no plans to publish the material — a promise of limited value given that the group has extorted hundreds of organizations and that its own operational security would be unlikely to survive a nation-state intelligence service. This week the bureau applied public pressure: "The longer you stay in this, the more we learn about you," said Brett Leatherman, assistant director of the FBI's cyber division. "You know how to find us, and we know how to find you." His remarks followed Dutch police arresting an alleged ShinyHunters leader.

Together the incidents amount to one of the largest potential espionage hauls since the 2015 breach of the Office of Personnel Management, in which hackers linked to China obtained 22.1 million records of government employees and people who had undergone background checks, including fingerprint scans for millions of people. That is the uncomfortable comparison for defenders: OPM reshaped federal cybersecurity policy, and the current cases raise the same unresolved questions — network segmentation, detection, and how long an intruder can sit inside government systems before anyone notices.