The FBI confirmed it detected and remediated “suspicious activities” on its networks and said it is using “all technical capabilities” to respond, but provided no additional details on scope, impact, or attribution. Reporting citing an anonymous source indicated the activity may have affected a digital system used to manage and conduct surveillance, including workflows tied to foreign intelligence surveillance warrants, wiretaps, and pen registers (used to trace communications metadata such as IP addresses and dialed numbers).
Public reporting did not establish who was responsible or when the activity occurred, and it was unclear whether the incident is connected to prior compromises of U.S. lawful-intercept and surveillance-related infrastructure (including earlier reporting about Salt Typhoon activity targeting U.S. wiretapping systems). The incident follows a pattern of repeated targeting of U.S. government networks; the FBI has previously disclosed other intrusions and security events affecting parts of its environment, underscoring ongoing operational risk to sensitive investigative and surveillance support systems even when public details remain limited.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-03, reporting said the compromised FBI surveillance system may have exposed phone numbers and related pen register and trap-and-trace metadata tied to surveillance targets. The report said such metadata could help a foreign adversary identify who the United States was monitoring and map associates' networks.
On 2026-03-23, the Justice Department formally classified the China-linked compromise of the FBI surveillance system as a 'major incident' under federal law, signaling significant national security risk. The determination was followed by congressional notification and reflected the seriousness of the breach affecting sensitive surveillance-related data.
By 2026-03-10, reporting said the FBI had designated the suspected Chinese intrusion into its surveillance data system a 'major cyber incident.' The designation signaled the bureau viewed the breach as especially serious and raised concern that sensitive information stored on FBI systems may have been accessed.
On 2026-03-10, reporting said investigators suspected hackers affiliated with the Chinese government, though the FBI had not publicly confirmed attribution or a link to Salt Typhoon.
By 2026-03-10, reporting indicated the White House, DHS, and NSA had joined the investigation, and investigators were examining a possible intrusion path through a vendor's internet service provider, suggesting a third-party or supply-chain vector.
By 2026-03-05, senior FBI and Justice Department officials responsible for national security and civil liberties were engaged in the response because of the system's sensitivity and possible implications for active investigations.
On 2026-03-05, multiple outlets reported that the FBI was investigating suspicious cyber activity affecting a digital platform used to manage court-authorized wiretaps and foreign intelligence surveillance warrants.
As the bureau assessed the potential impact, it notified members of Congress that a sensitive FBI system containing law-enforcement data and personally identifiable information was under investigation.
After identifying the activity, the FBI said it addressed the suspicious network activity using all available technical capabilities and launched an investigation to determine scope, origin, and whether any data was accessed.
On 2026-02-17, the FBI began investigating abnormal log activity affecting an unclassified but law-enforcement-sensitive internal system tied to wiretaps, pen registers, trap-and-trace data, and FISA warrant management.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
nextgov.com
Open sourcetechrepublic.com
Open sourcepolitico.com
Open sourcemalwarebytes.com
Open sourcetechcrunch.com
Open sourceedition.cnn.com
Open sourceabcnews.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.