Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Federal Bureau of Investigation (FBI)

Federal Bureau of Investigation (FBI) Vendor Cyber Rating & Cyber Score

fbijobs.gov

This is the official Federal Bureau of Investigation (FBI) LinkedIn account and is used to build awareness of workplace culture, engagement opportunities, and the FBI mission. The FBI does not collect comments or messages through this account. The FBI is the premier law enforcement agency in the world. We are an intelligence-driven, outcome-focused national security organization. Steeped in a history of innovation and determination, the Bureau is a collective of individuals united under one unwavering mission: to protect the American people and uphold the U.S. Constitution. The FBI mission guides our efforts and focuses our resources on critical threats, while our core values—respect, integrity, accountability, leadership, compassion,


FBI A.I CyberSecurity Scoring

FBI
Company Information
Website:http://www.fbijobs.gov
Employees number:10,425
Number of followers:963,487
NAICS:92212
Industry Type:Law Enforcement
Homepage:fbijobs.gov
FBI Risk Score (AI oriented)
Between 0 and 549
logo
FBILaw Enforcement
Updated:
28/09/2026
100/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
FBI Global Score (TPRM)
xxxx
logo
FBILaw Enforcement
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

FBICritical
Current Score
100C (CRITICAL)
01000
40 incidents
-44.8 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
100Before Incident
Vulnerability
27 Sep 2026 • FBI
Oracle and Federal Bureau of Investigation: FBI Confirms Breach Probe, FBIJobs.gov Down 5 Days

FBI Investigates Alleged Breach of FBIJobs.gov by ShinyHunters Extortion Group

100After Incident
CRITICAL0
FBIORA1790555191
FBI Investigates Alleged Breach of FBIJobs.gov by ShinyHunters Extortion Group The FBI is probing claims that the notorious extortion group ShinyHunters breached FBIJobs.gov, the bureau’s hiring portal, potentially exposing sensitive personal data of active agents and job applicants. The incident, first reported on September 22, has drawn heightened scrutiny due to the nature of the data at risk home addresses, family details, and identifying records of law enforcement personnel, which could endanger undercover agents and those involved in high-profile investigations. ### Key Details of the Incident - Who: ShinyHunters, a hacking collective with a history of high-profile extortion campaigns in 2026, claimed responsibility. The FBI has not confirmed the breach but acknowledged investigating "unauthorized activity" on FBIJobs.gov. - What: The group alleges it stole data on "almost all FBI agents and applicants," including names, addresses, phone numbers, spouses’ names, and in some cases, medical records. The FBI has not verified these claims or disclosed the scope of any potential exposure. - When: The breach claim surfaced on September 22, five days before initial reporting. The FBI’s investigation remains ongoing, with no confirmed timeline for resolution. - Where: The alleged intrusion targeted FBIJobs.gov, a portal built and hosted with third-party vendors, including potential use of Oracle PeopleSoft HR software and Amazon-hosted government cloud environments. - Why: ShinyHunters framed the attack as retaliation for the FBI’s May 2026 public warning against paying ransom demands a rare escalation where an extortion group targets a law enforcement agency rather than commercial victims. ### Unverified Claims vs. Confirmed Facts While ShinyHunters provided detailed allegations including a zero-day flaw in Oracle PeopleSoft and a pivot into AWS government cloud storage none have been corroborated by the FBI, Oracle, or independent researchers. The FBI’s public statements have been deliberately narrow: - Confirmed: The bureau is investigating unauthorized activity on FBIJobs.gov. - Unconfirmed: The point of breach (third-party vendor vs. FBI systems), the volume of data (e.g., 2TB claims), and the specific records allegedly stolen. ### Potential Impact and Broader Implications - Agent Safety Risks: If verified, the exposure of law enforcement personnel data could enable organized crime networks and hostile state actors to target agents, their families, or undercover operations. - Vendor and Cloud Security Concerns: The incident underscores vulnerabilities in shared government cloud environments and third-party HR software, echoing recent breaches tied to vendor misconfigurations. - Regulatory and Legal Fallout: Unlike corporate breaches, federal agencies face congressional oversight rather than fines. If a third-party vendor is found at fault, it could face contract termination or debarment. - Market Reactions: The claim has already spurred demand for identity protection services and renewed scrutiny of cybersecurity practices among government contractors. ### Historical Context and Comparisons The alleged breach follows a pattern seen in other 2026 incidents, where extortion groups exploit vendor-side flaws rather than direct attacks on hardened government networks. Unlike the 2015 OPM breach a state-sponsored espionage operation this case appears driven by criminal extortion, reflecting a shift in threat tactics. ### Next Steps The FBI is expected to issue further updates within weeks, potentially confirming a limited scope or dismissing the claims. In the meantime, security teams are advised to review PeopleSoft and HR system patching, while affected employees and applicants may take precautionary measures like credit monitoring. The investigation remains fluid, with no official confirmation of the breach’s scale or authenticity.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Retaliation for FBI’s May 2026 public warning against paying ransom demands
IMPACT
Data Compromised: Names, addresses, phone numbers, spouses’ names, medical recordsSystems Affected: FBIJobs.gov, Oracle PeopleSoft, AWS government cloud environmentsOperational Impact: Potential endangerment of undercover agents and high-profile investigationsBrand Reputation Impact: Heightened scrutiny and potential erosion of trust in FBI cybersecurity practicesIdentity Theft Risk: High
DATA BREACH
Personal Identifiable Information (PII)Medical recordsSensitivity Of Data: HighPersonally Identifiable Information: Names, addresses, phone numbers, spouses’ names
SEPTEMBER 2026
100Before Incident
Breach
23 Sep 2026 • FBI
Federal Bureau of Investigation: FBI investigating possible cyber breach of its job application website: Sources

Possible Cyber Breach of FBIjobs.gov

100After Incident
HIGH0
FBI1790195277
FBI Investigates Possible Cyber Breach of FBIjobs.gov The FBI is examining a potential cyber breach of its primary job application portal, FBIjobs.gov, which has served as the central platform for employment applications including for agent and support roles since 2017. According to sources, the agency is assessing the scope of the incident and determining what data may have been compromised, though the number of affected individuals remains unclear. In a brief statement on Tuesday, the FBI acknowledged reports of unauthorized activity on the site, confirming an ongoing investigation. While 404 Media reported that a hacking group claimed responsibility for accessing employee data, these claims have not been independently verified. The FBI continues to evaluate the breach’s impact as the situation develops.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Employee data (potential)Systems Affected: FBIjobs.gov
DATA BREACH
Type Of Data Compromised: Employment application data (potential)
SEPTEMBER 2026
100Before Incident
Cyber Attack
10 Sep 2026 • FBI
FBI: Threat groups enhance cyberattack capabilities with AI

AI-Powered Cyber Threats Escalate as State-Linked and Criminal Groups Adopt Automation

100After Incident
CRITICAL0
FBI1789057420
AI-Powered Cyber Threats Escalate as State-Linked and Criminal Groups Adopt Automation State-sponsored and cybercriminal threat actors are rapidly integrating AI into their attack frameworks, accelerating the speed and scale of cyber operations. According to John Hultquist, chief analyst at Google Threat Intelligence Group (GTIG), AI is now a standard tool across adversary groups, enhancing exploitation, reconnaissance, and social engineering tactics. A China-linked espionage group, tracked as Basin Castle, has developed an AI-assisted automated pipeline using tools like CC Switch to query large language models (LLMs) such as Claude, Gemini, and Codex. The group leverages these models to generate custom exploit scripts, spear-phishing lures, and localized malware, targeting high-value entities particularly government organizations. Similarly, an Iran-nexus group (Calanque Ion) has used generative AI for reconnaissance, language translation, and reverse-engineering software, tailoring attacks to regional languages and specific email targets. Google researchers warn of model-distillation campaigns, where threat actors conduct large-scale automated queries some exceeding 100 million prompts to extract AI model logic, reasoning capabilities, and chain-of-thought processes. Attackers are also deploying proxy infrastructure to bypass security controls, using compromised credentials and fraudulent accounts to execute automated attacks. Additionally, adversaries are targeting proprietary AI models to steal credentials and co-opt cloud environments, further expanding their operational reach. The shift toward agentic AI where AI systems operate with minimal human oversight poses a significant challenge for defenders. FBI officials and cybersecurity experts emphasize that AI is bolstering adversary capabilities, enabling faster vulnerability exploitation and more sophisticated attack methods. While AI adoption among threat actors is still evolving, researchers anticipate it will play an increasingly central role in future cyber campaigns.
INCIDENT DETAILS -
TYPE
EspionageCybercrime
MOTIVATION
EspionageCybercrimeData theft
IMPACT
AI model logicCredentialsProprietary dataCloud environmentsAI modelsOperational Impact: Accelerated cyber operations and enhanced attack sophistication
DATA BREACH
AI model logicCredentialsProprietary dataSensitivity Of Data: HighData Exfiltration: Yes
SEPTEMBER 2026
100Before Incident
Breach
02 Sep 2026 • FBI
FBI: I rented a car, and within hours, my driver’s license was for sale

Dark Web Marketplace Nexus Exposes Over 153 Million Scanned IDs, Including High-Profile Targets

100After Incident
CRITICAL0
FBI1788603918
Dark Web Marketplace Nexus Exposes Over 153 Million Scanned IDs, Including High-Profile Targets A recent investigation by KrebsOnSecurity has uncovered a dark web marketplace called Nexus, which is selling high-resolution scans of over 153 million driver’s licenses and other sensitive IDs including those of journalists, security researchers, and even an FBI assistant director. The breach appears to stem from car rental companies and other organizations that routinely scan customer IDs, with some records traced back to commercial driver’s licenses (CDLs) and Common Access Cards (CACs), used for secure government facility access. The stolen IDs, available for purchase, include multiple image formats standard scans, infrared, and ultraviolet captures likely intended to bypass hologram-based fraud detection. Beyond driver’s licenses, Nexus also offers medical cards, employment authorizations, residence permits, and marijuana dispensary IDs, with one victim confirming their data was linked to a Las Vegas Planet13 dispensary visit. The FBI is actively investigating the breach, which highlights the growing risk of third-party data exposure in industries handling sensitive identification documents. The incident underscores the vulnerabilities in ID verification processes, where scanned documents can be exfiltrated and monetized on underground markets.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial gain
IMPACT
Data Compromised: 153 million scanned IDsBrand Reputation Impact: HighLegal Liabilities: PotentialIdentity Theft Risk: High
DATA BREACH
Driver’s licensesMedical cardsEmployment authorizationsResidence permitsMarijuana dispensary IDsCommercial driver’s licenses (CDLs)Common Access Cards (CACs)Number Of Records Exposed: 153 million+Sensitivity Of Data: High (PII, government access credentials)Data Exfiltration: YesStandard scansInfraredUltravioletPersonally Identifiable Information: Yes
AUGUST 2026
100Before Incident
Cyber Attack
18 Aug 2026 • FBI
FBI and Medusa Ransomware: Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomwar

Medusa Ransomware Surge Targeting Critical Infrastructure Organizations

100After Incident
CRITICAL0
FBIMED1787142272
Medusa Ransomware Surges, Targeting Over 500 Critical Infrastructure Organizations by 2026 The FBI, CISA, and the Department of Health and Human Services issued an updated advisory on August 18, 2026, revealing that the Medusa ransomware-as-a-service (RaaS) operation has compromised over 500 critical infrastructure organizations as of April 2026 a sharp increase from the 300 victims reported in February 2025. The healthcare sector has been particularly hard-hit, with Medusa affiliates aggressively expanding their tactics to enhance initial access and post-exploitation capabilities. First detected in June 2021, Medusa initially operated as a closed ransomware group before shifting to an affiliate model in early 2023. The group is opportunistic, exploiting unpatched vulnerabilities rather than targeting specific industries. Notably, Medusa has accelerated its attack timeline, leveraging exploits within 24 hours of public disclosure and in some cases, up to a week before vulnerabilities are publicly known. While the group does not develop its own zero-days, its rapid exploitation has created significant challenges for defenders, as security teams struggle to patch systems before attacks occur. ### Evolving Tactics: Stealth, Lateral Movement, and Credential Theft Medusa has refined its post-exploitation techniques to evade detection and move laterally within networks. Key developments include: - PowerShell obfuscation to hide payloads and delete command-line history. - Legitimate remote monitoring tools (RMM) to blend into victim environments and bypass firewalls. - Nezha and GSocket for command-and-control (C2) operations, enabling backdoor access to compromised hosts. - Mimikatz to harvest credentials, including plaintext passwords from the LSA authentication mechanism, and steal Active Directory files to forge Kerberos tickets allowing attackers to impersonate trusted users and escalate privileges. ### Double Extortion and Data Exfiltration Medusa employs a double-extortion model, encrypting systems while exfiltrating sensitive data. Attackers use: - Bandizip to archive stolen files. - Rclone (renamed to evade detection) to transfer data to Medusa’s C2 servers via SFTP. - Secure file transfer to deploy the encryptor, which appends a .medusa extension, terminates services, and deletes shadow copies before dropping a ransom note. Victims are given 48 hours to respond, with attackers often following up via phone or email if no contact is made. Ransom demands are posted on Medusa’s leak site, with cryptocurrency payment links provided. The advisory underscores Medusa’s growing sophistication, blending legitimate tools with advanced credential theft and persistence techniques making detection and mitigation increasingly difficult for security teams.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData exfiltration for extortion
IMPACT
Data Compromised: Sensitive data exfiltrated (type unspecified)Systems Affected: Over 500 critical infrastructure organizations (primarily healthcare)Operational Impact: System encryption, service termination, and shadow copy deletionIdentity Theft Risk: High (due to credential theft and PII exposure)
DATA BREACH
Personally Identifiable Information (PII)Active Directory filesCredentialsSensitivity Of Data: High (credentials, PII, and sensitive organizational data)
JULY 2026
100Before Incident
Cyber Attack
26 Jul 2026 • FBI
FBI: Minnesota water systems hit with cyberattack, state officials say

Cyberattack Targets Over 30 Minnesota Water Systems

100After Incident
CRITICAL0
FBI1785270231
Cyberattack Targets Over 30 Minnesota Water Systems State officials confirmed that more than 30 water systems across Minnesota were hit by a cyberattack over the weekend. The incidents, detected on Sunday and Monday, prompted an investigation led by Minnesota IT (MNIT) Services, though no disruptions to drinking water safety were reported. Authorities have not released specific details about the attack or the affected utilities. MNIT Assistant Commissioner and Chief Information Security Officer John Israel stated that the agency is collaborating with federal and state partners, including the FBI, to assess the breach, support impacted communities, and bolster defenses against future threats. The investigation remains ongoing as officials work to restore operations and determine the full scope of the incident.
INCIDENT DETAILS -
TYPE
Cyberattack
IMPACT
Systems Affected: Water systemsOperational Impact: Investigation and restoration efforts underway
JUNE 2026
100Before Incident
Breach
01 Jun 2026 • FBI
Huntress and FBI: Huntress CEO says threat hunter used 'poor judgment' in alerting ransomware crim about law enforcement probe

Huntress Investigates Alleged Insider Threat After Employee Shared FBI Intel with Ransomware Operator

100After Incident
CRITICAL0
FBIHUN1782843828
Huntress Investigates Alleged Insider Threat After Employee Shared FBI Intel with Ransomware Operator Huntress CEO Kyle Hanslovan has acknowledged "questionable" communications between a current threat hunter at the cybersecurity firm and a cybercriminal, describing the exchanges as a lapse in judgment. The incident surfaced after former Huntress analyst Ben Folland accused the employee of acting as an insider threat by allegedly sharing law enforcement details with Devman, a ransomware operator linked to Russia. According to Hanslovan’s blog post, the employee disclosed to Devman that U.S. law enforcement had contacted them about the threat actor. While Hanslovan stated the disclosure was not illegal, he called it "poor judgment" and denied that it constituted insider activity. Huntress has since implemented stricter policies for researcher interactions with threat actors and taken administrative actions, though no evidence of illegal conduct or further disclosures was found. Folland, however, disputes this characterization. In a LinkedIn post, he claimed the employee forwarded FBI communications including agent names to Devman, warning the ransomware operator of an active investigation. He also alleged the employee refused to cooperate with law enforcement, a claim the FBI reportedly confirmed to Folland. Folland argued the actions went beyond poor judgment, equating them to an insider tipping off a criminal under investigation. Devman, known for using modified DragonForce ransomware built on leaked Conti source code, has been publicly targeting Folland and his family. The FBI has not responded to requests for comment, and Huntress has declined further statements. The dispute highlights tensions over ethical boundaries in threat intelligence, with Huntress maintaining the employee’s actions were not malicious, while Folland insists they meet the definition of an insider threat. The investigation remains ongoing.
INCIDENT DETAILS -
TYPE
Insider Threat
MOTIVATION
Tipping off a criminal under investigation
IMPACT
Data Compromised: FBI communications, agent namesOperational Impact: Stricter internal policies implementedBrand Reputation Impact: Potential reputational damage due to insider threat allegations
DATA BREACH
Type Of Data Compromised: Law enforcement communications, agent namesSensitivity Of Data: High (FBI investigation details)Personally Identifiable Information: Agent names
MAY 2026
100Before Incident
Cyber Attack
16 May 2026 • FBI
FBI and Cybersecurity and Infrastructure Security Agency: Cyber attack hits US gas stations, officials suspect Iran

U.S. Investigates Iranian-Linked Cyberattacks on Fuel Monitoring Systems

100After Incident
CRITICAL0
FBIOFF1778905426
U.S. Investigates Iranian-Linked Cyberattacks on Fuel Monitoring Systems U.S. cybersecurity officials are probing a series of breaches targeting automatic tank gauge (ATG) systems used to monitor fuel levels at gas stations with early indications pointing to Iranian-linked hackers. The attacks exploited poorly secured systems left exposed online without password protection, allowing threat actors to access and manipulate display readings in some cases. However, investigators confirmed that actual fuel quantities in storage tanks remained unaffected, and no physical damage or leaks have been reported. While the immediate impact appears limited, experts warn that unauthorized access to ATG systems could enable attackers to mask real fuel leaks or disrupt monitoring operations, raising concerns about vulnerabilities in U.S. critical infrastructure, particularly within the oil and gas sector. The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have not publicly attributed the attacks, though U.S. officials suspect Iranian involvement based on past incidents targeting similar systems, including water utilities and energy networks. The incident underscores growing risks to internet-connected industrial systems, which researchers have long flagged as poorly secured and prime targets for cyber threats. Iran-linked groups have previously been linked to disruptions of U.S. companies and government systems, with recent activity showing increased sophistication amid heightened geopolitical tensions involving Iran, the U.S., and Israel. The attacks align with a broader pattern of escalating cyber operations, including phishing campaigns, data leaks, and infrastructure-focused disruptions.
INCIDENT DETAILS -
TYPE
Cyberattack
MOTIVATION
Disruption of monitoring operations, potential masking of fuel leaks
IMPACT
Systems Affected: Automatic tank gauge (ATG) systems at gas stationsOperational Impact: Manipulation of display readings, potential disruption of monitoring operations
MAY 2026
100Before Incident
Vulnerability
15 May 2026 • FBI
Oracle and Federal Bureau of Investigation: ShinyHunters claims FBI hack: 'This is NOT financially motivated'

ShinyHunters Claims FBI Breach, Steals 2+ TB of Employee Data in Unusual Extortion Demand

100After Incident
CRITICAL0
FBIORA1790101489
ShinyHunters Claims FBI Breach, Steals 2+ TB of Employee Data in Unusual Extortion Demand The hacking group ShinyHunters has alleged it breached the FBI, stealing 2 to 3 terabytes of data belonging to current, former, and prospective employees. Unlike typical financially motivated attacks, the group claims its actions are a response to what it calls false allegations made by the FBI in a May 15 bulletin. According to a ShinyHunters spokesperson, the breach began with the exploitation of an Oracle PeopleSoft zero-day vulnerability on the FBI’s jobs webpage, enabling remote code execution (RCE). The group defaced the site, replacing it with a seizure notice, and later moved laterally into the FBI’s AWS GovCloud-managed servers, accessing sensitive systems including human resources, MedLink, and Criminal Justice Information Services. ShinyHunters asserts the stolen data includes employee and applicant records but insists it is not seeking a ransom. Instead, the group demands the FBI retract or correct statements from its May bulletin, which accused ShinyHunters of harassment tactics, including threatening messages, swatting, and false claims of possessing compromising material. The group denies these allegations, framing the breach as a direct rebuttal. As of publication, the FBI jobs site remains offline for maintenance, while Oracle and AWS have not responded to inquiries about the alleged zero-day or the breach. The FBI has not yet commented on the claims.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Retaliation against FBI allegations
IMPACT
Data Compromised: 2-3 TB of employee and applicant dataFBI jobs webpageAWS GovCloud-managed serversHuman ResourcesMedLinkCriminal Justice Information ServicesDowntime: FBI jobs site remains offline for maintenanceIdentity Theft Risk: High (employee and applicant records)
DATA BREACH
Type Of Data Compromised: Employee and applicant recordsSensitivity Of Data: High (personally identifiable information, internal systems data)Data Exfiltration: Yes (2-3 TB of data stolen)Personally Identifiable Information: Yes
MAY 2026
100Before Incident
Cyber Attack
05 May 2026 • FBI
FBI: FBI warns cyber-enabled cargo theft is surging as losses hit $725 million in 2025

