The FBI confirmed that suspicious cyber activity targeted one of its internal surveillance networks, and officials later classified the intrusion as a "major incident" under FISMA because of the potential national security impact. Reporting indicates the affected environment included systems tied to the FBI’s Virgin Islands operations, where attackers accessed highly sensitive law-enforcement information, including pen register and trap-and-trace returns as well as personally identifiable information connected to active investigations. The bureau said it detected unusual activity in February, informed lawmakers in early March, and publicly acknowledged that the activity had been contained while the investigation continued.
Multiple reports said investigators linked the operation to China, and that the attackers appear to have reached FBI systems through a commercial internet service provider’s vendor infrastructure rather than by directly breaching the bureau first. The incident prompted a broader U.S. government response, with the White House convening officials from the FBI, NSA, and CISA and the Justice Department establishing a working group to strengthen resilience and incident response. The breach was reported as separate from another cyber matter involving the FBI director’s personal email, underscoring that the bureau was confronting several cyber threats at the same time.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Following the breach determination, the White House convened officials from the FBI, NSA, and CISA, and the Justice Department formed a working group to improve cyber resilience and incident response. These actions reflected a broader federal response to the intrusion.
On March 23, the Justice Department determined that the FBI surveillance-system breach met the FISMA threshold for a major incident, signaling significant national security risk. The classification followed reporting that sensitive pen register, trap-and-trace, and personally identifiable information had been exposed.
On March 5-6, 2026, the FBI publicly acknowledged it was investigating suspicious cyber activity targeting a critical surveillance network. Multiple reports described the activity as affecting bureau systems and prompting an active investigation.
By March 4, the FBI had notified lawmakers about suspicious activity affecting a critical surveillance network. This marked the incident's escalation from internal detection to formal congressional notification.
The FBI detected unusual activity on one of its internal surveillance systems, later tied in reporting to a China-linked intrusion. The affected environment reportedly included systems in the Virgin Islands and exposed sensitive law-enforcement and investigative data.
On 2024-10-05, The Wall Street Journal reported that a China-linked intrusion affecting major U.S. broadband providers, including AT&T and Verizon, had potentially accessed systems used to submit and process court-authorized wiretap requests. The report said the attackers may also have accessed broader internet traffic and maintained access for months or longer.
The FBI disclosed that it had contained a cyber incident affecting its computer network at the New York Field Office. Reporting on February 17, 2023 indicates the bureau said the incident was isolated and under control.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcecbsnews.com
Open sourcecnn.com
Open sourceedition.cnn.com
Open sourceweb.archive.org
Open sourcefedscoop.com
Open sourcecnn.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.