FBI Labels China-Linked Hack a Major Cyber Incident Targeting Sensitive Data

A suspected China-linked breach of an FBI-managed surveillance system was formally labeled a “major cyber incident,” a rare designation that signaled hackers likely accessed highly sensitive law enforcement data with implications for U.S. national security and ongoing investigations nbcnews +1. The intrusion, first detected on February 17, targeted an unclassified but “law enforcement sensitive” system that stores surveillance returns and personally identifiable information on FBI investigative subjects politico.
The FBI told lawmakers the attackers broke in by exploiting infrastructure used by a commercial internet service provider’s vendor, effectively turning a private-sector foothold into a doorway into federal systems politico. The White House convened senior officials from the FBI, NSA and CISA in early March to assess the damage, while the bureau said publicly on March 5 it had “identified and addressed suspicious activities” and deployed all available technical capabilities in response hstoday +1.
What Was Breached — And Why It Matters for Investigations
According to a congressional notice described by multiple outlets, the compromised system holds “returns from legal process, such as pen register and trap and trace surveillance returns,” along with other law-enforcement-sensitive records and identifying data politico. That means hackers may have obtained metadata about calls and other communications collected under court orders, potentially revealing who the FBI was targeting, when, and how.
Officials and former agents warned such access could expose investigative methods and enable a foreign intelligence service to map U.S. law enforcement priorities or identify human sources nbcnews +1. One former senior FBI cyber official said China seeks “any information that can help them identify and track their own targets,” adding that intercept data and related metadata would directly advance that goal nbcnews. The full scope of what was accessed has not been made public, and no numbers of affected individuals have been disclosed.
A New Front in the U.S.–China Cyber Confrontation
U.S. investigators assessed the hackers used tactics similar to the 2024 “Salt Typhoon” campaign, in which Chinese state-linked actors infiltrated major telecom and internet providers and siphoned call records and wiretap-related data at massive scale nbcnews +1. That earlier operation touched networks serving hundreds of millions of users and yielded more than a million call records, according to subsequent analysis cisoseries, underscoring how access to telecom and vendor infrastructure can be repurposed against government systems.
The FBI’s decision to invoke the “major incident” label under federal cybersecurity law — a threshold former officials say is reached only a few times a year across government — immediately fed calls in Congress for tougher measures against Chinese cyber operations politico. Some lawmakers and experts urged more aggressive disruption campaigns, sanctions and stricter cybersecurity mandates for telecoms and critical infrastructure, while others cautioned that highly visible retaliation could escalate an already volatile cyber standoff with Beijing and further complicate broader U.S.-China relations cisoseries +1.
The Bigger Picture
The breach deepened a pattern in which Chinese government-linked hackers target the connective tissue of U.S. digital life — telecom backbones, vendors and unclassified but sensitive government systems — to quietly harvest data that can be mined for intelligence over years nbcnews +1. It also sharpened a policy debate in Washington over whether current defenses, reporting rules and deterrence strategies are adequate for an era when adversaries can move from private networks into some of the FBI’s most sensitive investigative tools.
Sources
nbcnews
FBI labels suspected China hack of law enforcement data 'a major cyber incident'
The FBI has labeled a suspected Chinese cyber intrusion into a government surveillance system a “major incident” that poses risks to U.S....
hstoday
FBI Labels China-Linked Hack of Surveillance System a “Major Cyber Incident”
The Federal Bureau of Investigation (FBI) communicated to Congress that a recent cyber intrusion into one of its internal surveillance...
politico
FBI declares suspected Chinese hack of US surveillance system a ‘major cyber incident’
The designation suggests the hackers successfully compromised swathes of sensitive data stored directly on FBI systems.
yahoo
FBI notified Congress last week of China-linked hack deemed 'major incident'
The FBI alerted members of Congress that a Chinese hack is considered a "major incident," a breach that could impact national security,...
cisoseries
New iOS patches over DarkSword, US surveillance hack is major incident, Cisco code stolen in Trivy-linked breach
New iOS patches over DarkSword, FBI: surveillance hack is major incident, Cisco code stolen in Trivy-linked breach. Cybersecurity Headlines.
aol
FBI notified Congress last week of China-linked hack deemed 'major incident'
The FBI alerted members of Congress that a Chinese hack is considered a "major incident," a breach that could impact national security,...
koacolorado
FBI Tells Congress Chinese Hackers Breached Its Systems In 'Major Incident'
A China-linked cyber intrusion into a sensitive agency surveillance system has been designated a "major incident" — a classification that...
ibtimes
Chinese Cyberattack on FBI Systems Reveals Sensitive Surveillance Processes in Ongoing Investigations
The FBI has classified a suspected Chinese cyberattack on its surveillance management system as a 'major incident,' accessing sensitive data...