FBI Warns of Surging Cyber-Enabled Cargo Theft

100After Incident
CRITICAL0
FBI1779517614
FBI Warns of Surging Cyber-Enabled Cargo Theft, Losses Hit $725 Million in 2025 The FBI has issued a public alert warning of a sharp rise in cyber-enabled strategic cargo theft, with threat actors impersonating brokers and carriers to hijack and resell high-value shipments. In 2025, losses in the U.S. and Canada reached nearly $725 million a 60% year-over-year increase while confirmed incidents rose 18%, with the average theft value climbing 36% to $273,990. Attackers gain access to logistics systems through phishing, spoofed emails, and compromised carrier accounts, then manipulate load boards by posting fraudulent listings or altering legitimate shipments. Once inside, they hijack identities, double-broker loads, and modify critical documents such as bills of lading and delivery addresses to reroute cargo. Some schemes culminate in ransom demands after shipments vanish. The FBI detailed a multi-step operation, where threat actors first deploy remote access tools via malicious links, then flood load boards with fake listings while bidding on real shipments using stolen credentials. They sustain deception by altering carrier contact and insurance details, delaying detection until goods are stolen and resold. Key warning signs include unauthorized shipment notifications, spoofed emails with slight domain variations, and requests to download documents from suspicious links. Compromised accounts may show unusual mailbox rules, such as auto-forwarding or hidden folders, while attackers often use short-lived VoIP numbers for communication. The alert underscores the growing sophistication of cyber-enabled cargo theft, targeting transportation and logistics sectors with high-value, selective attacks.
INCIDENT DETAILS -
TYPE
Cyber-Enabled Cargo Theft
MOTIVATION
Financial gainResale of high-value shipments
IMPACT
Financial Loss: $725 million (2025, U.S. and Canada)Logistics systemsLoad boardsOperational Impact: Unauthorized rerouting of shipments, identity hijacking, double-brokering of loadsIdentity Theft Risk: High (identity hijacking of brokers/carriers)
DATA BREACH
Carrier credentialsShipment detailsBills of ladingDelivery addressesSensitivity Of Data: High (logistics and shipment data)
APRIL 2026
100Before Incident
Breach
22 Apr 2026 • FBI
Agoda, Booking.com and Booking Holdings: Agoda refutes claims of massive data breach

Agoda Denies Data Breach as Cybercriminals Claim Theft of 82 Million Records

100After Incident
CRITICAL0
AGOBOO1776904233
Agoda Denies Data Breach as Cybercriminals Claim Theft of 82 Million Records Asia-based travel booking platform Agoda has refuted claims of a data breach after cybercriminals alleged the theft of 82 million user records. An Agoda spokesperson stated that internal investigations confirmed the leaked data did not originate from its systems. Researchers at Cybernews analyzed a sample of 23 records provided by the attackers, which included sensitive details such as full names, identity card numbers, phone numbers, email addresses, and hotel addresses primarily linked to Malaysian users. Notably, the sample lacked reservation dates, an unusual omission that raised questions about the data’s origin. Despite this, the researchers verified the legitimacy of the exposed information. The incident follows a recent confirmation by Agoda’s parent company, Booking Holdings, of a separate breach affecting Booking.com users. That attack exposed names, phone numbers, email addresses, and reservation details, leading to a surge in reservation hijacking scams across North America, Europe, and the UK. The timing of the two incidents has heightened concerns about cybersecurity risks in the travel industry.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: 82 million records allegedly stolenBrand Reputation Impact: Potential reputational damage due to breach claimsIdentity Theft Risk: High (exposure of full names, identity card numbers, phone numbers, email addresses)
DATA BREACH
Full namesIdentity card numbersPhone numbersEmail addressesHotel addressesNumber Of Records Exposed: 82 million (alleged)Sensitivity Of Data: High (personally identifiable information)Data Exfiltration: Claimed by cybercriminalsPersonally Identifiable Information: Yes
APRIL 2026
100Before Incident
Cyber Attack
07 Apr 2026 • FBI
FBI: FBI says cybercrime losses hit record $20.87B in 2025

FBI Reports Record $20.87 Billion in Cybercrime Losses for 2025, Driven by AI-Enhanced Scams

100After Incident
CRITICAL0
FBI1776097914
FBI Reports Record $20.87 Billion in Cybercrime Losses for 2025, Driven by AI-Enhanced Scams The FBI’s 2025 Internet Crime Report revealed a historic surge in cybercrime, with reported losses reaching $20.87 billion the first time losses exceeded $20 billion. Complaints submitted to the Internet Crime Complaint Center (IC3) surpassed one million, a 17% increase from 2024. Top Threats & Financial Impact Phishing remained the most reported crime (191,561 complaints), but investment scams caused the highest losses ($8.6 billion), followed by business email compromise (BEC) and tech support scams. Cyber-enabled fraud using digital tools to execute traditional scams accounted for 45% of complaints but 85% of financial losses. Meanwhile, classic cyber threats like ransomware and data breaches made up 75% of reported incidents. AI’s Growing Role in Cybercrime For the first time, the IC3 included an AI-focused section, highlighting its use in 22,364 complaints and $893 million in losses though the FBI cautioned that actual figures may be higher due to underreporting. Key AI-driven schemes included: - BEC attacks (high financial losses, despite fewer AI-specific reports) - Romance/confidence scams (fake profiles, voice cloning) - Employment fraud (deepfake interviews, forged documents) - Investment cons (AI-generated videos impersonating public figures) Complaints for these scams spiked significantly from 2023 to 2025, with corresponding increases in financial losses. Government Impersonation Scams Surge One notable outlier was government impersonation scams, which saw a 128% increase in complaints (from 14,190 in 2023 to 32,424 in 2025). The FBI previously warned of AI-generated voice and text messages mimicking senior U.S. officials to target government personnel and contacts. The report underscores how cybercriminals are leveraging AI to refine traditional scams, making them more profitable and harder to detect. While AI-related losses remain a fraction of the total, their rapid growth signals a shifting threat landscape.
INCIDENT DETAILS -
TYPE
phishinginvestment scamsbusiness email compromise (BEC)tech support scamsransomwaredata breachesgovernment impersonation scams
MOTIVATION
financial gainfraud
IMPACT
Financial Loss: $20.87 billionCustomer Complaints: 1,000,000+ complaints
Vulnerability
07 Apr 2026 • FBI
Rockwell Automation: U.S. Cybersecurity Agencies Warn of Rising Threats From Exposed Rockwell Automation PLCs

Thousands of Rockwell PLCs Exposed Online, Drawing Warnings from U.S. Agencies

100After Incident
CRITICAL0
ROC1776083482
Thousands of Rockwell PLCs Exposed Online, Drawing Warnings from U.S. Agencies Researchers at Censys have identified 5,219 Rockwell Automation programmable logic controllers (PLCs) accessible via the internet, with a significant concentration in the United States, heightening risks to critical infrastructure. The exposure of these operational technology (OT) devices has raised concerns about exploitation by advanced persistent threat (APT) groups, particularly those linked to Iran. On April 7, 2026, the FBI, CISA, and NSA issued a joint advisory warning of active targeting by Iran-backed threat actors. The agencies emphasized the urgency of securing these systems, noting that such groups have historically sought to disrupt, gather intelligence, or demonstrate offensive capabilities against vulnerable OT environments. The advisory recommends immediate disconnection of internet-facing PLCs where possible, alongside network segmentation, multi-factor authentication, and timely patching for cases where disconnection isn’t feasible. Additional measures include intrusion detection systems, behavioral analytics, and enhanced monitoring to detect unauthorized activity. Exposed devices span energy, manufacturing, and water systems, sectors where a successful compromise could have severe economic and public safety consequences. The agencies stressed that operators must act swiftly to reduce the attack surface, as threat actors continue to scan for and exploit unsecured industrial systems at scale.
INCIDENT DETAILS -
TYPE
Exposure of Critical Infrastructure
MOTIVATION
DisruptionIntelligence gatheringDemonstration of offensive capabilities
IMPACT
Systems Affected: 5,219 Rockwell Automation PLCsOperational Impact: Potential severe economic and public safety consequences
MARCH 2026
100Before Incident
Breach
21 Mar 2026 • FBI
U.S. Federal Bureau of Investigation: Pro-Iranian hackers expose FBI Director’s personal data in security breach

Pro-Iranian Hackers Leak Alleged Private Documents of FBI Official Kash Patel

100After Incident
CRITICAL0
FBI1774672716
Pro-Iranian Hackers Leak Alleged Private Documents of FBI Official Kash Patel A pro-Iranian hacking group, Handala Hack, has released purported private documents and images of Kash Patel, a director at the U.S. Federal Bureau of Investigation (FBI). The leak was confirmed by Department of Justice (DOJ) sources to Fox News, though officials have not verified the authenticity of the circulating photos. The group published a statement on its newly launched website, declaring the incident as proof of the "collapse of American security legends." This retaliation comes just one week after the DOJ seized two web domains linked to Handala Hack as part of a broader operation targeting Iranian-backed cyberattacks, transnational repression, and psychological operations. Handala Hack framed the breach as a direct response to what it called the FBI’s "ridiculous spectacle" of recent countermeasures. The group claims its team penetrated the FBI’s "impenetrable" systems within hours, making Patel’s emails, conversations, documents, and classified files publicly available for download. The hackers asserted the attack would be "etched forever in memory." The incident underscores escalating cyber tensions between Iranian-linked threat actors and U.S. law enforcement, following recent disruptions of the group’s infrastructure.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Retaliation for DOJ's seizure of web domains linked to Iranian-backed cyberattacks
IMPACT
Data Compromised: Emails, conversations, documents, classified filesSystems Affected: FBI systemsBrand Reputation Impact: Undermined confidence in FBI's securityIdentity Theft Risk: High (for affected individual)
DATA BREACH
EmailsConversationsDocumentsClassified filesSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
MARCH 2026
100Before Incident
Breach
05 Mar 2026 • FBI
FBI, Verizon, AT&T, U.S. Treasury, Lumen and Windstream: FBI investigating hack on its wiretap and surveillance systems: Report

FBI Network Breach Targets Surveillance Systems

100After Incident
CRITICAL0
LUMATTVERFBIWINFIN1772764213
FBI Network Breach Targets Surveillance Systems Hackers have reportedly compromised an FBI network used to manage wiretaps and foreign intelligence surveillance warrants, according to a CNN report citing an anonymous source. The breach was confirmed by an FBI spokesperson, who stated that the bureau detected and addressed "suspicious activities" on its systems, though no further details were provided. The incident marks the latest in a string of high-profile cyberattacks on U.S. government agencies and corporations. Last year, Chinese hackers infiltrated the U.S. Treasury and the National Nuclear Security Administration, while Russian operatives stole sealed court records. Separately, a Chinese state-linked group, Salt Typhoon, breached at least 200 U.S. companies, including major telecommunications providers like AT&T, Verizon, Lumen, Charter Communications, and Windstream. The FBI has not disclosed the extent of the breach or the identity of the attackers, but the incident underscores ongoing cybersecurity threats to critical U.S. infrastructure.
INCIDENT DETAILS -
TYPE
Network Breach
IMPACT
Data Compromised: Wiretaps and foreign intelligence surveillance warrantsSystems Affected: FBI network managing surveillance systems
DATA BREACH
Type Of Data Compromised: Wiretaps and foreign intelligence surveillance warrantsSensitivity Of Data: High
MARCH 2026
100Before Incident
Breach
01 Mar 2026 • FBI
Federal Bureau of Investigation: Iran-linked hackers claim breach of FBI drone program, threaten World Cup security

