INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
FBI Investigating Potential Breach of Wiretapping Tools
| 2026-03-08 23:14 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
The FBI is investigating a breach of its systems, which reportedly affected wiretapping and surveillance tools. China's Salt Typhoon, a PRC-backed crew known for hacking major US telecommunications firms and stealing information from nearly every American, may be behind the incident. The attack appears to have targeted the FBI's unclassified system containing law enforcement sensitive information, including returns from legal process such as pen register and trap and trace surveillance returns, and personally identifiable information pertaining to subjects of FBI investigations. The breach was first spotted on February 17, with the FBI notifying Congress that it began investigating the incident shortly after.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt Typhoon
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
cryptocurrencycryptocurrency
telecommunicationstelecommunications
Incident Timeline
December 2025
Attackers used display name spoofing to impersonate LastPass in phishing emails that targeted victims.
Click on any entity below to view its context and source!
financial
$154 Stolen / Extorted Funds
Crypto flows to sanctioned entities
Blockchain-watcher Chainalysis last week
published
research claiming sanctioned entities managed to conduct $154 billion worth of cryptocurrency transactions in 2025, a 694 percent year-over-year increase.
financial
$39 Stolen / Extorted Funds
According to the feds, Phobos affiliates victimized more than 1,000 public and private entities and extorted ransom payments worth more than $39 million.
financial
$104 Entities
$104 billion of that haul went to sanctioned entities, with the rest headed to “illicit addresses” – crypto accounts associated with crime or terrorist financing.
2026/03/08
The FBI is investigating a breach that may have affected its wiretapping tools, which reportedly contained law enforcement sensitive information.
Click on any entity below to view its context and source!
threat_actor
Salt Typhoon
Salt Typhoon
is the PRC-backed crew that famously
hacked major US telecommunications firms
and
stole information
belonging to
nearly every American
.
And while the FBI declined to provide any additional information, it's worth noting that China's Salt Typhoon previously
compromised wiretapping systems
used by law enforcement.
financial
$93.3 stablecoin
“The ruble-backed A7A5 stablecoin processed $93.3 billion in less than a year, acting as a critical bridge for Russian businesses to access global markets despite sanctions,” Chainalysis found, while Iran and Venezuela also used digi-dollars to dodg…
victims
100,000 organizations
At scale, the platform generated tens of millions of phishing emails each month and facilitated unauthorized access to nearly 100,000 organizations globally, including schools, hospitals, and public institutions.
victims
142,000 registered users
"
The website had over 142,000 registered users as of December 2025.
Tactical Metrics
Metrics
financial
93,300,000,000
Stablecoin
Click for context!
“The ruble-backed A7A5 stablecoin processed $93.3 billion in less than a year, acting as a critical bridge for Russian businesses to access global markets despite sanctions,” Chainalysis found, while Iran and Venezuela also used digi-dollars to dodg…
Metrics
victims
100,000
Organizations
At scale, the platform generated tens of millions of phishing emails each month and facilitated unauthorized access to nearly 100,000 organizations globally, including schools, hospitals, and public institutions.
Metrics
financial
154,000,000,000
Stolen / Extorted Funds
Crypto flows to sanctioned entities
Blockchain-watcher Chainalysis last week
published
research claiming sanctioned entities managed to conduct $154 billion worth of cryptocurrency transactions in 2025, a 694 percent year-over-year increase.
Metrics
victims
142,000
Registered Users
"
The website had over 142,000 registered users as of December 2025.
Metrics
financial
39,000,000
Stolen / Extorted Funds
According to the feds, Phobos affiliates victimized more than 1,000 public and private entities and extorted ransom payments worth more than $39 million.
Metrics
financial
104,000,000,000
Financial Impact
$104 billion of that haul went to sanctioned entities, with the rest headed to “illicit addresses” – crypto accounts associated with crime or terrorist financing.
Intelligence Sources
The Register - Cybercrime
2026-03-08
FBI is investigating breach that may have hit its wiretapping tools
The Register - Cybercrime
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:54
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
timeline
Temporal Reference
2024
date
7x
organisation
Identified Entity
the US
entity
4x
source region
Origin Country
United States
country
4x
attribution
Attributing Entity
FBI
authority
4x
target region
Target Country
China
country
4x
tactic
Cyber Operation Type
Ransomware
tactic
2x
industry
Targeted Sector
Telecommunications
sector
2x
general metric
Percent
62
percent
2x
financial
Stolen / Extorted Funds
154,000,000,000
worth
Contextual Telemetry
Context Block
7 METRICS
threat actor
APT Group
Salt Typhoon
actor
financial
Stablecoin
93,300,000,000
stablecoin
victims
Organizations
100,000
organizations
victims
Registered Users
142,000
registered users
general metric
Takedown Actions
100
takedown actions
general metric
Public Entities
1,000
public entities
financial
Financial Impact
104,000,000,000
entities
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.