← All 142 executive actions

FBI Declares Suspected Chinese Hack of Its Own Surveillance System a "Major Cyber Incident" as Trump Publicly Dismisses Chinese Cyber Activity

Foreign Affairs Apr 1, 2026
Our Analysis: Concerning

Suspected Chinese state-linked hackers breached the FBI's Digital Collection System Network — the bureau's own wiretap and surveillance management infrastructure — exposing phone numbers and identifying information of active FBI investigative targets, and the FBI formally classified it a "major incident" under FISMA, a threshold rarely crossed.

The breach extends a pattern that includes the 2024 Salt Typhoon campaign in which Chinese hackers compromised U.S. telecoms and accessed audio calls and unencrypted communications from phones belonging to Trump and Vance themselves during the campaign — called by Sen. Mark Warner "the worst telecom hack in our nation's history."

Despite having been a personal target, Trump has publicly downplayed Chinese cyber activity ("That's the way the world works. It's a nasty world"), diverging sharply from his own National Cyber Director and NSC cyber officials who have called such behavior "unacceptable," while the administration simultaneously cuts CISA funding and federal cyber personnel.

Details

On April 1, 2026, Politico reported that the FBI had formally classified a suspected Chinese cyber intrusion into one of its internal surveillance systems as a "major incident" under the Federal Information Security Modernization Act (FISMA). The classification — reserved for breaches likely to cause "demonstrable harm" to national security — triggers mandatory congressional notification within seven days and is considered one of the most serious breach categories under federal data security law.

Former FBI cyber division deputy assistant director Cynthia Kaiser told Politico she was not aware of the FBI making such a declaration about a hack affecting its own systems since at least 2020. "Thresholds under FISMA are quite high, and only a few agencies declare a major cyber incident every year," she said.

What Was Compromised

According to the FBI's notice to Congress, as reported by Politico and Nextgov/FCW, the compromised system contained "returns from legal process, such as pen register and trap and trace surveillance returns, and personally identifiable information pertaining to subjects of FBI investigations."

Multiple specialist outlets, including reporting summarized by Homeland Security Today, identified the affected system as DCS-3000 (internally known as "Red Hook"), an unclassified component of the FBI's Digital Collection System Network (DCSNet) used to manage court-authorized wiretaps and foreign intelligence surveillance requests. The FBI and DOJ have not publicly confirmed that identification.

Pen register and trap-and-trace tools capture metadata — numbers dialed, routing data, and the identities of surveillance targets — rather than the content of communications. As one threat intelligence official told Nextgov, that metadata is a counterintelligence asset of significant value because it can reveal whom the U.S. is surveilling and allow foreign services to map relationships among intelligence targets.

How the Attackers Got In

FBI analysts first flagged abnormal activity on the network on February 17, 2026, and the bureau initially notified Congress of "suspicious activity" on March 4. According to the FBI's statement, the attackers did not breach the FBI's own perimeter directly:

"The FBI identified anomalous activity on an unclassified network and quickly leveraged all technical capabilities to remediate the incident. It was determined the access was obtained through a third party and constitutes a major incident under the Federal Information Security Modernization Act (FISMA)."

Politico reported that the FBI's notice characterized the intrusion as "leveraging a commercial Internet Service Provider's vendor infrastructure" — a supply-chain technique consistent with Salt Typhoon, the Chinese Ministry of State Security-linked hacking group previously documented as having breached at least nine major U.S. telecommunications carriers between 2019 and 2024. The FBI has not formally attributed the DCSNet breach to a specific group, though investigators have said the techniques are consistent with Salt Typhoon's tradecraft.

Context: A Pattern of Chinese Cyber Operations

The DCSNet breach is the latest in a documented series of Chinese state-linked intrusions into U.S. networks:

  • Salt Typhoon (2019–2024): Compromised at least nine major U.S. telecom carriers — including AT&T, Verizon, T-Mobile, and Lumen — siphoning call metadata from over a million Americans and, per Washington Post reporting cited in Sen. Chuck Grassley's oversight letter, collecting audio from phone calls and unencrypted communications including text messages from political figures. The FBI informed the Trump campaign in October 2024 that phones belonging to Trump and Vance had been targeted, as were staff of the Harris-Walz campaign. The hackers also accessed CALEA wiretap systems used by law enforcement for court-authorized surveillance. Sen. Mark Warner, then chairing the Senate Intelligence Committee, called it "the worst telecom hack in our nation's history."
  • Volt Typhoon: Embedded inside U.S. critical infrastructure including ports, water facilities, and energy substations.
  • Treasury / CFIUS (2024): Chinese hackers breached the Committee on Foreign Investment in the U.S., the office that reviews foreign investments for national security risks.
  • House committee emails (December 2025): Intrusions attributed to Salt Typhoon detected in email systems used by staff on the House China committee and panels covering foreign affairs, intelligence, and armed services.

