'The FBI Called' Now Proves Nothing
A financially motivated extortion crew traded profit for revenge — and handed every impersonator a verified federal-agent roster while quietly breaking the 'pay and they delete' assumption your extortion playbook still rests on.
Threat Briefing
Someone else has already done the reconnaissance for the next round of fraud against your company. For years, criminals have used fraudulent emergency data requests (EDRs) to pry subscriber data out of tech firms, and the scam's weak point was always plausibility: the named agent might not exist, or might not sit at the claimed field office. A circulating roster of real agents — names, offices, specialties, phone numbers — erases that weakness at the scale of an entire agency.
This is T1589 (Gather Victim Identity Information) done at industrial scale, feeding downstream T1656 (Impersonation) and T1566.004 (vishing). The scenarios are concrete: a fraudulent EDR seeking subscriber data to enable a SIM swap; help-desk vishing that invokes an "urgent federal investigation" to justify an MFA reset; a fake agent inserted into your live incident response to harvest IOCs and victim data.
Attack Surface Analysis
Two shifts matter beyond the pretexting kit. First, the crew defaced the Bureau's jobs site — a peripheral property (T1491.002, External Defacement) used purely as coercive leverage, not as a route to access. Careers portals and marketing CMS instances are usually third-party hosted, owned by HR or marketing, and rarely feed your SOC. For an actor optimizing for embarrassment, they are the cheapest leverage available.
Second, and more corrosive to your playbook: a top-tier data-extortion crew traded profit for notoriety and revenge. That breaks the assumption baked into most extortion runbooks — that payment buys deletion and silence.
| Dimension | Financially motivated (prior) | Retaliation / notoriety (now) |
|---|---|---|
| Objective | Payment | Humiliation, forced concessions |
| Target selection | Data-rich firms able to pay | Whoever crossed the group |
| Predictability | Incentives legible | Escalation is the point |
| What it means for you | Standard playbook applies | No deletion guarantee; model re-extortion |
This story also compounds a second pattern in this briefing: with AI-polished lures and cheap voice cloning, a correct agent name, office, and specialty is now zero evidence of identity. Fluency and plausibility have both stopped functioning as trust signals.
Your Defense Playbook
- Verify every law-enforcement request out of band. Route all LE contact through one Legal-owned intake queue, and call back on a field-office number sourced independently from fbi.gov — never the number in the request or signature.
- Brief the people who answer the phone. Help desk, Trust & Safety, legal ops, and the SOC must treat an accurate-looking federal identity as an unverified claim.
- Rewrite the extortion playbook for ego-driven actors. Assume payment buys neither deletion nor silence; pre-draft defacement and leak communications for counsel review, and bring peripheral web properties under SOC visibility.
With a roster of real FBI agents circulating, 'the FBI called' proves nothing — independently verify every law-enforcement request before your company discloses any data.
What to do
Route all law-enforcement contact through one Legal-owned intake queue and require callback verification on a field-office number sourced independently from fbi.gov this week — never the number in the request.
Add an FBI-impersonation scenario to the next vishing simulation and issue a targeted bulletin to help desk, legal ops, executive assistants, and the SOC this week.
Rewrite the extortion and data-leak IR playbook this quarter to assume payment buys neither deletion nor silence, and pre-draft defacement communications for counsel.