FBI

organization

Last mentioned: Apr 25, 2026

Timeline

  1. Exfiltration

    Victim is instructed to move funds to a 'safe' account or pay a fine using cryptocurrency or wire transfers.

  2. Coercion

    High-pressure tactics are used to prevent the victim from hanging up or verifying the story with others.

  3. The Hook

    Scammer claims the victim has an urgent legal issue, such as an outstanding warrant or unpaid tax debt.

  4. Initial Contact

    Victim receives a call or text from a spoofed number posing as a government official.

  5. FBI Alert Issued

    The FBI releases a nationwide warning detailing the phishing tactics used against secure messaging apps.

  6. Attribution Identified

    Threat intelligence firms link the phishing infrastructure to known Russian state-sponsored groups.

  7. Security Tool Rollout

    Meta introduces AI-powered scam detection for Messenger and device-linking alerts for WhatsApp.

  8. Global System Disruptions

    Reports emerge of medical systems and patient services being affected worldwide.

  9. Federal Investigation Launched

    U.S. authorities begin coordinating with Stryker to assess the scope of the state-linked attack.

  10. Mass Account Disabling

    Meta confirms the removal of 150,000 accounts and the arrest of 21 key suspects in Thailand.

  11. Initial Breach Detection

    Stryker security teams identify unauthorized access and data exfiltration activity.

  12. Handala Claims Responsibility

    The Iranian-linked group publicly claims the theft of 50TB of data as retaliation.

  13. Initial Reports

    Cybersecurity researchers detect a spike in suspicious Signal registration attempts.

  14. Global Sting Commences

    International agencies begin real-time intelligence sharing to target SE Asian scam compounds.

  15. Record Low Reached

    Payment rates hit an all-time low of 28% despite a surge in total attack volume.

  16. Pilot Operation Launched

    Meta and Thai police conduct a trial crackdown, removing 59,000 accounts and issuing six warrants.

  17. Resilience Milestone

    Payment rates drop below 40% for the first time as backup adoption matures.

  18. Colonial Pipeline Aftermath

    Increased law enforcement scrutiny and sanctions begin to discourage ransom payments.

  19. Peak Payment Rates

    Over 80% of victims were paying ransoms as encryption tactics were highly effective.

Stories mentioning FBI 5

security Bearish

FBI Warns of Russian Phishing Campaign Targeting Signal and Secure Apps

The FBI has issued a critical alert regarding a sophisticated phishing campaign orchestrated by Russian-linked threat actors targeting users of Signal and other encrypted messaging applications. The campaign aims to hijack accounts through social engineering, bypassing the platforms' robust end-to-end encryption by compromising the user's initial authentication process.

5 sources
security Bullish

Meta Disables 150,000 Accounts in Global Sting on SE Asian Scam Hubs

Meta, in coordination with the FBI and Royal Thai Police, has dismantled a massive network of over 150,000 accounts linked to organized crime syndicates in Southeast Asia. The operation targeted sophisticated 'scam factories' in Cambodia, Myanmar, and Laos responsible for billions in losses through romance and cryptocurrency fraud.

2 sources
Threat Intelligence Bearish

Stryker Targeted in Massive 50TB Data Breach Linked to Iranian Hackers

Medical technology leader Stryker has been hit by a significant cyberattack attributed to the Iranian-linked group Handala, resulting in the alleged theft of 50 terabytes of data. The incident, described as a retaliatory strike, has disrupted medical systems serving millions of patients and signals a sharp escalation in state-sponsored targeting of the healthcare supply chain.

2 sources

About FBI coverage

This page surfaces every story mentioning FBI across our cybersecurity coverage. We track each entity's appearance over time so readers can trace how the narrative evolves — which developments are isolated incidents, which build into longer arcs, and which reframe how operators in the space think about the entity. Story selection uses the same multi-source verification gate applied across the rest of our coverage.

Read our editorial methodology for how we identify, deduplicate, and score entity references. Our glossary defines the technical terms used across stories on this page, and our trends index contextualizes individual developments against the longer-running cybersecurity beat. Cross-entity comparisons live on our compare view.

What you seeWhat it tells you
Story countNumber of distinct stories where FBI was a primary or referenced actor.
Recency clusteringWhether mentions are concentrated in a recent window (a news cycle) or distributed (a sustained arc).
Sentiment distributionAggregate sentiment of the stories mentioning this entity, weighted by impact score.
Cross-niche linksWhen the same entity surfaces in our sibling networks, we link to those views to enrich context.