Iran-Linked Hacking Group Claims Breach of FBI Drones Ahead of 2026 World Cup

100After Incident
CRITICAL0
FBI1781282098
Iran-Linked Hacking Group Claims Breach of FBI Drones Ahead of 2026 World Cup An Iran-affiliated hacking group, Handala, has claimed it breached FBI-operated first-person view (FPV) drones, gaining access to sensitive data collected over months, including images and intelligence from counterterrorism operations. According to the SITE Intelligence Group, the group alleged the drones were equipped with facial recognition and license plate-reading technology. In a statement, Handala issued a veiled threat tied to the 2026 FIFA World Cup, warning, “Better tighten your World Cup security… FPVs are everywhere; you never know when one might end up right in your team’s bus.” The FBI has confirmed drones will be deployed for security at World Cup venues, though unauthorized flights are prohibited near stadiums and fan zones. The tournament’s matches began on June 11. SITE cast doubt on Handala’s claims, noting that at least one video presented as evidence appeared to be unrelated 2024 footage of U.S. police drone software used after tornado damage. The group has a history of making unverified assertions, including a March claim that it hacked an FBI official’s email account. The incident follows broader warnings from U.S. officials about Iranian cyber threats, particularly after recent U.S. and Israeli strikes on Tehran. The State Department has offered a $10 million reward for information leading to the identification of Handala members.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Geopolitical, Threat to 2026 World Cup security
IMPACT
Data Compromised: Sensitive images and intelligence from counterterrorism operations, facial recognition data, license plate-reading dataSystems Affected: FBI-operated FPV dronesOperational Impact: Potential compromise of counterterrorism operations and World Cup securityBrand Reputation Impact: Potential reputational damage to FBI and U.S. security agenciesIdentity Theft Risk: High (facial recognition and license plate data)
DATA BREACH
Type Of Data Compromised: Images, intelligence data, facial recognition data, license plate-reading dataSensitivity Of Data: HighPersonally Identifiable Information: Yes (facial recognition and license plate data)
Cyber Attack
01 Mar 2026 • FBI
Federal Bureau of Investigation: FBI declares suspected Chinese hack of US surveillance system a ‘major cyber incident’

FBI Cyber Incident Linked to Chinese Hackers

100After Incident
CRITICAL0
FBI1775075315
FBI Confirms Major Cyber Incident Linked to Chinese Hackers The FBI recently notified Congress of a significant cyber intrusion under the Federal Information Security Modernization Act (FISMA), marking a rare declaration of a "major incident" involving its own systems. The breach, attributed to sophisticated hackers likely backed by China, compromised sensitive data, including legal surveillance returns such as pen register and trap-and-trace records and personally identifiable information tied to FBI investigations. The attack exploited a commercial internet service provider’s vendor infrastructure, demonstrating advanced tactics. While the exact trigger for the FISMA designation remains unclear, such incidents typically involve the exfiltration of data posing acute risks to national security, foreign relations, or public confidence. Former FBI cyber division official Cynthia Kaiser noted that the bureau has not reported a major incident of this scale since at least 2020, underscoring the severity of the breach. Pen register and trap-and-trace tools, which track call and internet activity without capturing content, are highly valuable to foreign intelligence services, as they could reveal FBI surveillance targets. The incident appears unrelated to a recent Iranian-linked compromise of FBI Director Kash Patel’s emails but aligns with China’s escalating cyber operations against U.S. national security systems. Sen. Mark Warner (D-Va.), chair of the Senate Intelligence Committee, described the breach as a stark reminder of China’s growing cyber aggression. Under FISMA, the declaration should trigger an interagency response, though it remains unclear whether containment efforts have been successful. The White House convened a meeting in early March with officials from the FBI, NSA, and CISA to address the breach. Chinese hackers have increasingly targeted commercial communications providers as entry points into federal networks, with recent campaigns such as those by groups like Volt Typhoon and Salt Typhoon compromising critical infrastructure and telecommunications providers, including the theft of call records and FBI wiretap data. While U.S. officials believe the FBI acted swiftly to mitigate the incident, the breach highlights persistent vulnerabilities in even the most secure systems. The attack serves as a reminder of the relentless threat posed by state-backed cyber adversaries.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Espionage, national security compromise
IMPACT
Data Compromised: Legal surveillance returns (pen register and trap-and-trace records), personally identifiable information tied to FBI investigationsSystems Affected: FBI systemsOperational Impact: Compromise of sensitive surveillance dataBrand Reputation Impact: Potential erosion of public confidenceIdentity Theft Risk: High (personally identifiable information exposed)
DATA BREACH
Legal surveillance dataPersonally identifiable informationSensitivity Of Data: High (national security implications)Data Exfiltration: Likely (implied by 'exfiltration of data posing acute risks')Personally Identifiable Information: Yes
FEBRUARY 2026
100Before Incident
Cyber Attack
17 Feb 2026 • FBI
AT&T, Verizon and Federal Bureau of Investigation: FBI is Investigating the ‘Sophisticated’ Hack of Its Surveillance System

FBI Investigates Sophisticated Breach of Surveillance System Holding Sensitive Law Enforcement Data

100After Incident
CRITICAL0
FBIATTVER1772836650
FBI Investigates Sophisticated Breach of Surveillance System Holding Sensitive Law Enforcement Data The FBI, alongside agencies including CISA and the NSA, is probing a cyber intrusion into the Digital Collection System Network (DCSNet), an unclassified but highly sensitive surveillance platform used to store law enforcement data. The breach was first detected on February 17, with the FBI notifying Congress this week after identifying unusual activity linked to the system. DCSNet contains legal process returns such as pen register and trap-and-trace data along with personally identifiable information (PII) on subjects of FBI investigations. Pen registers, which log dialed phone numbers, were among the compromised records. The attacker employed advanced techniques, including leveraging a commercial ISP’s infrastructure, to bypass security controls, a tactic increasingly used by nation-state threat actors. While the FBI has not disclosed the attacker’s identity, the incident aligns with recent campaigns by Chinese and Russian hacking groups, which have targeted U.S. government and telecom networks via ISP compromises. Notably, China-linked group Salt Typhoon breached major telecom providers including Verizon, AT&T, and Lumen Technologies in 2024, raising concerns about supply-chain infiltration. The breach occurs amid heightened cyber tensions, including Iran-backed hacking activity following U.S.-Israeli airstrikes on February 28. However, most Iranian cyber operations have focused on Middle Eastern and European targets rather than the U.S. The investigation also unfolds against a backdrop of staffing cuts at key cybersecurity agencies, with the FBI dismissing nearly two dozen employees many in cyber and counterintelligence roles just days before the Iran strikes. Security experts warn the breach underscores the risks of institutional knowledge loss. Damon Small of Xcape described the incident as a "catastrophic vulnerability window" created by the departure of experienced defenders, leaving critical systems exposed. The FBI has not released further details, but the involvement of the White House, NSA, and Justice Department signals the severity of the compromise.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Espionage
IMPACT
Data Compromised: Pen register and trap-and-trace data, personally identifiable information (PII)Systems Affected: Digital Collection System Network (DCSNet)Operational Impact: Compromise of sensitive law enforcement surveillance dataBrand Reputation Impact: HighIdentity Theft Risk: High
DATA BREACH
Pen register dataTrap-and-trace dataPersonally identifiable information (PII)Sensitivity Of Data: HighPersonally Identifiable Information: Yes
FEBRUARY 2026
146Before Incident
Breach
04 Feb 2026 • FBI
Social Security Administration: The Social Security data breach is a national-security disaster that could hurt Americans for the rest of their lives: whistleblower

Potential Massive Social Security Data Breach

100After Incident
CRITICAL-46
SOC1770609457
Former SSA Chief Data Officer Warns of Massive Social Security Data Breach A whistleblower has raised alarms over a potential national security disaster involving the exposure of sensitive Social Security data for every American with or who ever had a Social Security number (SSN). Chuck Borges, the former chief data officer of the Social Security Administration (SSA), resigned in August and filed a complaint alleging that employees of the Department of Government Efficiency (DOGE) uploaded a copy of the SSA’s database to an unsecured cloud environment. According to Borges, the breach if confirmed could leave personal data, including names, SSNs, and addresses, vulnerable to fraud and exploitation, with long-term consequences for millions of Americans. He has called for a congressional investigation into the alleged mismanagement, framing the incident as a severe threat to national security. The SSA has not publicly confirmed the breach, but the whistleblower’s claims highlight critical vulnerabilities in government data handling. If verified, the exposure could have far-reaching implications for identity theft, financial fraud, and cybersecurity risks across the U.S. The incident underscores ongoing concerns about federal agencies’ ability to safeguard sensitive citizen data.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Names, SSNs, AddressesSystems Affected: SSA DatabaseBrand Reputation Impact: SevereLegal Liabilities: PotentialIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII)Number Of Records Exposed: Potentially all Americans with an SSNSensitivity Of Data: HighPersonally Identifiable Information: Names, SSNs, Addresses
FEBRUARY 2026
229Before Incident
Breach
01 Feb 2026 • FBI
FBI, U.S. water and wastewater utilities, U.S. Department of the Treasury and Defense contractors: U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

Operation Economic Outcast: U.S. Treasury Sanctions Iranian Cyber Actors

145After Incident
CRITICAL-84
FBIOFFUS-CEN1787682734
U.S. Treasury Imposes Sweeping Sanctions on Iranian Cyber Actors in "Operation Economic Outcast" The U.S. Department of the Treasury has unveiled a new wave of sanctions targeting Iranian cyber actors as part of Operation Economic Outcast, an aggressive campaign to dismantle the financial networks sustaining Iran’s regime and its Islamic Revolutionary Guard Corps (IRGC). Announced by Treasury Secretary Scott Bessent, the initiative aims to sever Iran’s economic lifelines, including those supporting its cyber operations, nuclear programs, missile development, and oil trade. At the center of the sanctions are nearly 60 Iran-linked entities, individuals, and vessels, with a particular focus on a cyber group tied to Iran’s Ministry of Intelligence and Security (MOIS). This group has been responsible for extensive breaches of U.S. critical infrastructure, including energy companies, defense contractors, healthcare institutions, and financial firms since late 2023. The Treasury alleges that while these actors conduct cyber espionage on behalf of MOIS, some prioritize personal financial gain, even targeting Iranian companies for profit. Five individuals from the Tehran-based Mabna Institute Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda'i, Mojtaba Ghal'eh-Kuhi, and Arman Kahzadian were indicted by the U.S. Justice Department for their roles in these operations. Their activities include data exfiltration from U.S. government offices in summer 2024 and cryptocurrency theft, with blockchain analytics firm TRM Labs estimating that the group has received nearly $17 million across 30 wallets since 2018. Keyvan Fayyaz Ghareh Blagh alone accounts for 92% of the network’s on-chain volume, while Arman Kahzadian is linked to a 2023 Bitcoin heist worth over $30,000. The sanctions also target Zedcex and Zedxion, two U.K.-based front companies accused of processing $1 billion in funds for the IRGC. TRM Labs describes the operation as an effort to isolate Iran’s regime both financially and in the digital assets space, warning that secondary sanctions will pressure global entities still engaging with Iran. In parallel, the U.S. State Department’s Rewards for Justice program is offering up to $10 million for information on foreign-directed cyber threats to critical infrastructure. Iranian cyber activities have escalated since February 2026, following U.S. and Israeli airstrikes, with attacks including the breach of FBI Director Kash Patel’s personal email and disruptions to over 30 U.S. water and wastewater utilities. Suspected Iranian hackers also caused a four-day shutdown of a small U.K. power plant last month, though officials assured no broader energy risks emerged. Security firm SentinelOne characterizes Iran’s cyber operations as a multi-pronged threat, blending data theft, destructive attacks, social engineering, and opportunistic targeting of exposed operational technology. Meanwhile, a decentralized network of pro-Iran hacktivist groups operating via Telegram and DDoS-for-hire tools has amplified propaganda and psychological pressure campaigns, often timed with kinetic military actions. While technically unsophisticated, these efforts leverage speed and visibility to shape narratives in Western media. The Treasury’s sanctions mark a significant escalation in the U.S. government’s efforts to counter Iran’s cyber and financial networks, signaling a broader strategy to isolate the regime through economic and digital means.
INCIDENT DETAILS -
TYPE
Cyber EspionageData ExfiltrationRansomwareCryptocurrency Theft
MOTIVATION
State-sponsored espionageFinancial gainDisruption of critical infrastructurePropaganda
IMPACT
Financial Loss: $17 million (cryptocurrency theft)Data Compromised: Government data, corporate data, personally identifiable informationEnergy companiesDefense contractorsHealthcare institutionsFinancial firmsWater and wastewater utilitiesPower plantsDowntime: Four-day shutdown of a U.K. power plantOperational Impact: Disruptions to critical infrastructure, including water and wastewater utilitiesIdentity Theft Risk: High (personally identifiable information exposed)
DATA BREACH
Government dataCorporate dataPersonally identifiable informationSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
JANUARY 2026
235Before Incident
Cyber Attack
05 Jan 2026 • FBI
FBI, CISA, U.S. Department of Homeland Security and Defense Department's Cyber Crime Center: US Homeland Security warns of escalating Iranian cyberattack risks

