FBI cyber chief worries private sector not sharing enough cyber threat information
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
The private sector still isn’t sharing enough cyber information with the FBI in part because organizations are operating on false assumptions about what the bureau will do with what it collects, the FBI’s top cyber official said Wednesday.
Brett Leatherman, assistant director of the FBI’s cyber division, said in remarks at the Billington CyberSecurity Summit and in a discussion with reporters that organizations stand to benefit from bringing in the bureau when it’s compromised by hackers from the People’s Republic of China (PRC) and others. But one of the “key misconceptions” is that “the FBI is somehow sharing information with regulators for regulatory purposes, and that’s not the case.”
“From my standpoint over the last few years, I think we’ve seen a hesitancy on some companies to engage [with the] FBI,” Leatherman said.
“It worries me when an organization is breached by a nation-state actor and believes that bringing law enforcement in might be more risky than handling it on their own,” he said. “That should worry all of us when that happens, because who is positioned to eradicate the PRC from their environments as quickly as when they might have law enforcement or the intelligence teams at FBI come in and actually help with that effort?”
In response, the bureau has held events like outside counsel summits to walk attorneys through what the FBI offers victims during a major breach, Leatherman said. The FBI also has adjusted its standards for when to share information about threats when weighing how much it might help victims versus whether it might jeopardize a law enforcement operation in the future.
“Our posture is, ‘Share until it hurts,’” he said. “What I always ask my team is, if the victim were sitting in this room right now … would they want this information, and what is the compelling justification we have to not share this now to stop the impact versus taking an operation 90 days from now?”
“We have to in every situation where we have intelligence, we have to take that victim perspective because they can’t voice it in that moment,” he said. “Where we can share in a way that will protect our equities in conducting those operations, we’ll do it. But [where] we can have an impact to hundreds of pieces of critical infrastructure, we should share that, and we should share it quickly.”
The FBI published a new cyber strategy Wednesday that places an emphasis on aiding victims of cyberattacks. Helping victims also helps investigations, Leatherman said.
“We used to look at remediation and incident response as mutually exclusive to investigation and threat pursuit,” he said. “And what we’ve shown over the last few years is that they are not mutually exclusive. … If we can work with victims in a way that preserves investigative information, that allows us to move upstream against the actors.”
Latest Podcasts
Government
FTC rescinds policy requiring health apps to notify customers after a breach
Lawmakers call on Commerce to sanction hackers-for-hire
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Technology
European parliament members call for slowdown of Serbia’s EU entry over spyware use
The G7 tells industry to hurry up and prep for post-quantum encryption
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Wyden seeks upgraded NSA security guidance on commercial VPN use
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Reproduced in full under licence from CyberScoop. © CyberScoop. Written by Tim Starks.
Coverage
One outlet has carried this so far.
2026-09-09 15:05 UTC
Related stories
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Dark Reading · 2026-11-12
- [Virtual Event] Building a Secure AI Strategy for the Enterprise
Dark Reading · 2026-10-08
- AI agents can modify themselves without humans telling them to do so
The Register · 2026-09-16
- CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
Infosecurity Magazine · 2026-09-16
- Ministry of Justice apologizes after court staff accessed Southport victims' files
The Register · 2026-09-16