WASHINGTON — The FBI on Wednesday said it intends to formalize and speed up its collaborative takedowns of malicious hacking activity.
The bureau’s new four-part strategy describes how it will investigate, attribute and disrupt cyberattacks; quickly engage with victims and share useful information; partner with other agencies and the private sector; and enhance its own capabilities through recruitment, training and new tools.
“Our strategy is really focused on moving beyond the ad-hoc way that we do [disruptions] right now … to do it in a more steady state,” Brett Leatherman, the assistant director of the FBI’s Cyber Division, said during a talk here at the Billington Cybersecurity Summit.
The FBI has already significantly increased the number of disruption operations it has led and participated in over the past few years. Recent high-profile takedowns have targeted a Russian military intelligence agency’s router botnet, domains that the Chinese government used to target U.S. critical infrastructure and the AlphV ransomware gang. But the bureau’s new strategy reflects government officials’ fear that even this increased tempo has not been enough.
The cyber threat environment “is becoming untenable for any one organization to defend alone, and we have to bring consistency in how we approach it,” Leatherman said. “Every day, we’re having to send teams out across the [FBI’s] 56 field offices to help victims who are continually under attack.”
As part of the new strategy, FBI teams focused on countering specific threats, from Russia to China to cybercriminals, will develop their own customized plans. Teams focused on specific kinds of operations, including offensive hacking and investigating operational technology breaches, will also develop tailored strategies.
Reassuring reluctant companies
One of the cyber strategy’s goals is to convince companies that they should report hacks to the FBI because it cares about helping them and won’t share their reports with regulators.
“We have [seen] a lot of hesitation recently from organizations to quickly provide information that would support law enforcement operations,” Leatherman told reporters after his talk.
The FBI has seen a reduction in companies’ willingness to share information over the past few years, a continuation of a long-running trend. “I don’t know exactly why that is,” Leatherman said. He attributed it partly to “uncertainty about the FBI’s value in cyber” and partly to “concern about the regulatory environment and what the FBI may or may not share with regulators.”
The bureau is trying hard to address companies’ concerns, including through summits with law firms that specialize in advising companies on incident response.
“It worries me,” Leatherman said of companies’ reluctance to engage with the FBI. “It worries me when an organization is breached by a nation-state actor and believes that bringing law enforcement in might be more risky than handling it on their own. That should worry all of us.”
No company, he argued, is better positioned to evict Chinese government hackers from their networks on their own than they would be with the FBI’s help.
“We see things through our cyber authorities that no incident response company sees,” Leatherman said during his Billington talk. “If you reach out to us early, we can bring threat intelligence tools and capabilities to bear that you can't get elsewhere.”
Leatherman urged executives to meet with their lawyers now to increase their comfort with engaging the FBI. “Too often, I see weeks move by where outside counsel is the gatekeeper of information going to the FBI,” he said. “Discussions happen on breached networks, and as a result of that, actors [have a] leg up and they can move in and entrench themselves even harder.”
Collaboration also benefits the broader ecosystem, he noted. “Victims reporting early and providing information early allows us to move upstream against actors that are quickly moving across infrastructure in the U.S., Europe and beyond.”
In the past, the FBI has been reluctant to share significant information with organizations that could help them protect themselves, for fear of jeopardizing its sensitive investigations. That has changed in recent years, Leatherman told reporters.
“We have changed significantly our perspective on sharing quickly and more often than maybe what we did in years past, where we would preserve it for operational opportunities,” he said.
That has required what Leatherman called “a culture shift” inside the FBI’s Cyber Division, where agents are used to zealously guarding the technical details of their work for fear of tipping off adversaries.
Now, “our posture is: share until it hurts,” Leatherman said. “What I always ask my team is, if the victim were sitting in this room right now, or the potential victim, would they want this information, and what is the compelling justification we have to not share this now to stop the impact versus taking an operation?”
“In every situation where we have intelligence, we have to take that victim perspective because they can’t voice it in that moment,” he added. If the bureau “can have an impact to hundreds of pieces of critical infrastructure, we should share that.”
Expanding hacking partnerships
A major theme of the FBI’s cyber strategy is the bureau’s desire to partner with more organizations on disruption operations. But its investigations may run into new problems as the Trump administration implements an initiative to let private companies hack foreign cybercrime gangs on behalf of the U.S. government. Experts have warned that uncoordinated cyberattacks could interfere with the FBI’s monitoring of foreign targets.
Leatherman told reporters that it was too early to predict the effects of the new White House initiative, noting that the Justice Department is still “working on understanding the lanes in the road as to how those authorities apply to industry versus law enforcement.” But he emphasized that DOJ and the Department of Homeland Security will approve and closely supervise private hacking activities.
“This is not a situation where industry is going to pick targets and go after targets themselves,” he said.
Meanwhile, the FBI’s new strategy envisions the bureau’s own disruptive operations increasing in frequency and scope.
“As opposed to waiting for large joint sequenced operations that happen half a dozen times a year,” Leatherman said, “you're going to start to see many more of those [operations] of consequence, because we are engaged in that urgent, steady-state opportunity to disrupt adversaries.”
The bureau’s goal is to “make industry an operational partner in this fight,” he said, “as opposed to just somebody we share threat intelligence back and back and forth with.”