Reporting Cybercrime to the FBI and Other Agencies

After a cyberattack, a business email compromise or a wire fraud, the first priority is to contain the damage. The second question many administrators ask is who they are supposed to tell. The answer depends on what happened, and the list is longer than most people expect. This post explains the main places to report, what to gather and what to expect afterward.

This is general information, not legal advice. Your attorney and cyber insurer should be involved early, because some reporting obligations are legal and some are voluntary.

Voluntary reports to law enforcement

FBI and IC3

The FBI's Internet Crime Complaint Center, known as IC3, accepts complaints about internet-enabled crime, including ransomware, business email compromise, fraud and extortion. You file online at ic3.gov. You can also contact your local FBI field office, which is particularly worthwhile for a serious attack such as ransomware or a major breach. Oklahoma, Texas and Arkansas each have FBI field offices and resident agencies.

CISA

The Cybersecurity and Infrastructure Security Agency (CISA) takes incident reports and shares threat information. Reporting helps CISA spot trends and warn others. CISA does not act as your investigator or regulator, but it can offer guidance and resources.

Secret Service and local police

The U.S. Secret Service investigates certain financial crimes, and has field offices that handle cyber-enabled fraud. A local police report can also be helpful, particularly for fraud or theft, and some banks and insurers ask for one.

State attorneys general and state agencies

Many states require notice to the attorney general when a breach involves residents of that state. Rules vary, so ask your attorney which states are involved.

Reports that may be required

HHS Office for Civil Rights

If protected health information is breached, HIPAA's Breach Notification Rule requires covered entities to notify affected individuals, HHS and, for large breaches, the media. Notice to individuals must be made without unreasonable delay and no later than 60 days after discovery. Breaches affecting 500 or more people must be reported to HHS within the same period, and smaller breaches are reported to HHS annually. Business associates have their own duty to notify the covered entity.

Other obligations

Cyber insurance: policies usually require prompt notice, sometimes within days, and may require you to use approved vendors. Late notice can jeopardize coverage.

Contracts: payers, partners and vendors may require notification.

Licensing and survey agencies: long-term care facilities should ask counsel whether state licensing or survey agencies need to be told, particularly if care was disrupted.

Financial institutions: report wire fraud to your bank immediately.

What to include in a report

Gather facts before filing, but do not delay a report on a financial fraud waiting for perfect information. For wire fraud, speed matters because banks may be able to recall funds if contacted quickly. Useful details include:

Dates and times of discovery and of the suspicious activity.

A short description of what happened.

Names and email addresses involved, including sender addresses and domains.

Phone numbers, bank account details and amounts for any financial loss.

Any ransom note, cryptocurrency wallet address and communication with the attacker.

Affected systems and what you have done so far.

Contact information for your organization and your lawyer or IT provider.

Preserve evidence. Keep logs, emails, screenshots and affected devices, and do not wipe systems before your response team advises.

What to expect afterward

Be realistic. An IC3 complaint does not guarantee that an agent will contact you or recover money. Reports are analyzed and combined with others, which can lead to investigations and, sometimes, to recovery. For serious incidents, agents may contact you for information, ask for logs and coordinate with your forensic team. They typically do not run your recovery or fix your systems.

Agencies generally cannot promise outcomes, and you should avoid paying a ransom without consulting counsel, since sanctions rules can be involved.

Prepare before you need it

Put agency contacts and your insurer's hotline in your incident response plan.

Name who is authorized to file reports.

Keep a template of the information above.

Practice in a tabletop exercise.

UnityCare IT helps healthcare and senior-living organizations in Oklahoma, Texas and Arkansas prepare incident response plans and collect the technical evidence needed for reports. If you would like to review your plan, we are happy to help.

Related service

Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172