Other β›“ Supply Chain

FBI DCS-3000 Surveillance Network Breach - China-Linked 'Major Incident'

πŸ“… 2026-02-17 🏒 FBI Digital Collection System Network DCS-3000 (Red Hook) - pen register and tap-and-trace surveillance infrastructure
Primary Source β†—

Incident Details

On February 17, 2026, the FBI began investigating abnormal activity in an unclassified system β€” DCS-3000 (known as Red Hook), part of its Digital Collection System Network (DCSNet) β€” used to manage court-authorized wiretaps, pen registers, and trap-and-trace surveillance operations. By March 4, the FBI formally notified lawmakers and labeled it a ‘major cyber incident’ under federal data security law. The breach was localized to FBI systems in the US Virgin Islands. The suspected intruders are China-linked (attributed with medium confidence to Salt Typhoon or related PRC actors by multiple reports). Attackers accessed PII of individuals under active FBI investigation and potentially the identities of surveillance targets, including wiretap subjects β€” a significant counterintelligence risk. Access was gained by exploiting a commercial ISP vendor’s infrastructure, consistent with prior Salt Typhoon telecom supply chain TTPs.

Technical Details

Initial Attack Vector
Threat actors leveraged a commercial Internet Service Provider's vendor infrastructure to access FBI systems; FBI systems in the Virgin Islands were compromised
Vendor / Product
FBI Digital Collection System Network DCS-3000 (Red Hook) - pen register and tap-and-trace surveillance infrastructure
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2026-02-17 Breach occurred
  2. 2026-03-04 Publicly disclosed