DHS Warning of Escalating Cyberattack Risks by Iran-Backed Hacking Groups

219After Incident
CRITICAL-16
FBICISUS-UNI1767786135
DHS Warns of Escalating Cyber Threats from Iran-Backed Hackers Amid Rising Tensions The U.S. Department of Homeland Security (DHS) issued a National Terrorism Advisory System (NTAS) bulletin on Sunday, warning of heightened cyberattack risks from Iran-backed hacking groups and pro-Iranian hacktivists following recent geopolitical escalations. The advisory highlights a "heightened threat environment" in the U.S., with low-level cyberattacks likely targeting vulnerable networks. The DHS cautioned that violent extremists within the U.S. could mobilize in response to the Israel-Iran conflict, particularly if Iranian leadership issues a religious ruling calling for retaliatory violence. The bulletin also noted that anti-Semitic and anti-Israel sentiment has already motivated recent domestic attacks, raising concerns about further violence. The warning follows a pattern of Iranian state-affiliated hackers and hacktivists exploiting poorly secured U.S. networks. In October, authorities in the U.S., Canada, and Australia reported that Iranian hackers were acting as initial access brokers, breaching organizations in healthcare, government, IT, engineering, and energy sectors through brute-force attacks, password spraying, and MFA fatigue (push bombing). A separate August advisory from CISA, the FBI, and the Defense Department’s Cyber Crime Center (DC3) identified Br0k3r (also known as Pioneer Kitten, Fox Kitten, and other aliases) as a state-sponsored Iranian threat group involved in selling access to compromised networks to ransomware affiliates in exchange for a share of profits. While the DHS did not explicitly link the NTAS bulletin to recent events, the warning comes after U.S. strikes on Iranian nuclear facilities—including Fordow, Natanz, and Isfahan—on Saturday, just over a week after Israel targeted Iranian nuclear and military sites on June 13. Iran’s Foreign Minister, Abbas Araghchi, responded by warning of "everlasting consequences" and asserting Iran’s right to defend its sovereignty.
INCIDENT DETAILS -
TYPE
Cyberattack, Initial Access Brokerage, Ransomware
MOTIVATION
Retaliation for U.S. attacks on Iranian nuclear facilitiesFinancial gain (ransomware payments)Political/ideological (anti-Semitic or anti-Israel sentiment)
JANUARY 2026
251Before Incident
Cyber Attack
01 Jan 2026 • FBI
FBI: Russia used social engineering to breach prominent messaging accounts, Ukraine says

Russian Cyber Espionage Campaign Targets Government, Military, and Activists Across Ukraine, Europe, and the U.S.

234After Incident
CRITICAL-17
FBI1782484133
Russian Cyber Espionage Campaign Targets Government, Military, and Activists Across Ukraine, Europe, and the U.S. Ukraine’s Security Service (SBU), in collaboration with the FBI, has uncovered a prolonged Russian cyber espionage campaign aimed at compromising the messaging accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe, and the United States. The operation, designed to extract sensitive military, political, and economic intelligence, also sought to steal victims’ personal data. Rather than exploiting vulnerabilities in messaging apps, attackers relied on social engineering tactics. One common method involved sending fraudulent text messages often in the early morning posing as official support services to trick users into revealing account credentials. The SBU noted that victims were particularly vulnerable during these hours due to fatigue or distraction. Targets included Ukrainian government institutions, public officials, activists, and civilians, though the SBU did not disclose the specific Russian intelligence service behind the campaign, the primary messaging platforms affected, or the total number of victims. The FBI has not yet commented on the investigation. The disclosure aligns with previous warnings from Ukraine and Western intelligence agencies about Russian efforts to infiltrate secure messaging platforms. Earlier this year, Dutch authorities reported a global campaign by Russian state-backed hackers to hijack Signal and WhatsApp accounts belonging to government, diplomatic, and military personnel, often by impersonating customer support to obtain verification codes or PINs. Ukraine has repeatedly documented Russian espionage operations targeting military communications, including malware designed to steal data and attempts to extract encrypted Telegram and Signal messages from devices recovered on the battlefield.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Espionage, Intelligence Gathering
IMPACT
Data Compromised: Sensitive military, political, and economic intelligence; personal dataSystems Affected: Messaging accounts (unspecified platforms)Identity Theft Risk: High
DATA BREACH
Military intelligencePolitical intelligenceEconomic intelligencePersonal dataSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
DECEMBER 2025
248Before Incident
NOVEMBER 2025
239Before Incident
OCTOBER 2025
276Before Incident
Breach
01 Oct 2025 • FBI
Pentagon and Federal Bureau of Investigation: Keystone Kash and Pentagon Pete Hit by Twin Humiliations

FBI and Pentagon Hit by Major Data Breaches Exposing Sensitive Personnel Records

215After Incident
CRITICAL-61
PENFBI1790425578
FBI and Pentagon Hit by Major Data Breaches Exposing Sensitive Personnel Records Two high-profile U.S. government agencies the FBI and the Pentagon have suffered significant data breaches, exposing sensitive personnel information to potential adversaries. The FBI confirmed an ongoing investigation into a breach of its FBIjobs.gov system after hacking group ShinyHunters claimed to have stolen 2 to 3 terabytes of data. Among the compromised files were medical and psychiatric evaluations of FBI personnel, including records of allergies, depression symptoms, electrocardiogram results, and blood/urine test documents. Cybersecurity experts warn the breach could be of high value to foreign intelligence services, with former FBI operative Eric O’Neill suggesting adversaries like Russia may seek to exploit the stolen data. Separately, the Pentagon’s Defense Manpower Data Center (DMDC) disclosed a breach affecting up to 4 million current and former military personnel, with unauthorized access occurring between October 2023 and July 2024. Exposed data included Social Security numbers, occupational specialties, and other personal details, though officials stated there was no evidence of misuse. The DMDC, which manages over 60 million records, acknowledged the breach was not detected until months after the intrusion and that the data was unencrypted. Both agencies are assessing their cybersecurity measures in response to the incidents, which pose risks of espionage or criminal exploitation. Neither the FBI nor the Pentagon has provided further public comment.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized Access
MOTIVATION
EspionageCriminal Exploitation
IMPACT
2-3 terabytes (FBI)4 million records (Pentagon)FBIjobs.govPentagon’s Defense Manpower Data Center (DMDC)Brand Reputation Impact: HighIdentity Theft Risk: High
DATA BREACH
Medical and psychiatric evaluations (FBI)Social Security numbers (Pentagon)Occupational specialties (Pentagon)Personal details (Pentagon)2-3 terabytes (FBI)4 million records (Pentagon)Sensitivity Of Data: HighData Exfiltration: Yes (FBI)Data Encryption: No (Pentagon)Medical recordsPsychiatric evaluationsPersonal identification documentsPersonally Identifiable Information: Yes
AUGUST 2025
314Before Incident
Breach
15 Aug 2025 • FBI
FBI (Federal Bureau of Investigation)

Compromised FBI.gov and Other Government Email Accounts Sold on Dark Web for Fraudulent Use

258After Incident
CRITICAL-56
FBI833081625
Compromised FBI.gov email accounts are being sold on dark web channels (e.g., Telegram, Signal) for as low as $40, granting buyers full SMTP/POP3/IMAP access. These credentials enable attackers to impersonate law enforcement, submit fraudulent emergency data requests to tech companies (bypassing legal processes like subpoenas), and extract sensitive user data (IPs, emails, phone numbers). Criminals also exploit these accounts to distribute malware campaigns, access government-restricted intelligence tools (e.g., Shodan, Intelligence X), and infiltrate law enforcement portals. The breach stems from credential stuffing, infostealer malware, and targeted phishing, exploiting human/technical vulnerabilities rather than direct system hacking. The commoditization of institutional trust amplifies risks of large-scale fraud, unauthorized data disclosure, and erosion of public confidence in government communications. Accounts from domains like .gov bypass security filters, increasing phishing success rates and potential for supply-chain attacks on private sector entities relying on government verification.
INCIDENT DETAILS -
TYPE
Account CompromiseCredential TheftDark Web Marketplace ActivityPhishing/Social EngineeringMalware (Infostealer)Fraud (Forged Emergency Data Requests)
MOTIVATION
Financial Gain (Selling Access for $40–$X per Account)Fraud (Impersonation, Forged EDRs, Malware Distribution)Exploitation of Institutional TrustAccess to Premium OSINT ToolsData Theft (IP Addresses, Emails, Phone Numbers)
IMPACT
Email Account Credentials (SMTP/POP3/IMAP)Potential Disclosure of Sensitive Data via Forged EDRs (e.g., IP Addresses, Phone Numbers, Emails)Access to Law Enforcement Portals/OSINT ToolsFBI.gov Email AccountsOther U.S. Government Email Accounts (.gov, .police Domains)Tech Company/Telecom Provider Systems (via Forged EDRs)OSINT Platforms (Shodan, Intelligence X)Risk of Large-Scale Malware CampaignsErosion of Trust in Government CommunicationsPotential Legal Liabilities for Tech Companies Complying with Forged EDRsFBI/Government Agencies (Loss of Credibility)Tech Companies (If Tricked by Forged EDRs)Potential Violations of Data Protection Laws (If Sensitive Data Disclosed via Forged EDRs)Liability for Tech Companies Complying with Fraudulent RequestsIdentity Theft Risk: High (Impersonation of Law Enforcement)
DATA BREACH
Email Credentials (SMTP/POP3/IMAP)Potentially Sensitive Data via Forged EDRs (e.g., Subscriber Information)Sensitivity Of Data: High (Government Email Access, Potential PII via EDRs)Data Exfiltration: Likely (Credentials Sold; Data Accessed via Forged EDRs)Personally Identifiable Information: Potential (If Disclosed via Forged EDRs)
MAY 2025
328Before Incident
Cyber Attack
01 May 2025 • FBI
FBI: Cyber-crime increasingly coming with threats of physical violence

