FBI urges breached firms to share more threat intel

The FBI’s top cyber official is again urging U.S. companies to share more cyber threat information with the bureau, warning that persistent hesitation is undermining efforts to contain nation-state intrusions, including those linked to the People’s Republic of China. Speaking Wednesday at the Billington CyberSecurity Summit, Brett Leatherman, assistant director of the FBI’s cyber division, said many victims still avoid calling the bureau based on misconceptions about how their data will be used. Leatherman stressed that the FBI treats hacked organizations as victims, not enforcement targets, and does not reflexively share incident details with regulatory agencies examining data security lapses, echoing assurances previously made by FBI Director Christopher Wray in 2018 remarks to corporate leaders.[11]

Private-sector reluctance to engage with law enforcement has long been documented in Justice Department and congressional reports, which cite fears that information handed to the FBI simply disappears into a “black hole” with little feedback to the victim.[1][4] Analysts at the Justice Department’s Office of Inspector General and the Congressional Research Service have also highlighted concerns that threat data shared with the government may be outdated, lack context, or be repurposed in ways that raise privacy and regulatory liability worries for firms.[1][2][10] Those longstanding anxieties, Leatherman suggested, continue to shape breach-response decisions inside corporate boardrooms despite FBI attempts to clarify its role.

Leatherman said those anxieties are particularly troubling when a company is facing a sophisticated intrusion from a nation-state actor such as the PRC, where the bureau’s intelligence and investigative authorities may be uniquely positioned to help evict adversaries from corporate networks. FBI leadership has repeatedly warned that unreported intrusions leave the government unaware of ongoing campaigns, limiting its ability to disrupt hostile actors and protect partners and critical infrastructure.[13] The result, officials argue, is that companies handling incidents entirely on their own may miss the opportunity to contribute to broader efforts to identify attack infrastructure, track threat groups and preempt follow-on operations against other targets.

To rebuild trust, the bureau has stepped up structured engagement with general counsel and security leaders, including hosting outside-counsel summits to walk them through how agents handle evidence, protect sensitive business information and coordinate with incident responders. The FBI’s Office of Private Sector now maintains standing partnerships with business through programs such as the Domestic Security Alliance Council and InfraGard, which share threat bulletins and analysis with hundreds of major corporations and tens of thousands of infrastructure security professionals.[12][13] Specialized units like the Cyber Threat Analytics Collaboration Unit also work with alliances that bring together government and industry analysts to pool indicators and analytic findings.[9] These mechanisms are designed to make threat sharing a two-way exchange rather than the one-direction flow that earlier audits found so frustrating for companies.[1]

Leatherman said the bureau’s updated cyber strategy puts victim support at the center of operations, emphasizing rapid sharing of actionable intelligence whenever doing so will not compromise active cases. A recent comprehensive cyber review from the Justice Department similarly underscored the value of sharing anonymized investigative findings with the private sector so companies can harden defenses without exposing sensitive sources or methods.[15] Leatherman described the FBI’s posture as “share until it hurts”, instructing teams to default to disclosure when intelligence can mitigate harm to victims or prevent cascading impacts across critical infrastructure, even if it forces investigators to adjust or delay future operations.

For organizations weighing whether to call law enforcement after a breach, the bureau’s message is that early reporting can both accelerate containment and feed a “virtuous cycle” of intelligence that helps protect peers across sectors.[13] Companies can coordinate with local FBI field offices and established programs for private-sector engagement to discuss sharing options in advance, clarifying how evidence will be handled and what information is likely to flow back to defenders.[9][12] Leatherman argued that treating the FBI as a partner, rather than a potential source of regulatory exposure, is essential to counter increasingly aggressive nation-state and criminal campaigns targeting U.S. businesses and infrastructure.

References

  1. Audit of the Federal Bureau of Investigation’s Implementation of Its Next Generation Cyber Initiative
  2. National Cyber Investigative Joint Task Force
  3. Cyber sharing with industry improving, DOJ says – Nextgov/FCW
  4. FBI Cyber – Private Sector Engagement
  5. Justice Department’s Role in Cyber Incident Response
  6. FBI chief: Corporate hack victims can trust we won’t share info
  7. Office of Private Sector | Federal Bureau of Investigation
  8. FBI Partnering with the Private Sector to Counter the Cyber Threat | Federal Bureau of Investigation
  9. [PDF] Comprehensive Cyber Review – Department of Justice

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply