Skip to main content
CybersecurityHacking

FBI Warns AI Bolsters Malicious Hackers, Urges Focus on Cyber Basics

Government briefing room with podium, laptop, and chairs near tall windows.

"The wave is coming. I don’t think we’ve hit the crest yet," Jason Bilnoski, the FBI’s deputy assistant director for its cyber division, warned Tuesday.

Jason Bilnoski on AI-augmented attackers

Speaking to CyberScoop and at the Billington CyberSecurity Summit, Bilnoski said artificial intelligence is “taking actors to the next level,” increasing both the speed and capability of offensive cyber activity. He framed the change as measurable already — noting AI-enabled attacks appear in a new section of the FBI's annual report on digital crimes — and said the bureau sees “an exponential increase in the use of AI, whether it’s nation-state or criminal.”

Despite the rising sophistication, Bilnoski emphasized that many successful intrusions still exploit fundamental lapses. He said adversaries repeatedly take advantage of failures to follow “basic cyber hygiene principles,” and he cited the bureau’s recent emphasis on 10 fundamental defensive measures such as multifactor authentication. “If we can harden up those top 10 controls that we talked about, it would certainly reduce the risk of both criminal and nation-state targeting of our environment,” he said.

Colleen Ferranti on patching pacing

At the same Billington event, Colleen Ferranti, assistant section chief for the cyber engagement and intelligence section, warned that AI models are revealing vulnerabilities faster than organizations can respond under traditional schedules. “We no longer can essentially do the quarterly patching,” she said, and urged a move to “more risk-based type patching” and continuous approaches.

Ferranti pushed the metaphor further: Patch cycles tied to Patch Tuesday or quarterly maintenance windows are insufficient, she argued, because organizations must be able to “engage with that type of technology and at that speed and that level.” Her prescription is operational: patch “all of the time,” guided by risk prioritization, rather than waiting for periodic rollups.

FBI Cyber strategy: AI-enabled tools, CNO, and operational language

The remarks came one day before the FBI released a new cyber strategy that explicitly incorporates artificial intelligence into defenders’ toolsets. The strategy states: “FBI Cyber will deploy AI-enabled tools to triage large datasets, surface relationships, accelerate malware analysis, prioritize victim notifications, map adversary infrastructure, support attribution, and identify patterns that no human analyst could process at the required pace.”

It further commits the bureau to adopt “agentic AI” in line with a White House-level cyber strategy, stating: “Consistent with President Trump’s Cyber Strategy for America, FBI Cyber will rapidly adopt agentic AI in ways that securely scale defense and disruption, and will implement AI-enabled tools to detect, divert, and deceive threat actors where operationally appropriate.”

The strategy also affirms continued development of the bureau’s Computer Network Operations (CNO) program, saying the FBI “will continue to develop its Computer Network Operations (CNO) program, providing investigative teams with the court-authorized or otherwise lawfully authorized technical operations tools to remotely collect, conduct surveillance, and disrupt the activities of nation-state and cybercriminal actors when traditional investigative techniques will not achieve the required outcome.”

Relief for victims, privacy protections, and field-level capacity

Alongside operational commitments, the strategy contains a stated pledge toward victims: “Pursuing our mission, we recognize that we will encounter unique and novel issues related to privacy and the handling of sensitive data. We will always treat victims with dignity and respect, protect their privacy and data, and rigorously adhere to the U.S. Constitution; applicable laws, regulations, and policies; and the FBI’s Core Values.”

The document also promises faster intelligence sharing and incident response, and a specific capacity-building measure: expanding the bureau’s Industrial Control Systems (ICS) Coordinator program to “designate dedicated personnel in every field office.”

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: Expect pressure to shorten patch windows and adopt continuous, risk-based patching models that match faster vulnerability discovery, as Colleen Ferranti urged.
  • Policymakers and regulators: The strategy’s explicit move to deploy “agentic AI” and to expand CNO tools raises questions for those setting legal and oversight frameworks, especially where the FBI frames operations as “court-authorized or otherwise lawfully authorized.”
  • Affected enterprises and procurement leaders: Bilnoski’s repeated emphasis on the top 10 defensive controls – including multifactor authentication – signals that basic hardening will remain central to reducing exposure even as adversaries use AI to scale attacks.

The FBI’s public posture combines two parallel threads: an acknowledgment that adversaries are using AI to accelerate and scale attacks, and a belief that adherence to foundational cyber hygiene and faster operational processes can blunt that threat. Whether organizations will shift from periodic maintenance to the continuous, risk-based patching the bureau prescribes — and whether the bureau’s own AI and CNO investments will yield faster disruption without constitutional or privacy trade-offs — are the immediate tests implied by the strategy and the officials’ remarks.

Original CyberScoop story