Cybercriminals Escalate Threats with Physical Violence in Extortion Schemes

276After Incident
CRITICAL-52
FBI1778466322
Cybercriminals Escalate Threats with Physical Violence in Extortion Schemes Cyberattacks are increasingly accompanied by threats of physical harm, marking a dangerous evolution in ransomware and extortion tactics. According to FBI data, incidents involving physical threats in the U.S. more than doubled last year, with similar trends reported in Europe, where over 18 cases were documented. Attackers are leveraging stolen personal data such as home addresses, social security numbers, and workplace details to intimidate victims. In one instance, hospital staff received harassing calls from hackers who named nurses individually and disclosed their private information, creating a climate of fear. Some criminals go further, hiring third parties to carry out threats or even commit violence, a tactic known as "violence-as-a-service." The cryptocurrency sector has become a hotspot for such attacks, with hackers targeting high-profile investors who flaunt their wealth online. Last year, French police rescued the father of a cryptocurrency millionaire who had been kidnapped, while another victim reportedly had a finger severed as part of an extortion attempt. Many perpetrators are young, with FBI profiles indicating ages between 17 and 25. Ransomware gangs, some state-sponsored by nations like Russia, China, Iran, and North Korea, are driving this shift. A Semperis report found that in 40% of global ransomware attacks in 2025, criminals resorted to physical threats. The financial toll is staggering U.S. organizations lost $20.8 billion to cybercrime last year, up from $16.6 billion in 2024. Experts warn the trend will persist as long as victims continue to pay ransoms. In one case, a cybersecurity negotiator received a threatening package at his home, underscoring the personal risks faced by those involved in ransom negotiations. The rise of "In Real Life Com," a network of online-linked criminals, has further normalized the use of real-world violence in cyber extortion schemes.
INCIDENT DETAILS -
TYPE
ransomwareextortionphysical threats
MOTIVATION
financial gainintimidationdata extortion
IMPACT
Financial Loss: $20.8 billion (U.S. organizations in 2025)home addressessocial security numbersworkplace detailspersonal identifiable informationclimate of fear in hospitalsdisruption of cryptocurrency operationsIdentity Theft Risk: high
DATA BREACH
personal identifiable informationworkplace detailshome addressesSensitivity Of Data: highData Exfiltration: yesPersonally Identifiable Information: yes
JANUARY 2025
388Before Incident
Cyber Attack
01 Jan 2025 • FBI
FBI: Seniors Targeted—FBI Issues Cyber Attack Advice For The Over 60s

FBI Warns Seniors as Cyber Scams Surge, Losses Hit $7.7 Billion in 2025

286After Incident
HIGH-102
FBI1778948621
FBI Warns Seniors as Cyber Scams Surge, Losses Hit $7.7 Billion in 2025 In observance of National Senior Fraud Awareness Day on May 15, the FBI issued a stark warning about the escalating threat of cyber scams targeting Americans over 60. According to the FBI’s Internet Crime Complaint Center (IC3), seniors filed over 200,000 fraud complaints in 2025 a 37% increase from the previous year with financial losses soaring to $7.7 billion, up 59% from 2024. FBI Special Agent Rebecca Keithley attributed the targeting of older adults to several factors: accumulated savings, heightened trust in unsolicited communications, and vulnerability to loneliness, which scammers exploit to establish fraudulent relationships. Common schemes include impersonation of relatives in financial distress, fake tech support offers, romance scams, and fraudulent charity solicitations. The FBI highlighted key red flags, such as demands for secrecy, urgency, requests for wire transfers, or payment via gift cards. Special Agent Ron Miller emphasized that ignoring unsolicited calls and messages is the most effective defense, as prolonged engagement increases the likelihood of falling victim. The warning underscores the growing sophistication and financial impact of scams disproportionately affecting older populations.
INCIDENT DETAILS -
TYPE
Scam
MOTIVATION
Financial gain
IMPACT
Financial Loss: $7.7 billionCustomer Complaints: 200,000 fraud complaintsIdentity Theft Risk: High
Cyber Attack
01 Jan 2025 • FBI
FBI Internet Crime Complaint Center: FBI Flags Cybercrime Losses Hit $20.87 Billion As AI Fuels Online Fraud

AI-Driven Cybercrime Losses Hit Record $20.87 Billion in 2025, FBI Reports

286After Incident
CRITICAL-102
FBI1775659096
AI-Driven Cybercrime Losses Hit Record $20.87 Billion in 2025, FBI Reports Cybercrime losses surged to an unprecedented $20.87 billion in 2025, with artificial intelligence playing an increasingly central role in fraud schemes, according to the FBI’s Internet Crime Complaint Center (IC3) report. For the first time, the report included a dedicated section on AI, underscoring its growing use by criminal networks to enhance the scale and sophistication of attacks. AI-powered fraud accounted for 22,364 complaints and $893 million in reported losses, though authorities believe the true figure is higher due to underreporting and victims’ unawareness of AI involvement. Cyber-enabled fraud crimes leveraging technology to execute traditional scams dominated the landscape, representing 45% of complaints but a staggering 85% of total financial losses. The total number of cybercrime complaints exceeded one million in 2025, a 17% increase from the previous year. Phishing remained the most reported offense, followed by extortion and investment scams. However, investment fraud caused the greatest financial damage, totaling $8.6 billion, while business email compromise (BEC) and tech support scams also contributed heavily to losses. While ransomware and data breaches accounted for 75% of reported technical attacks, the majority of cybercrime activity centered on digitally enabled fraud rather than purely technical exploits. AI-driven tactics included deepfake voices, cloned identities, and fabricated video content, used in BEC, romance scams, employment fraud, and investment schemes. A particularly alarming trend was the 128% surge in government impersonation scams, rising from 14,190 reports in 2023 to 32,424 in 2025. The FBI warned that AI-generated messages impersonating officials including voice and text communications have been used to deceive victims into compromising personal accounts. Despite their rapid growth, these scams received limited attention in AI-specific reporting. The report highlighted the evolving nature of cyber threats, driven by the broader adoption of emerging technologies, signaling a shift toward more adaptive and deceptive criminal tactics.
INCIDENT DETAILS -
TYPE
fraudphishingextortioninvestment scamsransomwaredata breachesbusiness email compromise (BEC)tech support scamsgovernment impersonation scams
MOTIVATION
financial gain
IMPACT
Financial Loss: $20.87 billionCustomer Complaints: 1,000,000+ complaints
DECEMBER 2024
398Before Incident
Cyber Attack
05 Dec 2024 • FBI
Stryker and Federal Bureau of Investigation: Pro-Iranian group claims credit for hacking into FBI Director Patel's personal account

Pro-Iranian Hackers Claim Breach of FBI Director’s Personal Account

381After Incident
CRITICAL-17
STRFBI1774644063
Pro-Iranian Hackers Claim Breach of FBI Director’s Personal Account A pro-Iranian hacking group, Handala, announced on Friday that it had compromised an account belonging to FBI Director Kash Patel, releasing decades-old personal photographs, a resume, and other documents online. The group, which has ties to Iran and Palestine, posted a statement alongside the materials, taunting Patel and declaring him among their "successfully hacked victims." The leaked files including images of Patel with a vintage sports car and a cigar appear to date back over a decade, primarily involving personal travel and business records. The FBI confirmed awareness of the incident, stating that the exposed data was historical and contained no classified or government information. The bureau added that it had taken steps to mitigate risks from the breach. The timing of the hack remains unclear, though reports from December 2024 indicated Patel had been previously warned by the FBI about Iranian targeting efforts. Handala, which has escalated its cyber operations in recent months, recently claimed responsibility for disrupting systems at Stryker, a Michigan-based medical technology firm, in retaliation for alleged U.S. airstrikes linked to Iranian civilian casualties. The group has been a persistent threat, with the U.S. Justice Department seizing four web domains tied to its operations last week as part of efforts to counter Iranian cyber campaigns. The Trump administration has also offered a $10 million reward for information leading to the identification of Handala members. The incident underscores the growing role of proxy hacking groups in Iran’s broader cyber conflict with Western targets.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Retaliation for alleged U.S. airstrikes linked to Iranian civilian casualties, cyber conflict with Western targets
IMPACT
Data Compromised: Personal photographs, resume, and other personal documentsBrand Reputation Impact: Potential reputational harm to FBI DirectorIdentity Theft Risk: Possible risk due to exposure of personal documents
DATA BREACH
Type Of Data Compromised: Personal photographs, resume, personal documentsSensitivity Of Data: Low (historical, no classified or government information)Data Exfiltration: YesImagesDocumentsPersonally Identifiable Information: Yes
DECEMBER 2024
453Before Incident
Breach
01 Dec 2024 • FBI
FBI

Investigation of Radical Ideology Inspired by 'The Turner Diaries'

397After Incident
CRITICAL-56
FBI001121924
In the film 'The Order,' the FBI investigates the proliferation of a radical ideology that leads to significant acts of domestic terrorism, including armed revolt and assassination. Based on historical events, the narrative identifies the influence of 'The Turner Diaries' in inspiring Timothy McVeigh's Oklahoma City bombing. Given the profound effect on national security and the potential for sparking wide-ranging violence, the involvement of law enforcement to thwart such threats is imperative.
INCIDENT DETAILS -
TYPE
Domestic TerrorismArmed RevoltAssassination
MOTIVATION
Radical IdeologyPolitical Motives
AUGUST 2024
480Before Incident
Breach
01 Aug 2024 • FBI
FBI

Dissemination of Propaganda and Child Abuse Material by FBI Informant

424After Incident
CRITICAL-56
FBI001080624
An FBI informant, Joshua Caleb Sutter, linked to extreme right-wing and neo-Nazi movements disseminated propaganda contributing to the rise of violent groups and networks engaged in child abuse. His actions, along with other radical elements, have led to the proliferation of child sexual abuse material (CSAM) and potentially influenced ultraviolent terrorist acts. Despite Sutter's past as an informant and implication in serious crimes, the FBI's stance and handling of his case remain unclear, raising concerns over informant accountability and the extent of malfeasance overlooked in intelligence operations.
INCIDENT DETAILS -
TYPE
Dissemination of Propaganda and Child Abuse Material
MOTIVATION
Right-wing ExtremismNeo-Nazism
IMPACT
Brand Reputation Impact: Concerns over FBI's handling of informants
JANUARY 2024
530Before Incident
Breach
01 Jan 2024 • FBI
FBI Dallas and Texas Attorney General: Texas Cyber Crooks Siphon Off $70.4 Million In Data Breach Hits

