The FBI released its first public cybersecurity strategy, a 17-page unclassified plan to counter cybercrime, nation-state intrusions and digital criminal groups. Its four pillars are imposing costs on adversaries, supporting victims, expanding industry cooperation, and strengthening FBI digital capabilities. The bureau will direct its 56 field offices and overseas personnel to coordinate investigations and accelerate sequenced disruption operations; it has conducted 50 such operations since early 2025, including actions against Russian GRU activity targeting U.S. home routers and the joint disruption of Lumma malware infrastructure with Microsoft.
The strategy calls for human-reviewed and legally controlled AI use in malware analysis, infrastructure mapping, relationship analysis, attribution, threat-pattern detection and prioritizing victim notifications. FBI officials said AI is increasing adversaries’ speed and vulnerability-discovery capabilities, while urging organizations to adopt continuous risk-based patching and maintain fundamentals such as multifactor authentication. Cyber Division leadership also pressed victim organizations to share incidents sooner, stressing that the FBI can help eradicate intruders and preserve evidence without passing reports to regulators for regulatory enforcement; the bureau plans faster threat-intelligence sharing, expanded industrial-control-system coordination, and stronger protections for victim privacy.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
The strategy calls for human-reviewed and legally controlled AI use in malware analysis, infrastructure mapping, relationship analysis, attribution, threat-pattern detection, and prioritizing victim notifications. It also commits to faster incident response, privacy-conscious victim support, expansion of Industrial Control Systems coordinators, and development of lawfully authorized computer network operations.
The FBI released a 17-page unclassified public cyber strategy covering criminal and national-security threats. It directs the bureau’s 56 field offices and overseas cyber personnel to coordinate investigations, support victims, expand partnerships, and increase the pace of disruption operations and threat-intelligence sharing.
A presidential memorandum directed the Departments of Justice and Homeland Security to establish operating procedures and participation standards for a federally supervised program allowing vetted U.S. companies to conduct operations against foreign criminal organizations. Nation-state threat groups are excluded from the proposed program.
Since the beginning of 2025, the FBI has conducted 50 “sequenced operations” against cyber threats, including operations targeting Russian military intelligence activity on vulnerable U.S. home routers and Lumma malware infrastructure.
FBI officials said AI is increasing the speed and capability of nation-state and criminal cyber actors, while AI-driven vulnerability discovery makes periodic patching insufficient. They recommended continuous, risk-based patching and stressed that basic controls such as multifactor authentication remain effective.
See what this changes for your reporting obligations and which controls it puts on the clock.
9 references tracked. Mallory keeps watching after this page renders.
health-isac.org
Open sourceinfosecurity-magazine.com
Open sourcemalware.news
Open sourcetherecord.media
Open sourcenextgov.com
Open sourcecyberscoop.com
Open sourcefbi.gov
Open sourcecyberscoop.com
Open sourcefbi.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.