⚾ FBI Headquarters and SAC Jason Hudson gave a Texas-size welcome to our hometown two-time World Series champions, the Houston @astros. Staff members and their family visited the FBI Experience on Tuesday during the team's three-game D.C. series against the Washington Nationals. We hope you enjoyed your visit!
To learn more about the FBI Experience visit https://t.co/qHE6OzGex5
As we celebrate our country's 250th birthday, the #FBI reaffirms our commitment to uphold the laws of the United States and protect every American. We are proud to serve.
Have a safe and happy #IndependenceDay! 🇺🇸
#BREAKING Three individuals now face federal charges for allegedly flying drones in #FIFAWorldCup No Drone Zones:
1) Huu An Nguyen Dinh - received a warning from police just days earlier
2) John Alexander Meza
3) Jordan Lee Zale
Since the start of @FWC26Houston, the FBI and our partners have seized 28 drones. Don't want to be federally charged? Then don't fly in a #NoDroneZone!
Today, as part of Operation Endgame, the FBI joins our international law enforcement partners in announcing the disruption of SocGholish malware. SocGholish, active since 2018, is a Java-script based malware that masquerades as a legitimate browser update via compromised websites. The malware establishes an initial foothold into victim computers, collectively known as a botnet, and is then used by threat actors for further targeting with ransomware campaigns and espionage. As part of the operation, 106 servers and domains were taken down, 14,971 websites were remediated, the botnet was disabled, and victims were notified.
This action is part of Operation Riptide, an ongoing FBI campaign targeting the criminal actors, infrastructure, and financial networks behind cybercrime, cyber-enabled crime, and fraud against the American people.
Learn more: https://t.co/ob4ugpxmDG
Yesterday the FBI released an advisory on the Silent Ransom Group (SRG), aka Luna Moth, Chatty Spider, and UNC3753, who use social engineering techniques like phone calls and phishing emails to access victim computers. SRG actors have been steadily targeting law firms since 2023, and they focus on accessing victim systems, exfiltrating data, and extorting their victims by threatening to release or sell the stolen data.
Since SRG actors use legitimate remote access tools, there are few artifacts of their attacks. Review the advisory to learn how SRG actors operate to exfiltrate data and potential signs of SRG activity: https://t.co/JxQXleJNC8.
Today the FBI released a #PSA warning the public about Kali365—an emerging Phishing-as-a-Service (PhaaS) platform. Kali365, first seen in April 2026, enables cyber threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication (MFA) protocols without intercepting the user’s credentials. The platform allows less-skilled attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities.
Learn more about how the scam works and review recommendations on how to protect yourself: https://t.co/Ym8g4zRGNL
The 2026 @FIFAWorldCup is rapidly approaching here in the U.S., and this FBI has been working nonstop behind the scenes as one of the lead security agencies with our great interagency partners @DHSgov and more - led by the @WhiteHouse FIFA Task Force.
This is expected to be one of the largest sporting events ever held here in the U.S. with 48 national teams, 78 matches, 11 host cities, and millions of expected international visitors. We are building off of delivering safe and secure events at last summer’s Club World Cup, the 2026 Winter Olympics, F1 Grand Prix, and the Super Bowl.
Over the next few weeks we will be doing a daily highlight on specific, unclassified work we’ve been doing to give a behind the scenes look to the public on what your FBI does. Today’s highlight: The FBI’s National Counter-Unmanned Training Center (NCUTC) at Redstone Arsenal.
The NCUTC is the FBI’s new, first of its kind program training state and local law enforcement partners combatting the threat of drones. Unmanned aircrafts are increasingly exploited by criminals, terrorists, and hostile foreign actors - making the counter UAS program a critical area for the FBI to modernize and adapt particularly for large host events.
That’s where the NCUTC comes in. We train officers and employees of state, local, tribal, and territorial law enforcement and correctional agencies to safely detect, identify, track, and (when legally authorized) mitigate unlawful drone activity.
We started this after President Trump signed an executive order in June of 2025 directing recommendations for the creation of a National Counter-UAS Training Center. FBI got up and running quickly, had our first class in 2025, and had our latest class graduate this last weekend – a major success in helping us be better prepared for high volume events.
Stay tuned for more in the days ahead on how this FBI is working 24/7 to stay ahead of threats and protect the American people ahead of the World Cup and beyond.
The FBI’s Criminal Justice Information Services Division has an important mission – to get criminal justice information to our agents and law enforcement partners on the front lines, when and where they need it. This is done 24/7/365 and is made possible by combining what we know with tools and technologies from our industry partners. On Wednesday, the #FBI hosted more than 250 private sector partners to engage on the newest and upcoming technologies that will help keep us ahead of the threat.#FBI #YourFBI is committed to keeping you and criminal justice information secure.