Texas Personal Data Breach Losses in 2024

428After Incident
CRITICAL-102
TEXFBI1773153659
Texas Hit by $70.4 Million in Personal Data Breach Losses in 2024, FBI Reports Texas residents lost over $70.4 million in 2024 due to account takeovers and identity fraud, a sharp increase driven by criminals exploiting stolen personal data. According to an FBI Dallas Facebook post on March 9, the losses stem from breaches of bank accounts, investment portfolios, email systems, devices, and cryptocurrency wallets. The figure reflects a growing trend of fraudsters bypassing traditional identity theft to directly drain financial assets. The $70.4 million total marks a significant rise from previous years, with Texas reporting $37 million in 2020, $42 million in 2021, $46 million in 2022, and $31 million in 2023. These losses contribute to the FBI’s Internet Crime Complaint Center (IC3) national tally, which recorded over $16 billion in U.S. cybercrime losses in 2024. Texas ranks among the states with the highest financial impacts, with extortion, personal data breaches, and phishing as the most common complaint types. Criminals leverage stolen data such as Social Security numbers, birthdates, and account credentials to reset passwords, bypass security measures, and siphon funds across linked accounts. A single breach can trigger cascading theft, amplifying financial damage. The IC3’s 2024 Internet Crime Report highlights the scale of these attacks, with personal data breaches generating some of the largest losses nationwide. In response, law enforcement is pushing for faster victim reporting and stronger account protections to disrupt fraudulent transactions before funds are irretrievable. Texas businesses facing breaches must comply with state reporting laws, notifying affected individuals and regulators under guidelines set by the Texas Attorney General. Early reporting aids recovery efforts and helps authorities track emerging fraud patterns. The FBI continues to urge victims to alert financial institutions, file complaints via IC3, and contact local law enforcement, emphasizing that timely reporting strengthens investigations and supports broader enforcement actions.
INCIDENT DETAILS -
TYPE
Data Breach, Identity Fraud, Account Takeover
MOTIVATION
Financial gain
IMPACT
Financial Loss: $70.4 millionData Compromised: Personal data (Social Security numbers, birthdates, account credentials), financial account details, cryptocurrency walletsBank accountsInvestment portfoliosEmail systemsDevicesCryptocurrency walletsIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Personal dataFinancial account detailsCryptocurrency wallet informationSensitivity Of Data: High (PII, financial data)Data Exfiltration: YesPersonally Identifiable Information: Social Security numbers, birthdates, account credentials
FEBRUARY 2023
510Before Incident
Breach
12 Feb 2023 • FBI
Federal Bureau of Investigation: Foreign hacker reportedly breached FBI servers holding Epstein files in 2023

FBI’s Epstein Investigation Files Compromised in 2023 Cyber Breach by Foreign Hacker

454After Incident
CRITICAL-56
FBI1773239371
FBI’s Epstein Investigation Files Compromised in 2023 Cyber Breach by Foreign Hacker In February 2023, a foreign hacker infiltrated a server at the FBI’s New York field office, accessing files related to the bureau’s investigation of the late sex offender Jeffrey Epstein. The breach, first reported by Reuters and CNN on February 17, 2024, occurred when a server in the FBI’s child exploitation forensic lab was left vulnerable due to procedural errors by Special Agent Aaron Spivack. The intrusion was discovered on February 13, 2023, after Spivack found a text file warning of the compromise. Internal documents revealed the hacker had searched through Epstein-related files, though it remains unclear whether data was exfiltrated or which specific records were accessed. The FBI described the incident as an “isolated” cyber incident, stating it had restricted access and remediated the network, though its investigation is ongoing. A source familiar with the breach indicated the hacker was likely a cybercriminal rather than a state actor, though the incident highlights the intelligence value of Epstein’s files. The release of U.S. Justice Department documents in recent years has exposed Epstein’s ties to high-profile figures, sparking global investigations. Security experts, including Georgia Tech’s Jon Lindsay, have noted the potential for foreign intelligence services to exploit such material for kompromat (compromising information). The hacker reportedly expressed shock upon encountering child abuse imagery on the server and threatened to report the owner to law enforcement. FBI officials defused the situation by convincing the hacker of their identity via a video call, during which they displayed law enforcement credentials. The hacker’s identity, origin, and motives remain unknown, as does whether any data was retained or disseminated. The breach stemmed from Spivack’s attempt to navigate the FBI’s complex digital evidence protocols, according to internal documents. Spivack, who has been involved in the Epstein investigation, denied responsibility, citing conflicting bureau policies and inadequate IT guidance. The outcome of the FBI’s internal review is unclear. Many of the Justice Department’s Epstein-related documents remain heavily redacted or withheld, with the Trump administration citing protections for victims and ongoing investigations. The incident underscores the persistent risks of cyber intrusions targeting sensitive law enforcement data.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Potential intelligence value (kompromat), financial gain, or opportunistic access
IMPACT
Data Compromised: Files related to Jeffrey Epstein investigation, possibly including child abuse imagerySystems Affected: FBI New York field office server (child exploitation forensic lab)Operational Impact: Restricted access to affected server; ongoing investigationBrand Reputation Impact: Potential reputational damage to FBI due to sensitive data exposure
DATA BREACH
Type Of Data Compromised: Investigative files, child abuse imagery, personally identifiable information (PII) of victims and persons of interestSensitivity Of Data: High (involves child exploitation, high-profile individuals, and national security implications)Data Exfiltration: UnclearPersonally Identifiable Information: Likely (victims, witnesses, and persons of interest in Epstein investigation)
JANUARY 2022
616Before Incident
Ransomware
01 Jan 2022 • FBI
FBI: Ransomware hit critical infrastructure hard in 2022, FBI says

FBI Reports Ransomware Surge in Critical Infrastructure

393After Incident
CRITICAL-223
FBI1774268926
FBI Reports Ransomware Surge in Critical Infrastructure, Highlights Persistent Threats In 2022, ransomware attacks continued to plague organizations, with phishing, remote desktop protocol (RDP) exploitation, and software vulnerabilities remaining the primary initial infection vectors, according to the FBI. Threat actors increasingly relied on extortion tactics threatening to leak stolen data to pressure victims into paying ransoms. Of the 2,385 ransomware incidents reported to the FBI last year, 870 targeted critical infrastructure sectors, with the healthcare and public health sector bearing the brunt of attacks. Collectively, these infections resulted in adjusted losses exceeding $34 million. However, the FBI acknowledged that the true scale of ransomware activity remains underreported, as many incidents go unreported to law enforcement. Extortion both ransomware-related and other forms ranked as the fourth-highest cybercrime type reported to the FBI in 2022, though overall extortion complaints remained flat compared to 2021 and down nearly 50% from a 2020 peak. Security leaders and government officials emphasized the need for bipartisan cooperation on cyber resilience, stressing that national security priorities should transcend partisan divides, particularly as the U.S. approaches the presidential election. Meanwhile, experts warned that third-party vendors must prioritize secure development practices over speed to market to mitigate supply chain risks. The report underscores the ongoing threat ransomware poses to critical infrastructure, with healthcare, public health, and other essential services facing disproportionate targeting.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
ExtortionFinancial Gain
IMPACT
Financial Loss: $34 million (adjusted losses)
DATA BREACH
Data Exfiltration: Threatened (extortion tactic)
SEPTEMBER 2021
617Before Incident
Cyber Attack
01 Sep 2021 • FBI
FBI and NCAA: FBI: Hackers target online accounts to steal nude photos

FBI Warns of Rising Sextortion Schemes Targeting Social Media Accounts

600After Incident
CRITICAL-17
FBINCA1786544643
FBI Warns of Rising Sextortion Schemes Targeting Social Media Accounts The FBI has issued a public alert warning that cybercriminals are increasingly targeting adults and children by hijacking social media and online accounts to steal sexually explicit images or videos. These attackers then use the stolen content for blackmail, threatening to leak it publicly or share it with victims’ contacts unless demands often financial are met. In some cases, the material is sold on criminal marketplaces, sometimes alongside victims’ personal details, such as names, birthdates, and social media handles, which can be used to coerce further exploitation. The agency highlighted that victims frequently face ongoing harassment, stalking, or additional attacks, including the unauthorized posting of stolen content on their own social media profiles. The warning follows a joint alert from the FBI and the NCAA, which revealed that student-athletes are also being targeted in similar schemes. Cybercriminals often trick victims into providing verification codes or clicking malicious password reset links, enabling account takeovers. To mitigate risks, the FBI advises against storing explicit content on accessible platforms, using weak or personal information-based passwords, or engaging with unsolicited messages requesting verification codes. While the bureau did not specify the catalyst for the alert, such advisories typically follow a surge in reported incidents. In 2021, the FBI noted a sharp rise in sextortion complaints, and recent cases underscore the severity of the threat one Canadian man was sentenced to 33 years in prison in May for sextorting over 145 children, some as young as six, over an eight-year period.
INCIDENT DETAILS -
TYPE
Sextortion
MOTIVATION
Financial gainHarassmentExploitation
IMPACT
Financial Loss: Financial demands met by victimsSexually explicit images/videosPersonal details (names, birthdates, social media handles)Social media accountsOnline accountsIdentity Theft Risk: High
DATA BREACH
Sexually explicit images/videosPersonally identifiable information (names, birthdates, social media handles)Sensitivity Of Data: HighData Exfiltration: Sold on criminal marketplacesImagesVideosPersonally Identifiable Information: Yes
JULY 2021
710Before Incident
Ransomware
15 Jul 2021 • FBI
FBI, Multi-State Information Sharing and Analysis Center and Cybersecurity and Infrastructure Security Agency: I've Been Hit By Ransomware!

#StopRansomware Guide Update for Incident Response

610After Incident
CRITICAL-100
CISTHEFBI1774844752
CISA and Partners Release Updated #StopRansomware Guide to Strengthen Incident Response In May 2023, the Cybersecurity and Infrastructure Security Agency (CISA), alongside the FBI, NSA, and the Multi-State Information Sharing and Analysis Center (MS-ISAC), released an updated #StopRansomware Guide to standardize ransomware response protocols. The guide outlines a structured approach for organizations to detect, contain, eradicate, and recover from ransomware attacks, emphasizing coordinated action to minimize damage. The response process begins with detection and analysis, where impacted systems must be isolated immediately either by disconnecting networks at the switch level or physically unplugging devices. For cloud environments, snapshots of volumes should be taken for forensic review. Organizations are advised to use out-of-band communication (e.g., phone calls) to avoid tipping off attackers, who may monitor internal activity to escalate attacks. If isolation isn’t feasible, powering down devices is recommended, though this risks losing volatile memory evidence. Critical systems such as those tied to health, safety, or revenue should be prioritized for restoration, while unaffected systems are deprioritized to streamline recovery. Security teams are urged to examine logs for precursor malware (e.g., Bumblebee, QakBot, or Cobalt Strike) and signs of data exfiltration, as ransomware often follows earlier compromises. Threat hunting should focus on anomalous activity, including unauthorized Active Directory accounts, suspicious VPN logins, and misuse of built-in Windows tools (e.g., vssadmin.exe, PsExec) to inhibit recovery. Reporting and notification are critical, with organizations directed to engage internal stakeholders (IT, leadership, cyber insurers) and external agencies like CISA, the FBI, or the U.S. Secret Service. If a data breach occurs, legal and communications teams must follow incident response plans to manage disclosures. Containment and eradication involve capturing system images, memory dumps, and malware samples for analysis. Trusted guidance (e.g., from CISA or security vendors) should be followed to disable ransomware binaries and remove associated registry entries. Breaches often involve credential theft, requiring measures like disabling remote access and resetting passwords. Forensic analysis should identify persistence mechanisms, such as rogue accounts or backdoors, before systems are rebuilt using clean images or infrastructure-as-code templates. Recovery prioritizes reconnecting systems from offline backups while preventing reinfection. Post-incident, organizations are encouraged to document lessons learned and share indicators of compromise with CISA or sector-specific ISACs to bolster collective defense. The guide underscores that ransomware incidents may signal deeper compromises, necessitating thorough investigation to prevent recurrence.
INCIDENT DETAILS -
TYPE
Ransomware
DATA BREACH
Data Exfiltration: Possible (threat hunting for signs of data exfiltration)Data Encryption: Possible (ransomware data encryption)
JUNE 2021
749Before Incident
Cyber Attack
16 Jun 2021 • FBI
Federal Bureau of Investigation (FBI)

