FBI warns private firms won’t share enough cyber threat data—while AI token theft and MFA bypasses surge
On September 9, 2026, the FBI’s top cyber official, Assistant Director Brett Leatherman, said the private sector is still not sharing enough cyber threat information with the bureau. He attributed the gap partly to companies operating on false assumptions about how the FBI will handle the intelligence it receives. The same day, reporting highlighted a new wave of AI-focused account compromise techniques, where “information stealer” logs can produce replayable AI tokens that bypass multi-factor authentication (MFA). Separately, another analysis warned that attackers are shifting toward account recovery workflows—reset and identity-verification steps used to regain access—turning them into a new attack path. Taken together, the cluster points to a widening public-private cybersecurity intelligence problem at the exact moment threat actors are exploiting authentication and identity processes at scale. The FBI’s concern suggests a strategic mismatch: industry may be withholding actionable indicators, while adversaries are accelerating tactics that rely on stolen session artifacts, tokens, and social-engineering leverage. This dynamic benefits cybercriminals and potentially state-aligned operators by reducing defenders’ situational awareness and slowing coordinated response. It also raises pressure on US regulators and critical infrastructure operators to tighten data-sharing frameworks, incident reporting, and identity assurance practices, because the “weakest link” is increasingly procedural rather than cryptographic. Market and economic implications are most visible in cybersecurity spending and risk pricing rather than in direct commodity moves. Demand is likely to tilt toward identity and access management (IAM), MFA hardening, secure account recovery, and endpoint/log protection, with vendors positioned around “stealer” detection and token/session security gaining attention. Publicly traded names in the broader cyber-defense complex—such as CrowdStrike (CRWD), Palo Alto Networks (PANW), and Okta (OKTA)—could see sentiment support as buyers prioritize authentication resilience and incident response readiness. In the near term, insurers and enterprise risk teams may also reprice cyber premiums for organizations with weak recovery desk verification, increasing total cost of ownership for IAM and security operations. The next watch points are whether the FBI and industry move from voluntary information sharing to more operationally trusted pipelines, including clearer handling rules and faster feedback loops. On the threat side, defenders should monitor for indicators tied to replayable AI tokens and for abuse patterns targeting help-desk or service-desk recovery flows, including identity proofing failures. A key trigger for escalation would be evidence of widespread compromise of accounts tied to model-provider tooling (e.g., Google and Anthropic ecosystems) using token replay rather than brute-force. Over the coming weeks, the most actionable signals will be incident disclosures, updates from identity-security vendors like Specops, and any FBI guidance that changes how private firms package and submit threat intelligence.
Geopolitical Implications
- 01
US public-private cyber intelligence friction could weaken national resilience as identity attacks scale.
- 02
AI-enabled token theft raises identity assurance and incident reporting to national security priorities.
- 03
If sharing norms don’t improve, critical services depending on model-provider tooling face higher operational risk.
Key Signals
- —FBI guidance on handling and feedback for shared threat intel.
- —Incidents showing replayable AI tokens and session artifact abuse.
- —Enterprise rollouts tightening service-desk identity verification and recovery controls.
- —Cyber insurance underwriting changes tied to recovery workflow strength.
Topics & Keywords
Related Intelligence
Full Access
Unlock Full Intelligence Access
Real-time alerts, detailed threat assessments, entity networks, market correlations, AI briefings, and interactive maps.