the420
Suspected Chinese Breach of FBI System Raises National Security Concerns
FBI declares China-linked hack of surveillance system a major incident, raising concerns over compromised sensitive data and national...
politico
White House assisting probe of 'sophisticated' hack into FBI surveillance system
The FBI recently informed Congress it detected suspicious cyber activity on an unclassified system containing “law enforcement sensitive...
staradvertiser
Hacker claims breach of police tip system used nationwide
WASHINGTON >> Law enforcement agencies in Hawaii and across the country are assessing potential risks after a hacker claimed to have...
denver7
Law enforcement agencies reevaluate contracts with CodeRED after data breach
CodeRED is an emergency alert platform used by dozens of Colorado agencies to notify residents about fire evacuations, active shooters,...
vcstar
UPDATED: Ventura County license plate reader system data breach
A flaw in the automated license plate reader system used by most Ventura County law enforcement agencies allowed searches by out-of-state...
healthexec
Maine health system confirms data breach impacted 145K as civil litigation moves forward
The cyberattack on Central Maine Healthcare happened in summer 2025, but the investigation was complicated by the hackers having access to...
wflx
Flock Safety exposed live police camera feeds in internet data breach, company says
Flock Safety says only a small number of Condor cameras were affected, but the exposure still allowed outsiders to view and manipulate...
securityaffairs
Cybercrime group accessed Google Law Enforcement Request System (LERS)
Google found threat actors created a fake account in its Law Enforcement Request System (LERS) and shut it down.
cyberpress
CareCloud Data Breach: Hackers Access IT Systems, Steal Patient Data
The intrusion was first detected on March 16, 2026, when the CareCloud Health division experienced an unexpected network disruption.
hipaajournal
Nebraska AG’s Lawsuit Against Change Healthcare Survives Motion to Dismiss
A lawsuit filed by Nebraska Attorney General Mike Hilgers over the 2024 Change Healthcare data breach has been allowed to proceed after...
thedartmouth
More than 40,000 hit by Dartmouth data breach
Ransomware group Clop exposed birth dates, bank account information and social security numbers using a zero-day vulnerability in Oracle's...
cisoseries
North Korean attackers steal crypto. Who's sending UK phones to China? Avnet confirms data breach
North Korean hackers steal more than $2B in crypto, group suspected of sending stolen UK phones to China, Avnet says stolen data unreadable.
industrialcyber
Jaguar Land Rover cyberattack deepens, with prolonged production outage, supply chain fallout
Jaguar Land Rover (JLR), the U.K.-based automaker owned by Tata Motors, has extended production shutdowns after a cyberattack that disrupted...
therecord
Attackers breach France’s national bank account database
A spokesperson for the French government said potentially 1.2 million accounts were impacted by the incident.
rescana
Allianz Life Data Breach: 1.4 Million U.S. Customers’ Data Compromised via Cloud CRM System
Publication Date: July 26, 2025. On July 26, 2025, Allianz Life publicly confirmed a significant data breach that has impacted the majority...
thehackernews
⚡ Weekly Recap: APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More
Here's what mattered in cybersecurity this week—summarized, sharpened, and signal-boosted.
cfr
Recommendations | Confronting Reality in Cyberspace: Foreign Policy for a Fragmented Internet
The internet today is more fragmented, less free, and more dangerous than it was at its emergence. The threats in cyberspace continue to grow,...
industrialcyber
US Homeland Security Committee warns of rising cyber threats, as federal shutdown and lapsed law hamper defenses
The U.S. House Committee on Homeland Security published an updated 'Cyber Threat Snapshot,' outlining the heightened threats posed by malign...
lawfaremedia
Reconfiguring U.S. Cyber Strategy in the Wake of Salt Typhoon
Persistent penetration of domestic networks makes coordinated defenses and robust deterrence essential to preventing cyber conflict.
coindesk
Bitcoin News: China Accuses U.S. of Stealing 127K BTC in High-Profile Crypto Hack
China's National Computer Virus Emergency Response Center (CVERC) accused the U.S. government of seizing 127,000 stolen bitcoin (worth $13...
csis
How Can the U.S. Government Safeguard Commercial Satellites from Threats?