Man pardoned for Jan. 6 gets life in prison for plotting to incite 'civil war,' attack FBI agents

732After Incident
CRITICAL-17
FBI501070425
Edward Kelley, a Tennessee man pardoned for his role in the Jan. 6, 2021, U.S. Capitol assault, was sentenced to life in prison for plotting to attack FBI agents and seeking to incite a 'civil war.' Kelley created a 'kill list' of FBI agents and distributed it to a co-conspirator. He was convicted of conspiracy charges and viewed the FBI as the enemy, targeting them for assassination. The Justice Department stated that Kelley identified 36 law enforcement personnel to target, including names, titles, and cell phone numbers.
INCIDENT DETAILS -
TYPE
Conspiracy to incite civil war and attack FBI agents
MOTIVATION
Incite civil warTarget law enforcement for assassination
JUNE 2021
750Before Incident
Cyber Attack
01 Jun 2021 • FBI
CISA, Symantec, FBI and Fortinet: Medusa Ransomware Hits 40+ Victims in 2025, Demands $100K–$15M Ransom

Medusa Ransomware Surges, Targeting Critical Infrastructure with Double Extortion Tactics

725After Incident
LOW-25
CISSYMFBIFOR1768715192
Medusa Ransomware Surges, Targeting Critical Infrastructure with Double Extortion Tactics The Medusa ransomware operation, tracked by Symantec as Spearwing, has claimed nearly 400 victims since its emergence in January 2023, with attacks rising 42% between 2023 and 2024. In the first two months of 2025 alone, the group has attributed over 40 incidents, signaling an aggressive expansion amid the disruption of other major ransomware-as-a-service (RaaS) players like LockBit and BlackCat. Medusa employs double extortion, stealing sensitive data before encrypting networks to pressure victims into paying ransoms ranging from $100,000 to $15 million. Targets span healthcare, financial services, government, education, legal, and manufacturing sectors many within critical infrastructure. If victims refuse to pay, the group threatens to leak stolen data via its dedicated leak site. ### Attack Methods & Tools Medusa’s intrusion chains often begin with exploiting known vulnerabilities in public-facing applications, particularly Microsoft Exchange Server, or through initial access brokers. Once inside, attackers deploy remote management tools like SimpleHelp, AnyDesk, and MeshAgent for persistence, alongside the Bring Your Own Vulnerable Driver (BYOVD) technique to disable antivirus software using KillAV a tactic previously seen in BlackCat attacks. Other tools in Medusa’s arsenal include: - PDQ Deploy for lateral movement and payload delivery - Navicat for database access - RoboCopy and Rclone for data exfiltration - Advanced IP Scanner and SoftPerfect Network Scanner for reconnaissance - Ligolo and Cloudflared for command-and-control (C2) evasion The group also employs living-off-the-land (LotL) techniques, such as PowerShell commands (Base64-encoded to avoid detection) and Mimikatz for credential theft, alongside legitimate remote access tools like ConnectWise and PsExec to move undetected. ### Evasion & Triple Extortion Risks Medusa actors take steps to evade detection, including deleting PowerShell command histories and terminating endpoint detection and response (EDR) tools. In at least one case, a victim who paid the ransom was later contacted by a separate Medusa affiliate, who claimed the original negotiator had stolen the funds and demanded an additional payment suggesting a potential triple extortion scheme. ### CISA Advisory & Historical Context A joint advisory from CISA, the FBI, and MS-ISAC, released on March 12, 2025, revealed that Medusa has compromised over 300 critical infrastructure victims as of December 2024. The group, unrelated to MedusaLocker or the Medusa mobile malware, first appeared in June 2021 as a closed ransomware variant before shifting to an affiliate-based model. While affiliates execute attacks, core developers retain control over ransom negotiations. Recent campaigns have exploited vulnerabilities in ConnectWise ScreenConnect (CVE-2024-1709) and Fortinet EMS (CVE-2023-48788). Despite the RaaS landscape’s volatility with new groups like Anubis, LCRYX, and Xelera emerging Medusa has established itself as a persistent threat, ranking among the top ransomware actors in late 2024.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData extortion
IMPACT
Financial Loss: Ransoms ranging from $100,000 to $15 millionData Compromised: Sensitive data stolen before encryptionIdentity Theft Risk: High (due to data exfiltration)
DATA BREACH
Type Of Data Compromised: Sensitive data (including personally identifiable information)Sensitivity Of Data: High
JANUARY 2020
734Before Incident
Cyber Attack
01 Jan 2020 • FBI
FBI, U.S. Justice Department and Conti: Ukrainian hacker gets four years in US prison over Conti ransomware attacks

Ukrainian Conti Ransomware Developer Sentenced to Four Years in U.S. Prison

699After Incident
CRITICAL-35
THEUSDFBI1789129739
Ukrainian Conti Ransomware Developer Sentenced to Four Years in U.S. Prison A Ukrainian national, Oleksii Lytvynenko (44), has been sentenced to four years in a U.S. prison for his role in the Conti ransomware operation, one of the most prolific cybercriminal groups in recent history. Lytvynenko, who previously resided in Cork, Ireland, pleaded guilty in June 2024 to charges related to his work as both a hacker and developer for Conti, which targeted over 1,000 victims worldwide before disbanding in 2022. According to the U.S. Justice Department, Lytvynenko personally attacked at least a dozen companies and helped develop malicious tools, including a malware "loader" used to deploy ransomware on compromised systems. Investigators recovered stolen data from eight U.S. victims and four international targets in his online accounts. Between 2020 and 2022, Conti launched attacks across 47 U.S. states, 31 countries, Washington, D.C., and Puerto Rico, extorting an estimated $150 million in ransoms by early 2022. The group targeted critical infrastructure entities, prompting the FBI and DOJ to label it a major cybersecurity threat. Lytvynenko was arrested in July 2023 at his home in Ireland following a U.S. extradition request. After spending years in an Irish jail fighting extradition, he was transferred to the U.S. for prosecution. Forensic evidence from his arrest revealed he remained involved in ransomware activities even after Conti’s shutdown. Conti, believed to have operated from Russia and Eastern Europe, gained notoriety after its leadership publicly supported Moscow’s invasion of Ukraine in February 2022. Shortly after, an apparent insider reportedly Ukrainian leaked internal chats, exposing the group’s operations. In a separate case, four other alleged Conti members were charged in September 2023, and Ukrainian authorities arrested another suspect in Kyiv in 2024.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain, Cybercrime
IMPACT
Financial Loss: $150 million (estimated ransoms extorted)Data Compromised: Stolen data from 8 U.S. victims and 4 international targetsOperational Impact: Critical infrastructure entities targeted
DATA BREACH
Type Of Data Compromised: Stolen data (unspecified types)Data Exfiltration: YesData Encryption: Yes (ransomware encryption)
JUNE 2017
741Before Incident
Breach
16 Jun 2017 • FBI
Federal Bureau of Investigation (FBI)

Alleged Unauthorized Media Leak by Former FBI Director James Comey Involving Daniel Richman

684After Incident
HIGH-57
FBI3562235102125
The FBI faced a high-profile breach involving unauthorized leaks of sensitive information tied to its investigation into Hillary Clinton’s private email server. Former FBI Director James Comey was indicted for allegedly authorizing Daniel Richman, a Columbia University law professor and former federal prosecutor, to act as an anonymous media source. The leak, investigated under Operation Arctic Haze, involved classified details appearing in a 2017 New York Times article, though no charges were filed against Richman or Comey for the leak itself. The incident stemmed from Comey’s 2020 Senate testimony, where he denied authorizing any FBI personnel to leak investigation details—contradicted by later revelations. While no direct data theft or financial loss occurred, the breach compromised the FBI’s operational integrity, eroded public trust, and triggered legal repercussions for Comey, including charges of false statements and obstruction. The case also highlighted political interference allegations, with Comey’s legal team arguing the prosecution was motivated by former President Trump’s personal vendetta. The reputational damage extended to the FBI’s credibility in handling politically sensitive investigations, reinforcing perceptions of institutional vulnerability to internal leaks and external manipulation.
INCIDENT DETAILS -
TYPE
Unauthorized DisclosureInsider ThreatAlleged Perjury
MOTIVATION
Political InfluenceMedia Narrative ControlDisputed: Personal Vendetta (per Comey's defense)
IMPACT
Classified FBI Investigation Details (alleged)Internal FBI Communications (memos)FBI Credibility UnderminedInternal Trust ErosionHigh (FBI & DOJ)Politicization of Law EnforcementPerjury Charges (Comey)Obstruction of Congress (Comey)
DATA BREACH
Classified Investigation Details (alleged)Internal FBI Memos (Trump conversations)Sensitivity Of Data: High (Classified/Confidential)Media Leaks (New York Times, Wall Street Journal)Text (Memos)Investigation Notes
JANUARY 2017
797Before Incident
Data Leak
01 Jan 2017 • FBI
Federal Bureau of Investigation (FBI)

FBI Website Data Breach by CyberZeist

736After Incident
HIGH-61
FED328131123
Data on Pastebin was exposed by the infamous black hat hacker CyberZeist, who gained access to the FBI website FBI.gov. Account information, including names, SHA1 encrypted passwords, SHA1 salts, and emails, are contained in leaked documents. While professionals at the FBI worked to resolve the issue, the expert provided more details about the attack. The website administrators appear to have made some unfortunate mistakes. For instance, they left backup files on the same server, which allowed hackers to access them even if they chose not to publish them right away.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesSHA1 encrypted passwordsSHA1 saltsEmails
DATA BREACH
Personal InformationCredentialsSensitivity Of Data: HighData Encryption: SHA1

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for FBI ?
?
What was FBI's A.I Rankiteo Cyber Score in August 2026 ?
?
What was FBI's A.I Rankiteo Cyber Score in July 2026 ?
?
What was FBI's A.I Rankiteo Cyber Score in June 2026 ?
?
What was FBI's A.I Rankiteo Cyber Score in May 2026 ?
?
What was FBI's A.I Rankiteo Cyber Score in April 2026 ?
?
What was FBI's A.I Rankiteo Cyber Score in March 2026 ?
?
What was FBI's A.I Rankiteo Cyber Score in February 2026 ?
?
What was FBI's A.I Rankiteo Cyber Score in January 2026 ?
?
What was FBI's A.I Rankiteo Cyber Score in December 2025 ?
?
What was FBI's A.I Rankiteo Cyber Score in November 2025 ?
?
What was FBI's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on FBI's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with FBI ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view FBI's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?