FBI

10 items · Policy 1 · Defense 2 · Attacks 7 · all entities

CISA and the FBI say a compromised US automation firm handed actors customers' SCADA data

In a joint product for critical-infrastructure operators working with third-party ICS integrators, CISA and the FBI describe actors who compromised a US industrial automation company serving utilities and transportation entities between March and April 2025, "searched terms, including 'customers' and 'SCADA,'" and "created nine .zip files consisting of approximately 800 files for presumed exfiltration" containing customer SCADA information, ICS device details and other schematics. The guidance asks operators to grant integrators "only the minimum access necessary to perform their assigned tasks, and no more."

On the recordCISA and FBI ↗ ·

Coast Guard and FBI cyber teams boarded two Texas-bound tankers after attacks on their systems at sea

Rear Adm. Amy Grable, commander of Coast Guard Cyber Command, said investigators who boarded the Liberian-flagged crude tanker VL Prosperity on August 21 “did find malicious cyber activity”; a second Texas-bound tanker was also boarded, and the US is investigating whether the attacks are linked. Iranian state media claimed hackers reached the ship's propulsion, navigation and cargo systems and cut communications for 30 hours from August 7; the US has not attributed the attacks, and the Coast Guard found no evidence the ship had become unsafe to navigate (via CBS News).

Reported by pressCBS News ↗ ·

The Chinese Communist Party's own newspaper rejects the US distillation allegations and warns of countermeasures

A People's Daily commentary rejected the US allegation that Chinese AI companies ran industrial-scale distillation against American frontier models as “without factual or legal basis,” accused Washington of “politicising” a normal technical and commercial practice, and said Beijing would take “countermeasures” if the allegation were used as a pretext to suppress Chinese companies' development. The allegation was made in the September 8 NSA/CISA/FBI joint advisory that named six Chinese labs; China's commerce ministry rejected it on September 10, and the Party newspaper's commentary lands ahead of a Xi–Trump meeting expected on September 24.

Reported by pressPeople's Daily (via South China Morning Post) ↗ ·

Anthropic names seven China-based AI companies it says ran industrial-scale distillation against Claude

The Hacker News, reading Anthropic's September 2026 misuse report, says the company attributes illicit distillation campaigns to seven China-based labs and gives each a tracking identifier: Alibaba (GTG-16005), Moonshot AI (GTG-16002), DeepSeek (GTG-16001), Zhipu/Z.ai (GTG-16006), Xiaomi (GTG-16008), SenseTime (GTG-16012) and MiniMax (GTG-16003). It reports 151 million exchanges attributed to Alibaba from more than 3,500 fraudulent accounts between May and July 2026, 23 million to Moonshot from 5,380 accounts over the same window with almost 300,000 customer requests relayed in ten days, and more than 12.1 million to DeepSeek over 14 days in July. Five of the seven — Alibaba, Moonshot, DeepSeek, Z.ai and MiniMax — also appear in the September 8 NSA/CISA/FBI advisory; Xiaomi and SenseTime do not, and StepFun, which the advisory names, is not among Anthropic's seven.

Reported by pressAnthropic (via The Hacker News) ↗ ·

NSA, CISA and FBI name six China-based AI companies running industrial-scale distillation campaigns against US frontier models

The joint advisory says DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI “extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models” — naming the Claude, GPT, Gemini and Grok families — “since at least late 2024,” routed through a gray market of API proxies the advisory calls “transfer stations,” which resell frontier-model access below official prices, and through pools of accounts running concurrent sessions with load distribution. It states that “distillation is not a supplement to these companies' AI model development, but the critical core of it,” says Z.AI distilled “billions of tokens of GPT-5.5 data and Claude Opus 4.8 data,” and calls DeepSeek's publicly quoted $5.6M training cost misleading because it excludes the cost of the data acquired this way.

On the recordNSA / CISA / FBI ↗ ·

FBI, NSA and Cyber National Mission Force say a China-linked group has been integrating AI into its operations

A joint advisory attributes the group it tracks as QTFY to Nanjing Xinjiuwei Network Technology Co. and describes malicious distributed platforms used against defense industrial base, communications, government, higher education, energy, information technology and water and wastewater targets. The advisory states the actors “have also been observed heavily researching and integrating AI into their processes over the last two years.”

US agencies warn attackers are using AI-generated scripts to target Siemens S7 industrial controllers

A joint advisory (AA26-231A) from the NSA, CISA, FBI, DOE and EPA warned that threat actors are running persistent reconnaissance and capability development against internet-exposed Siemens S7 programmable logic controllers with weak or default credentials, and are using AI-assisted development to rapidly iterate exploit code — including AI-generated Python scripts that call the snap7.dll library to read PLC memory and configuration. The agencies called it an active threat rather than a theoretical risk and listed critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities as targeted sectors; no threat actor was attributed.

On the recordNSA / CISA / FBI / DOE / EPA ↗ ·

FBI and EPA alert on actors targeting internet-facing water-sector PLCs across at least seven states

The FBI issued an alert stating that since 27 July 2026 at least seven states have reported incidents in which malicious cyber actors changed IP addresses and passwords on internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs at water and wastewater utilities, causing loss of monitoring and control functionality, with operational impacts including loss of pressure and flooding. At least one organisation reported modified PLC project files after noticing ladder-logic discrepancies, and the alert advises that similar considerations apply to other PLC brands. The alert names no actor, state or country. Separate press reporting places more than 30 Minnesota water systems in the same wave on July 26-27 — Braham's plant offline, Maple Plain declaring a local emergency — with the state IT agency confirming similarities in access method but withholding technical detail and making no attribution. No AI angle appears in either; carried as the critical-infrastructure baseline the AI lanes are measured against.

On the recordFBI ↗ ·

Seventeen agencies update the minimum elements for a software bill of materials, and leave AI systems to separate guidance

CISA, NSA, FBI and international partners including Australia, Canada, Czechia, France, Germany, India, Italy, Japan, South Korea, the Netherlands, New Zealand, Poland and Slovakia updated the 2021 NTIA baseline, adding ten data elements including SBOM Author Signature, Component Hash Value and Component License. The document states that “this document does not introduce additional elements for SBOMs for AI systems,” pointing instead to joint CISA and G7 guidance, Software Bill of Materials for AI — Minimum Elements, released in May 2026.

US advisory: Iran-linked actors manipulating Rockwell, Siemens and Schneider PLCs

A US government advisory (CISA/FBI/NSA/EPA), updated July 22, warns Iran-linked actors are using vendors' own engineering software to alter project files on Rockwell, Siemens (S7-1200) and Schneider (Modicon M340) PLCs — disabling shutdown and alarm logic at US water, energy and government facilities, with at least one confirmed US victim. No direct AI angle, but a strategically significant critical-infrastructure escalation.

Confirmed by orgSecurityWeek ↗ ·