Though the Founding Fathers could not have anticipated today's global security landscape, they did navigate a complex threat environment...
nextgov
US agencies assessed Chinese telecom hackers likely hit data center and residential internet providers
Data center giant Digital Realty and mass media titan Comcast were documented as likely victims of the Salt Typhoon cyberespionage group,...
washingtonpost
China’s cyber sector amplifies Beijing’s hacking of U.S. targets
Chinese-government hacking attacks against U.S. targets are more serious than ever before, current and former officials said in interviews.
propublica
Microsoft Used China-Based Support for Multiple U.S. Agencies, Potentially Exposing Sensitive Data
Microsoft says it will no longer use China-based engineers to support the Pentagon. But ProPublica found that the tech giant has relied on...
carnegieendowment
Managing the Risks of China’s Access to U.S. Data and Control of Software and Connected Technology
U.S. policymakers need to develop a more systematic and comprehensive framework for managing the data security and influence risks that come...
stimson
Toward Strategic Agility: A Case for South Korea's Evolving and Adaptive Approach to Cybersecurity
An argument for "strategic agility" in South Korea's cybersecurity policy to counter rising breaches and geopolitical uncertainty.
foreignaffairs
China Is Winning the Cyberwar: America Needs a New Strategy of Deterrence
American companies are world leaders in technology—be it innovative software, cloud services, artificial intelligence, or cybersecurity...
tnsr
Hard Then, Harder Now: CoCom’s Lessons and the Challenge of Crafting Effective Export Controls Against China
Will the US-led technology control regime against China have a meaningful impact on the emerging great power competition?
cyfirma
TYPHOON IN THE FIFTH DOMAIN : CHINA’S EVOLVING CYBER STRATEGY
China's cyber operations have evolved from economic espionage to strategic, politically driven campaigns that pose significant threats to...
jsis
U.S.-China Cybersecurity Cooperation
Since the early 2000s, cyber espionage issues have strained U.S.-China relations. In response, the U.S. and China entered into a...
nytimes
Chinese Hackers Are Exploiting Flaws in Widely Used Software, Microsoft Says
The company said state-backed hacking groups were breaching systems through flaws in SharePoint, which is used by the U.S. government and...
carnegieendowment
U.S.-China Technological “Decoupling”: A Strategy and Policy Framework
A partial “decoupling” of U.S. and Chinese technology ecosystems is well underway. Without a clear strategy, Washington risks doing too...
friendsofeurope
The digital battlefield: EU-China cybersecurity diplomacy in the 21st century – Part II
This two-part article examines the potential for strategic cooperation, drawing on the European Union's 'White Paper for European Defence – Readiness 2030'
americasquarterly
U.S. Cybersecurity Diplomacy Is Helping Counter China
A year after AQ's special report on cybersecurity in Latin America, US aid and collaboration are making some headway.
cset
Dakota Cary’s Testimony Before the U.S.-China Economic and Security Commission
CSET Research Analyst Dakota Cary testified before the U.S.-China Economic and Security Review Commission hearing on "China's Cyber...
reuters
US suspects China in breach of FBI surveillance network, WSJ reports
U.S. investigators believe hackers affiliated with the Chinese government are responsible for a cyber intrusion on an internal Federal ...
reuters
FBI 'identified and addressed' suspicious cyber activity on ... - Reuters
The Justice Department referred questions to the FBI. U.S. government networks are routinely targeted by a variety of hackers. In November, ...
Chinese Cyberattack on FBI Systems Reveals Sensitive ... - Facebook
In 2013, Chinese hackers trying to monitor news coverage of China hacked into the Journal's network, apparently aiming to spy on reporters ...
x
The FBI last week decided a recent China-linked cyber intrusion into ...
... FBI last week decided a recent China-linked cyber ... FBI declares suspected Chinese hack of US surveillance system a 'major cyber incident'.
business991
FBI Tells Congress Chinese Hackers Breached Its Systems In 'Major ...
The hack involved FBI systems in the Virgin Islands, not FBI headquarters. The full scope of what was compromised has not been made public.
The FBI is urging Americans to be aware of potential security risks ...
US officials suspect that hackers linked to China may have breached an internal FBI network connected to surveillance systems.
fliegerfaust
FBI Hacked: Every Breach From 2011 to 2026, What They Reveal
FBI Hacked: The Full 15-Year Timeline of Cyber Failures. The hacktivist era: early FBI hack targets from 2011 to 2013. The FBI's cyber ...
threatbeat
FBI declares suspected Chinese hack of U.S. surveillance system a ...
The FBI last week deemed a recent China-linked cyber ... FBI declares suspected Chinese hack of U.S. surveillance system a 'major cyber incident'.
apnews
US charges Chinese hackers in broad cyberespionage campaign
Twelve Chinese nationals — including mercenary hackers, law enforcement officers and employees of a private hacking company — have been charged ...
The FBI has identified a suspected cybersecurity incident on a ...
