FBI cyber chief says bureau won't feed breach data to regulators
Leatherman's reassurance targets the general counsel, not the CISO, and it arrives while DOJ's Civil Cyber-Fraud Initiative and CISA's CIRCIA rulemaking are both formalizing the regulatory machinery he's distancing the FBI from.
TL;DR
FBI cyber division head Brett Leatherman said Wednesday that one of the "key misconceptions" keeping companies from sharing breach data is the belief that the FBI passes it to regulators. "That's not the case," he told the Billington CyberSecurity Summit. The bureau has adjusted its internal threshold for sharing threat intelligence with victims, adopting a "share until it hurts" posture that inverts the default from protecting operations to protecting victims unless there's a compelling reason not to. A new FBI cyber strategy published Wednesday codifies victim remediation and threat pursuit as intertwined rather than competing priorities.
Leatherman's pitch is not new. The FBI has been making versions of this argument since at least the 2019 ransomware summit in Pittsburgh, when Herb Stapleton, then cyber division section chief, told attendees the bureau needed industry to "fill in some of the gaps in the intel." The structural problem hasn't moved much since. Companies still weigh the risk of bringing in law enforcement against handling a breach quietly, and the quiet path often wins.
The audience that matters here isn't the security team. It's the general counsel. Leatherman's remarks about "outside counsel summits" are a nod to that reality: the FBI is walking corporate lawyers through what the bureau actually does with breach data because the lawyers are the ones who say no. The reassurance that FBI cyber doesn't share with regulators is aimed squarely at that decision-maker.
But it lands in a complicated moment. DOJ's Civil Cyber-Fraud Initiative is actively pursuing contractors under the False Claims Act for misrepresenting their cybersecurity posture. CISA's CIRCIA rulemaking is formalizing mandatory incident reporting requirements. Leatherman is drawing a hard boundary around his division: the FBI's cyber arm doesn't feed that machinery. Whether corporate counsel will treat that boundary as durable (particularly when other parts of DOJ are building the cases) is the question the reassurance doesn't fully answer.
The operational shift is nonetheless real. "Share until it hurts" inverts the default from "protect the investigation" to "protect the victim, unless." Leatherman framed it as a standing question to his team: if the victim were in the room, would they want this information, and what's the compelling justification for withholding it? The new cyber strategy, published Wednesday, codifies that posture, remediation and investigation as the same mission, not competing ones.
Published ·Deep Fathom