The FBI’s first agency-wide unclassified cyber strategy prioritises disruption of criminal networks, faster victim support, industry partnerships and AI-assisted investigations.

FBI Unveils First Public Cyber Strategy, Plans Stronger Disruption of Hackers and Victim Support

The420 Web Correspondent
7 Min Read

The FBI has released its first agency-wide, unclassified cyber strategy, promising to disrupt criminal infrastructure, strengthen cooperation with private companies and provide faster assistance to victims of cyberattacks.

The 17-page strategy, announced on September 9, 2026, is intended to coordinate the bureau’s 56 field offices and overseas operations against ransomware gangs, online fraud networks and state-sponsored hackers. It also commits the agency to expanding its cyber workforce and using artificial intelligence under human review and legal controls.

Brett Leatherman, assistant director of the FBI’s Cyber Division, said the strategy would align the bureau’s efforts around threats that are becoming more complex and frequent.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Four Pillars of the New Strategy

The FBI’s plan is organised around four priorities: disrupting adversaries, supporting victims, strengthening partnerships and improving the bureau’s own capabilities.

The first priority focuses on targeting the people, infrastructure, tools and money that cybercriminals depend on. Where arrests are possible, the FBI will pursue them. Where suspects remain beyond US jurisdiction, the bureau intends to disrupt their operations through other lawful measures.

That may include seizing criminal infrastructure, confiscating funds and dismantling services used to conduct attacks.

The approach recognises that cybercriminals can continue operating even after individual suspects are identified. Disrupting the systems that support them may reduce their ability to attack more victims.

Victims Will Become a Measure of Success

The strategy places greater emphasis on helping organisations and individuals affected by cybercrime.

Leatherman said the FBI should not measure success only through arrests or money recovered. Faster victim notifications, useful threat intelligence and assistance that helps contain an attack will also matter.

The bureau intends to engage victims quickly and provide specialised capabilities where available, even when an immediate enforcement action is not possible.

For a business facing ransomware, timely information about an attacker’s methods may help prevent further damage. For a fraud victim, rapid coordination can improve the chances of tracing funds before they are moved through additional accounts.

The strategy does not guarantee recovery or assistance in every case, but it establishes victim support as a central operational priority.

Private Companies to Become Operational Partners

The FBI wants to move beyond occasional information-sharing arrangements with the technology industry.

Leatherman said companies have sometimes hesitated to report incidents because they are uncertain about the FBI’s role or concerned that information could be shared with regulators. The bureau says it will clarify its obligations to protect information provided by victims.

The new approach seeks more sustained cooperation in operations against cybercriminal networks. Companies may possess technical information or control infrastructure that can help identify and disrupt malicious activity.

Leatherman cited previous cooperation involving companies including CrowdStrike, Microsoft and Google. The goal is to make such partnerships more regular rather than relying on individual, ad hoc arrangements.

What Does Disrupting Cyber Infrastructure Mean?

Cyber infrastructure disruption means interfering with the systems criminals use to carry out attacks, rather than only investigating the crime after it occurs.

For example, a ransomware group may rely on servers to communicate with infected computers, websites to collect payments and cryptocurrency wallets to receive proceeds.

Law enforcement may seek court-authorised control of servers, seize funds or work with service providers to disable malicious systems. These actions can make it harder for criminals to continue operating.

The FBI’s strategy also discusses imposing costs on adversaries, meaning increasing the financial, technical and operational consequences of their activities.

Such operations must be conducted under applicable legal authorities. The strategy does not give private companies unrestricted permission to hack other systems.

Secure 2027 and Critical Infrastructure

Leatherman also announced an initiative called “Secure 2027”, focused on strengthening critical infrastructure against cyber threats.

The effort will involve cooperation with government agencies and industry, including preparation for threats that could arise during a potential conflict involving China and Taiwan.

Critical infrastructure includes systems such as water, electricity, transport and communications. Attacks against these services can affect large numbers of people and disrupt essential operations.

The initiative is a defensive preparation measure. It should not be interpreted as evidence that a Chinese invasion is imminent or that a specific attack has been confirmed.

Detailed implementation plans for Secure 2027 have not yet been independently reviewed.

AI and Specialist Recruitment

The FBI plans to recruit and retain specialists including malware analysts, data scientists, cryptocurrency experts, intelligence analysts and technical investigators.

The strategy also identifies AI as a tool that could help investigators process large datasets, analyse malware, identify relationships between suspects and prioritise victim notifications.

For example, AI may help identify patterns across thousands of malicious transactions or connect pieces of infrastructure associated with the same criminal group. Human investigators would still need to assess the evidence and make decisions under legal controls.

The official announcement explicitly states that AI will be used under human review. The strategy does not authorise autonomous systems to make independent law-enforcement decisions without oversight.

What this means for you: For businesses, the strategy signals that reporting a cyber incident may lead to more direct technical assistance and cooperation with investigators. Organisations should preserve evidence, maintain incident-response plans and establish trusted law-enforcement contacts before an attack occurs.

For individuals, the basic reporting advice remains unchanged. If you become a victim of cyber fraud, contact your bank immediately and report the incident through the appropriate authority. In India, use 1930 or cybercrime.gov.in. Do not pay unknown recovery agents who claim they can retrieve stolen funds.

https://www.linkedin.com/company/policetechnology/

Stay Connected