How Does the FBI Combat Cybercrime Globally?

TL;DR
The FBI combats cybercrime by identifying the people behind attacks, combining criminal and national security authorities, and coordinating with private companies and foreign police. Its intelligence-driven approach also prioritizes network defense, including sharing threat indicators before attacks, because law enforcement tools alone cannot defeat cybercrime.
Transcript
Good afternoon, everyone. Good afternoon. Um, first of all, I wanna thank, uh, RSA, uh, for the invite, uh, for the FBI to come here and talk today. I'm honored, uh, that, uh, I'm getting the opportunity to represent, uh, the FBI in this discussion today. I think you'll find my, my talk, uh, of interest to you. Uh, Asia itself is very much a target... Read More
Key Insights
- The FBI's cyber mission is to identify, locate, arrest, and bring cyber actors to justice. Its investigative approach treats every intrusion as an act ultimately performed by a human behind a keyboard, making traditional investigative techniques relevant even when the evidence and activity are digital.
- The FBI Cyber Division handles both criminal and national security matters. It has approximately 2,500 cases, about 55 percent of which are criminal, while the remaining cases concern national security, illustrating how its workload spans distinct but frequently overlapping authorities.
- The FBI's cyber workforce is distributed across 56 field offices and 73 cyber squads. These squads combine technically trained agents, computer scientists, and analysts, with some focused primarily on crime, others on national security, and hybrid teams addressing both categories.
- Intelligence is the foundation of FBI cyber operations. Analysts are integrated with operational personnel to collect and process intelligence, produce useful findings, and determine how investigations and other activities should proceed rather than treating intelligence as a separate support function.
- Private-industry collaboration is necessary because cybercrime cannot be defeated through law enforcement tools alone. The FBI treats outreach as a formal mission, helping companies defend their networks while asking those partners to assist operations aimed at identifying and locating cyber actors.
- Pre-attack threat sharing can take priority over preserving an investigative advantage. The FBI may downgrade classified intelligence, provide companies with indicators and context, or publicly release information affecting critical infrastructure, even when disclosure could reduce its ability to use that intelligence against an actor.
- International police cooperation is essential because many intrusions affecting the United States originate overseas. The FBI uses legal attaché offices in United States embassies and places technically trained agents alongside foreign police colleagues to build trust, share systems, and strengthen local investigative capabilities.
- Low-technology attacks can be as effective as sophisticated tools because attackers often target people rather than technical controls. Social engineering and spear phishing can persuade an unsuspecting employee to provide access, allowing an attacker to compromise a network without advanced penetration code.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How does the FBI investigate and combat cybercrime?
The FBI focuses on the person responsible for an intrusion, reasoning that every cyberattack ultimately has a human behind the keyboard. It uses traditional investigative techniques to identify, locate, arrest, and bring cyber actors to justice. That work is supported by technical personnel, intelligence analysts, private companies, and foreign police partners because attacks can involve remote actors and cross national borders.
Q: How is the FBI organized to address cybersecurity threats?
The Cyber Division, established around 2002, addresses both criminal and national security cyber matters. Across the FBI's 56 field offices, 73 cyber squads bring together technically trained agents, computer scientists, and analysts. Some squads primarily investigate criminal activity, some concentrate on national security threats, and hybrid squads handle both, reflecting the overlap between these categories.
Q: Why is intelligence important to FBI cyber operations?
The FBI describes itself as an intelligence-driven organization, so intelligence collection is integrated into everything it does. Analysts work directly with operational personnel to receive and process information, create useful intelligence products, and guide future activity. This integration helps the bureau decide where threats are developing, how investigations should proceed, and which information may assist companies with network defense.
Q: Why does the FBI partner with private companies on cybersecurity?
Private-sector partnership is necessary because law enforcement tools alone cannot defeat cybercrime. Companies own and defend networks that attackers target, while the FBI investigates the people responsible. The relationship operates in both directions: the bureau shares intelligence, indicators, and threat context that support network defense, and companies help with takedowns, arrests, and operations intended to identify and locate cyber actors.
Q: When does the FBI share cyber threat intelligence before an attack?
The FBI may share intelligence when companies need actionable information to defend their networks, particularly when critical infrastructure is involved. It can downgrade material from classified to unclassified, send agents to a company before an attack, provide indicators, and explain the threat's context. The bureau may choose disclosure even when doing so limits its ability to use the same information to locate an actor.
Q: How does the FBI work with foreign police on cybercrime?
The FBI develops relationships with overseas police because many intrusions affecting the United States involve actors located abroad. It maintains legal attaché offices in United States embassies and strategically places technically trained agents within foreign police departments. Those agents work alongside local authorities, bring FBI systems into the collaboration, and help build capabilities for investigations and prosecutions within the countries where the activity occurs.
Q: Why can social engineering be as effective as advanced hacking?
Social engineering can succeed without sophisticated code because it targets a person who can provide access to an account or network. An attacker may send a spear-phishing message or impersonate an employee when contacting a service provider. If the targeted person clicks a link or resets a password, the attacker can gain access as effectively as someone using technically advanced penetration tools.
Q: What cybersecurity risks do insiders create for organizations?
Insiders can be malicious or unwitting. A malicious insider may seek employment under a plan, be recruited, or receive payment to steal proprietary research, military secrets, or other valuable documents. An unwitting employee joins without criminal intent but may expose the organization through unsafe network activity or by responding to a deceptive email. The remarks identify insider involvement as important across many intrusions.
Summary & Key Takeaways
-
The FBI approaches cyber incidents as human-driven crimes, using traditional investigative techniques to identify, locate, arrest, and prosecute actors behind keyboards. Its Cyber Division addresses both criminal and national security matters through approximately 2,500 cases, with technically trained agents, computer scientists, and analysts working across 73 cyber squads in 56 field offices.
-
Intelligence collection and private-sector outreach are central to FBI cyber operations. Analysts work alongside operational personnel to process information and guide investigations. The bureau also provides companies with threat indicators and context, sometimes downgrading classified intelligence or sacrificing investigative opportunities when disclosure can strengthen network defense, particularly for critical infrastructure.
-
Cybercrime frequently crosses national borders and involves overlapping actor types, including criminals, nation-state operators, hacktivists, malicious insiders, and unwitting employees. The FBI therefore works through legal attaché offices, embeds technically trained agents with foreign police departments, and builds trusted partnerships that support local investigations, prosecutions, arrests, and broader defensive capabilities.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator