
AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
An intruder reached an unclassified FBI network holding pen-register and trap-and-trace returns, exposing phone numbers of surveillance targets. Reports point to China; no official attribution has been made.
What happened
The FBI opened an inquiry into abnormal activity on one of its networks on 17 February 2026, Bloomberg reported. The affected system is unclassified but holds sensitive law enforcement information: returns from pen-register and trap-and-trace orders (court-approved collection of call and message metadata, not content) and personal details of people under investigation. Lawmakers were first briefed in early March.
On 23 March the Justice Department ruled the intrusion a "major incident" under the Federal Information Security Modernization Act (FISMA), which triggers formal notice to Congress. According to that notice, the attacker exploited a commercial internet service provider vendor's infrastructure to get around FBI network security controls, and its techniques "appear sophisticated".
Confirmed vs. claimed
Confirmed by the FBI: anomalous activity on an unclassified network, access through a third party, ongoing remediation and notification of Congress. Nextgov/FCW reported that phone numbers of surveillance targets were exposed. The FBI has also set up a working group to improve cyber resilience, according to Bloomberg.
Reported, not confirmed: The Wall Street Journal and Politico linked the intrusion to China, according to Nextgov/FCW, which said it had not independently confirmed that link. The government's notice did not name who was responsible.
Who is affected
People whose phone numbers appear in FBI surveillance returns, and investigations that depend on targets not knowing they are being watched. There is no indication the general public needs to act.
What to do
- Organisations that handle lawful-intercept or surveillance data should review vendor and ISP access paths into those systems.
- Monitor for unusual access to metadata stores, not just content stores; metadata alone can reveal who is under investigation.
Sources
More breaches in United States
- IDScan.net — 01 Sep 2026
- Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) — 27 Aug 2026
- Boston Scientific — 26 Aug 2026
- Aesto Health — 14 Aug 2026
- DentaQuest — 17 Jul 2026