Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
government-diplomatic-threatstate-sponsored-espionagethird-party-vendor-breachbreach-disclosure-notification

China-Linked Breach Hit FBI Surveillance Network and Exposed Sensitive Case Data

Updated 1mo agoFirst seen May 25, 20267 sources

The FBI confirmed that suspicious cyber activity targeted one of its internal surveillance networks, and officials later classified the intrusion as a "major incident" under FISMA because of the potential national security impact. Reporting indicates the affected environment included systems tied to the FBI’s Virgin Islands operations, where attackers accessed highly sensitive law-enforcement information, including pen register and trap-and-trace returns as well as personally identifiable information connected to active investigations. The bureau said it detected unusual activity in February, informed lawmakers in early March, and publicly acknowledged that the activity had been contained while the investigation continued.

Multiple reports said investigators linked the operation to China, and that the attackers appear to have reached FBI systems through a commercial internet service provider’s vendor infrastructure rather than by directly breaching the bureau first. The incident prompted a broader U.S. government response, with the White House convening officials from the FBI, NSA, and CISA and the Justice Department establishing a working group to strengthen resilience and incident response. The breach was reported as separate from another cyber matter involving the FBI director’s personal email, underscoring that the bureau was confronting several cyber threats at the same time.

Share:
China-Linked Breach Hit FBI Surveillance Network and Exposed Sensitive Case Data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Mar 23, 20263mo ago

White House and DOJ launch coordinated response measures

Following the breach determination, the White House convened officials from the FBI, NSA, and CISA, and the Justice Department formed a working group to improve cyber resilience and incident response. These actions reflected a broader federal response to the intrusion.

Justice Department classifies FBI breach as a major incident

On March 23, the Justice Department determined that the FBI surveillance-system breach met the FISMA threshold for a major incident, signaling significant national security risk. The classification followed reporting that sensitive pen register, trap-and-trace, and personally identifiable information had been exposed.

Mar 5, 20264mo ago

FBI publicly confirms suspicious activity on surveillance network

On March 5-6, 2026, the FBI publicly acknowledged it was investigating suspicious cyber activity targeting a critical surveillance network. Multiple reports described the activity as affecting bureau systems and prompting an active investigation.

Mar 4, 20264mo ago

FBI informs lawmakers of suspicious cyber activity

By March 4, the FBI had notified lawmakers about suspicious activity affecting a critical surveillance network. This marked the incident's escalation from internal detection to formal congressional notification.

Feb 17, 20264mo ago

FBI detects unusual activity on internal surveillance system

The FBI detected unusual activity on one of its internal surveillance systems, later tied in reporting to a China-linked intrusion. The affected environment reportedly included systems in the Virgin Islands and exposed sensitive law-enforcement and investigative data.

Oct 5, 20242y ago

WSJ reports China-linked hack breached telecom wiretap systems

On 2024-10-05, The Wall Street Journal reported that a China-linked intrusion affecting major U.S. broadband providers, including AT&T and Verizon, had potentially accessed systems used to submit and process court-authorized wiretap requests. The report said the attackers may also have accessed broader internet traffic and maintained access for months or longer.

Exclusive | U.S. Wiretap Systems Targeted in China-Linked Hack - WSJ
Feb 17, 20233y ago

FBI contains cyber incident at New York Field Office network

The FBI disclosed that it had contained a cyber incident affecting its computer network at the New York Field Office. Reporting on February 17, 2023 indicates the bureau said the incident was isolated and under control.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

China-Linked Breach Hit FBI Surveillance Network and Exposed Sensitive Case Data | Mallory