A new digital #forensic examiner opportunity is coming soon to the #FBI. Apply your #TechnicalSkills to recover and analyze #digital evidence supporting investigations. Be a part of creating a safer, more secure future. Learn more today. #FBIJobs#Cyber
https://t.co/Oy9o0YDG0u
The FBI is aware of a service disruption affecting an online Learning Management System (LMS). This disruption has impacted schools, educational institutions, and students across the country.
If you are contacted directly by anyone claiming to have your data, we recommend you not send payment or respond to their demands. By receiving a message, that does not necessarily mean your personal information has been compromised. Threat actors often exaggerate or fabricate their access to sensitive or personal information to prompt payment from victims. We encourage individuals to be cautious of unsolicited emails, calls, or texts claiming to be from your school, the LMS provider, or law enforcement and to verify the contact through known channels before responding.
We understand that the immediate concern for individuals/students is determining what, if any, of their data or other sensitive information may have been exposed. At this time, the strongly recommended course is to await formal guidance from your educational institution regarding the scope of the incident and the nature of any affected data.
If you believe you have been impacted by the attack, please file a complaint at https://t.co/DbJcDzldwF.
All crimes can have a devastating effect on those who have been impacted, as well as their families who may need help coping with what happened. Visit https://t.co/QkwTszk8Dx for more resources on coping with the impact of crime:
⚫ https://t.co/wC1eqXwymH
⚫ https://t.co/MMU78iJw0i
The FBI is aware of a service disruption affecting an online Learning Management System (LMS). This disruption has impacted schools, educational institutions, and students across the country.
If you are contacted directly by anyone claiming to have your data, we recommend you not send payment or respond to their demands. By receiving a message, that does not necessarily mean your personal information has been compromised. Threat actors often exaggerate or fabricate their access to sensitive or personal information to prompt payment from victims. We encourage individuals to be cautious of unsolicited emails, calls, or texts claiming to be from your school, the LMS provider, or law enforcement and to verify the contact through known channels before responding.
We understand that the immediate concern for individuals/students is determining what, if any, of their data or other sensitive information may have been exposed. At this time, the strongly recommended course is to await formal guidance from your educational institution regarding the scope of the incident and the nature of any affected data.
If you believe you have been impacted by the attack, please file a complaint at https://t.co/Y65F8KJfqo.
All crimes can have a devastating effect on those who have been impacted, as well as their families who may need help coping with what happened. Visit https://t.co/9AqIPEVFmM for more resources on coping with the impact of crime:
◾https://t.co/DkdlfncMAc
◾https://t.co/C7pDUTNb5E
⚽ For well over a year, FBI Houston, and dozens of our partner agencies, have been prepping for the upcoming #FIFAWorldCup matches that start in Houston next month.
Public safety is our priority. It should be yours, too. #WeAreHouston
Virtually every major success you see out of the new FBI today under President Trump is a direct result of Dan Bongino’s work.
He didn’t have to do it, but chose to step away from a lucrative career to serve.
Now the new FBI is arresting bad guys at a record clip, communicating with the American people more than ever before, breaking down bureaucracy every day, and has an entirely new enterprise operation with more accountability mechanisms and better operations across the board.
None of it would’ve been possible without his work.
Thank you @dbongino. 🇺🇸
Weaponization of the USG by its senior members in a time of global pandemic, who were entrusted to protect us. They violated that trust and the law- destroyed records the public had every right to see. They covered up and got caught by this @FBI and @TheJusticeDept
https://t.co/C9kDW4UtXm
🟥 Drones near Houston Stadium? That's a red card.
🚫 World Cup venues and fan festivals are No Drone Zones.
🙅♂️ If you fly drones illegally, you will be prosecuted. #FIFAWorldCup
When the “ransomware negotiator” is working both sides, you don’t just have a ransomware problem — you have an insider threat problem at the worst possible moment.
This case is exactly why incident responders and negotiators need real vetting, segregation of duties, and independent monitoring of access and communications during an event — not blind trust because someone shows up with a cybersecurity title. 🧐
Last night, Shamim Mafi, 44, of Woodland Hills, was arrested at Los Angeles International Airport for trafficking arms on behalf of the government of Iran. She is charged with a violation of 50 U.S.C. § 1705 for brokering the sale of drones, bombs, bomb fuses, and millions of rounds of ammunition manufactured by Iran and sold to Sudan.
If convicted, she faces a statutory maximum sentence of 20 years in federal prison.
Mafi is an Iranian national who became a lawful permanent resident of the United States in 2016.
She is expected to make her initial appearance on Monday afternoon in U.S. District Court in downtown L.A. She is presumed innocent until proven guilty in court.