John Wiley ▻ 2600 - The Hacker Quarterly. 1y · Public · FBI confirms China-backed hackers breached US telecom giants to steal wiretap data. FBI ...
securityboulevard
FBI is Investigating the 'Sophisticated' Hack of Its Surveillance System
March 6, 2026 March 6, 2026 Jeffrey Burt Chinese hackers, cisa, Congress, Data breach, FBI, Hack, internet service providers, Russian ...
cpomagazine
Chinese Hackers Accused of Security Breach Involving FBI ...
These hackers not only accessed sensitive data, but attempted to alter court dockets for cases involving figures from Russia and other Eastern ...
msn
FBI wiretap system hit in suspected China hack - MSN
FBI wiretap system hit in suspected China hack. U.S. officials suspect Chinese state-linked hackers breached an FBI surveillance network ...
chosun
U.S. Attributes FBI Breach to Chinese Government-Linked Hackers
The United States has identified hackers linked to the Chinese government as the perpetrators behind the recent intrusion into the Federal ...
wsj
China Suspected in Breach of FBI Surveillance Network - WSJ
U.S. investigators believe hackers affiliated with the Chinese government are responsible for a cyber intrusion on an internal Federal ...
reuters
China hacked email systems of US congressional committee staffers ...
China hacked email systems of US congressional committee staffers, FT reports ... Jan 7 (Reuters) - A Chinese hacking group has compromised emails ...
BREAKING: FBI officials reached out to members of Congress last ...
US Treasury says it was hacked by China in 'major incident' A Chinese state-sponsored hacker has broken into the US Treasury Department's ...
FBI officials reached out to members of Congress last week to alert ...
Did you know FBI Network Reportedly Hacked? Investigators believe hackers linked to China may have breached an internal system at the Federal ...
foxnews
FBI alerted lawmakers last week about Chinese hack deemed 'major ...
FBI officials recently reached out to members of Congress to alert them to a cyber hack classified as a "major incident.".
reuters
US Treasury says Chinese hackers stole documents in 'major incident'
US Treasury says Chinese state-sponsored hackers stole documents · China says it has always opposed all forms of hacker attacks · Attack follows a ...
reuters
FBI says Chinese hackers preparing to attack US infrastructure
Chinese government-linked hackers have burrowed into US critical infrastructure and are waiting for just the right moment to deal a devastating blow.
politico
FBI declares suspected Chinese hack of US surveillance system a ‘major cyber incident’ The determination suggests the hackers successfully compromised swathes of sensitive data stored directly on FBI systems, likely marking a major counterintelligence coup for China. FISMA requires agencies to tell lawmakers within seven days about any digital intrusion it has determined is “likely to result in demonstrable harm” to U.S. national security. Cynthia Kaiser, the former deputy assistant di...
nbcnews
FBI labels suspected China hack of law enforcement data 'a major cyber incident' The FBI has labeled a suspected Chinese cyber intrusion into a government surveillance system a “major incident” that poses risks to U.S. national security, according to a senior law enforcement official and a source with knowledge of the matter. The hack compromised sensitive information related to domestic law enforcement, the sources said, and the FBI recently informed lawmakers about it. The revelation s...
reuters
FBI 'identified and addressed' suspicious cyber activity on its networks, agency spokesperson says March 5 (Reuters) - The FBI "identified and addressed suspicious activities" on its networks, an agency spokesperson said on Thursday, adding that the bureau had "leveraged all technical capabilities to respond." The spokesperson declined to provide any details as to the nature of the activity, when it was identified or where within the FBI's computer networks. Sign up here. The suspiciou...
politico
White House assisting probe of 'sophisticated' hack into FBI surveillance system The FBI — which first detected suspicious activity on Feb. 17, according to the notice — did not indicate who was responsible for the possible breach but said the hackers’ techniques “appear sophisticated.” The details the FBI shared with Congress and the White House’s outreach to the NSA and CISA suggest the incident could be a significant cybersecurity and counterintelligence concern for the Trump ad...
foreignaffairs
China Is Winning the Cyberwar: America Needs a New Strategy of Deterrence American companies are world leaders in technology—be it innovative software, cloud services, artificial intelligence, or cybersecurity products. Yet beginning as many as three years ago, hackers believed to be backed by the Chinese government did something the United States, the tech powerhouse, could not adequately defend against: they gained and maintained access to major U.S. telecommunications networks, copying con...
lawfaremedia
Reconfiguring U.S. Cyber Strategy in the Wake of Salt Typhoon In a multiyear campaign called Salt Typhoon, threat actors from the People’s Republic of China (PRC) have broken into many major telecom providers, including Verizon, AT&T, and T-Mobile. Collectively, 397.1 million users subscribe to these three telecom providers, indicating that Salt Typhoon could impact hundreds of millions of people. Due to the magnitude of this data breach, Sen. Mark Warner (D-Va.), vice chairman of the Senate ...