Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
government-diplomatic-threatbreach-disclosure-notificationoperational-disruption

FBI Investigates Suspected Intrusion Affecting Wiretap and Surveillance Management Systems

Updated 3mo agoFirst seen Mar 5, 202615 sources

The FBI confirmed it detected and remediated “suspicious activities” on its networks and said it is using “all technical capabilities” to respond, but provided no additional details on scope, impact, or attribution. Reporting citing an anonymous source indicated the activity may have affected a digital system used to manage and conduct surveillance, including workflows tied to foreign intelligence surveillance warrants, wiretaps, and pen registers (used to trace communications metadata such as IP addresses and dialed numbers).

Public reporting did not establish who was responsible or when the activity occurred, and it was unclear whether the incident is connected to prior compromises of U.S. lawful-intercept and surveillance-related infrastructure (including earlier reporting about Salt Typhoon activity targeting U.S. wiretapping systems). The incident follows a pattern of repeated targeting of U.S. government networks; the FBI has previously disclosed other intrusions and security events affecting parts of its environment, underscoring ongoing operational risk to sensitive investigative and surveillance support systems even when public details remain limited.

Share:
FBI Investigates Suspected Intrusion Affecting Wiretap and Surveillance Management Systems
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Apr 3, 20263mo ago

Report says breach exposed surveillance targets' phone numbers

On 2026-04-03, reporting said the compromised FBI surveillance system may have exposed phone numbers and related pen register and trap-and-trace metadata tied to surveillance targets. The report said such metadata could help a foreign adversary identify who the United States was monitoring and map associates' networks.

Suspected Chinese breach of FBI system exposed surveillance targets’ phone numbers - Nextgov/FCW
Mar 23, 20263mo ago

Justice Department formally designates FBI breach a major incident

On 2026-03-23, the Justice Department formally classified the China-linked compromise of the FBI surveillance system as a 'major incident' under federal law, signaling significant national security risk. The determination was followed by congressional notification and reflected the seriousness of the breach affecting sensitive surveillance-related data.

FBI Declares Surveillance System Breach a ‘Major Incident’
Mar 10, 20264mo ago

FBI classifies surveillance-system hack as a major cyber incident

By 2026-03-10, reporting said the FBI had designated the suspected Chinese intrusion into its surveillance data system a 'major cyber incident.' The designation signaled the bureau viewed the breach as especially serious and raised concern that sensitive information stored on FBI systems may have been accessed.

FBI declares suspected Chinese hack of US surveillance system a ‘major cyber incident - Infosec.Pub

Report says investigators suspect China-linked hackers

On 2026-03-10, reporting said investigators suspected hackers affiliated with the Chinese government, though the FBI had not publicly confirmed attribution or a link to Salt Typhoon.

Investigation expands with interagency support and supply-chain lead

By 2026-03-10, reporting indicated the White House, DHS, and NSA had joined the investigation, and investigators were examining a possible intrusion path through a vendor's internet service provider, suggesting a third-party or supply-chain vector.

Mar 5, 20264mo ago

Senior DOJ and FBI officials are mobilized over legal and security risks

By 2026-03-05, senior FBI and Justice Department officials responsible for national security and civil liberties were engaged in the response because of the system's sensitivity and possible implications for active investigations.

News reports reveal FBI probe of wiretap and FISA warrant system

On 2026-03-05, multiple outlets reported that the FBI was investigating suspicious cyber activity affecting a digital platform used to manage court-authorized wiretaps and foreign intelligence surveillance warrants.

Feb 17, 20264mo ago

FBI notifies Congress about the surveillance-system incident

As the bureau assessed the potential impact, it notified members of Congress that a sensitive FBI system containing law-enforcement data and personally identifiable information was under investigation.

FBI contains suspicious activity and opens incident response

After identifying the activity, the FBI said it addressed the suspicious network activity using all available technical capabilities and launched an investigation to determine scope, origin, and whether any data was accessed.

FBI detects abnormal log activity on surveillance data system

On 2026-02-17, the FBI began investigating abnormal log activity affecting an unclassified but law-enforcement-sensitive internal system tied to wiretaps, pen registers, trap-and-trace data, and FISA warrant management.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

29 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Organizations
27 linked
PoliticoThe Wall Street JournalTrellixNextgov/FCWCable News NetworkVerizon CommunicationsCisco SystemsChainalysisAT&TLastPasseSentireMicrosoft CorporationGoogleArctic WolfThe RegisterEnvatoMalwarebytesBlackpoint CyberTechCrunchWindstream HoldingsCharter CommunicationsLumen TechnologiesGitHubThe Associated PressCyberScoopSecurity AffairsCBS
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.