Trump's Public Response to Chinese Cyber Activity

Trump has not publicly addressed the DCSNet breach directly, but his prior statements on Chinese cyber operations have been consistently dismissive. In a June 29, 2025 Fox News interview with Maria Bartiromo, when asked about Chinese hacking of U.S. telecoms and intellectual property theft, Trump responded:

"You don't think we do that to them? We do. We do a lot of things. … That's the way the world works. It's a nasty world."

Asked in August 2025 whether he would raise alleged Russian hacking of U.S. courts with Vladimir Putin, Trump told reporters: "I guess I could, are you surprised? … They hack in, that's what they do. They're good at it, we're good at it, we're actually better at it."

This posture contrasts with statements from Trump's own cyber officials. Alexei Bulezel, senior director for cybersecurity at the National Security Council, said in May 2025 of Salt Typhoon and Volt Typhoon: "We need to find some way to communicate that this is not acceptable." National Cyber Director Sean Cairncross said in October 2025 that "the United States has [not] done a tremendous job of sending the signal, in particular to China, that their behavior in this space is unacceptable."

Christopher Painter, who served as the top State Department cyber official under President Obama, told CyberScoop: "Either cyber and cyberattacks are a priority or they're not, and it's [a] problem if you communicate they're not serious by saying, 'Oh, we don't care now.'"

Congressional Response

Democrats called the breach evidence of broader administration neglect. Rep. Bennie Thompson (D-MS), the top Democrat on the House Homeland Security Committee, told Nextgov:

"Reports that China-linked threat actors compromised sensitive FBI systems are disturbing — and are even more evidence that the Trump administration has taken its eye off the ball when it comes to defending government and critical infrastructure networks from our adversaries."

Sen. Mark Warner (D-VA), vice chair of the Senate Intelligence Committee, told NBC News the incident illustrates the persistent threat posed by China and added: "What makes this even more concerning is that, at the very moment these threats are escalating, this administration has been systematically hollowing out the very cyber expertise we rely on to defend the country, pushing out experienced professionals at the FBI and at Cybersecurity and Infrastructure Security Agency."

Republicans largely did not publicly criticize the administration's response. The House Select Committee on the CCP posted on X that the intrusion showed "the CCP continues to test America's vulnerabilities." Rep. Andrew Garbarino (R-NY), chair of the House Homeland Security Committee, said the panel was in contact with CISA and emphasized the growing sophistication of PRC actors.

Cybersecurity Workforce and Budget Cuts

The breach occurred against a backdrop of significant reductions to federal cybersecurity capacity. Reporting by CyberScoop documented substantial personnel cuts at the Cybersecurity and Infrastructure Security Agency during the Trump administration's second term. A subsequent Trump budget proposal would cut hundreds of millions more from CISA.

A former senior cybersecurity official told NBC News that adversaries are aware of these reductions: "They've got awareness at this point that the federal government is fairly hollowed out. If you're an adversary thinking about intelligence collection, this is certainly a time to take advantage of this opportunity."

The Administration's Case

The administration and its defenders point to several actions and constraints:

The October 2025 trade framework with China. At the Busan summit on October 30, 2025, Trump and Xi reached a framework agreement. According to the White House fact sheet, China committed to halt the flow of fentanyl precursors, suspend new rare-earth export controls announced October 9, 2025, end retaliation against U.S. semiconductor firms, and resume large-scale purchases of U.S. agricultural products. Trump cut the fentanyl-linked tariff rate in half and maintained a one-year suspension of heightened reciprocal tariffs.

Indictments and bounties remain in place. On March 5, 2025, the Justice Department charged 12 Chinese nationals, including two Ministry of Public Security officers and eight employees of contract hacking firm i-Soon, in connection with global computer intrusion campaigns dating back to 2013. The State Department's Rewards for Justice program offered up to $10 million for information on i-Soon and the MPS officers, plus $2 million for APT27 actors Zhou Shuai and Yin Kecheng. The defendants remain at large.

A new national cyber strategy emphasizing offense. On March 6, 2026, Trump released a seven-page national cyber strategy organized around six policy pillars. Its first pillar — "shaping adversary behavior" — calls for using "the full suite" of U.S. offensive and defensive cyber capabilities to "detect, confront, and defeat cyber adversaries before they breach our networks." Analysis in Lawfare noted the strategy envisions an expanded role for private-sector companies in offensive operations and directs updates to foundational documents governing federal cyber authorities including NSPM-13 and PPD-41. National Cyber Director Sean Cairncross described the premise as moving "beyond reactive defense toward proactive operations."

Structural constraints from rare-earth dependence. Analysts have noted that China's dominance of rare-earth processing — roughly 90% of global capacity, essential to semiconductors, electric vehicles, and U.S. defense systems including the F-35 — gives Beijing leverage that complicates any aggressive U.S. retaliation until domestic supply chains mature. China's October 9, 2025 expansion of export controls erased over $1.5 trillion in market value within two days before the Busan framework suspended the controls for a year.

Expert Disagreement on Significance

Outside the administration, some analysts argue Trump's framing reflects reality. Michael Daniel, who held the top White House cyber position under Obama, told CyberScoop that "it's extremely difficult, if not impossible, to deter espionage." Erica Lonergan of Columbia University's School of International and Public Affairs noted: "We do it, because we all do it, and everyone knows we do it. … We're not going to go to war over cyberespionage."

Richard Harknett, director of the Center for Cyber Strategy and Policy at the University of Cincinnati, interpreted Trump's remarks as reflecting "confidence" in U.S. offensive capabilities rather than complacency.

There is also a long-running debate about whether cyberespionage — passive intelligence collection — rises to the level of a cyberattack. Former Director of National Intelligence James Clapper drew that distinction after the 2015 OPM hack, describing it as "passive intelligence collection activity" rather than a full cyberattack.

Critics of the new cyber strategy note gaps between its stated ambitions and the administration's actions. A Foundation for Defense of Democracies analysis observed that despite the strategy's "unapologetic" offensive posture, CISA's workforce had been "eviscerated" — reduced by roughly 40% under former DHS Secretary Kristi Noem — and that the strategy "falls short of identifying America's most aggressive adversaries — Russia and China." Former NSA leadership has separately warned that the U.S. offensive edge in cybersecurity is slipping.

Historical Contrast: The 2023 Chinese Spy Balloon

The dismissive tone around the DCSNet breach contrasts with the Republican response three years earlier to a different Chinese surveillance incident. In late January and early February 2023, a Chinese high-altitude surveillance balloon transited the continental United States before President Biden ordered it shot down off the South Carolina coast on February 4 — after Defense Secretary Lloyd Austin and Joint Chiefs Chair Gen. Mark Milley advised waiting until the balloon was over water to minimize risk to civilians on the ground.

Republican reaction was sharply critical. Then-House Speaker Kevin McCarthy tweeted that "China's brazen disregard for U.S. sovereignty is a destabilizing action that must be addressed, and President Biden cannot be silent." Many prominent Republicans — including then-former President Trump — called on Biden to shoot the balloon down earlier than he did, and House Republicans weighed a resolution condemning the administration's handling of the incident. Rep. Joe Wilson (R-SC) demanded Biden and Harris resign over what he called a "catastrophic Chinese spy balloon spectacle." Outside Congress, conservative commentators including Robby Starbuck and Jack Posobiec argued that those responsible should be "impeached and/or fired."

After the fact, the Defense Department acknowledged that similar Chinese balloons had transited U.S. airspace during the Trump administration but were only discovered after Biden took office. Erica Lonergan noted in her 2025 remarks on cyber deterrence that "we didn't go to war over the spy balloon" either — underscoring that dramatic Chinese surveillance episodes have repeatedly generated political heat disproportionate to the retaliatory measures ultimately taken by either administration.

The DCSNet intrusion involved direct, prolonged compromise of an internal FBI system holding identifying data on active surveillance targets — a substantially different magnitude of counterintelligence exposure than a balloon transiting at 60,000 feet. Public Republican reaction to the DCSNet breach has, to date, been limited to the House Select Committee on the CCP's general observation that "the CCP continues to test America's vulnerabilities."

Diplomatic Context

The breach landed as Trump prepared for a May 14–15, 2026 summit in Beijing with Xi Jinping, an initial meeting postponed from March. China has denied responsibility for Salt Typhoon and related campaigns; Chinese Embassy spokesperson Liu Pengyu has called the allegations "unfounded speculation" and accused the U.S. of using cybersecurity to "smear and slander China." U.S. intelligence agencies have attributed the campaign to China's Ministry of State Security with high confidence.