Home / Blog / FBI arrests another suspected ShinyHunters hacker after…
Tech News

FBI arrests another suspected ShinyHunters hacker after agency breach

The FBI arrested a suspected ShinyHunters co-conspirator in Pennsylvania linked to last month's breach of FBIjobs.gov, Director Kash Patel announced Friday.

By Dillip Chowdary • Oct 10, 2026 • Source: BleepingComputer

FBI arrests another suspected ShinyHunters hacker after agency breach

The FBI has made another arrest in its accelerating crackdown on the ShinyHunters extortion group, with Director Kash Patel announcing Friday that agents had apprehended a suspected co-conspirator linked to last month's breach of FBI systems. According to BleepingComputer's report, The New York Times identified the suspect as a Canadian citizen taken into custody in Pennsylvania, described by sources as a primary co-conspirator in the intrusion into FBIjobs.gov. Authorities have not publicly released the suspect's name or the specific charges filed against him.

This article covers the full timeline of law enforcement actions against ShinyHunters since the FBI breach, what data was stolen, who is affected, and where the investigation now stands. It is relevant to security professionals, federal employees, job applicants who used FBIjobs.gov, and anyone whose data may have passed through systems targeted by the group over the past two years.

What broke in FBI arrests another suspected ShinyHunters

ShinyHunters told reporters in September that it accessed FBI systems by exploiting an alleged Oracle PeopleSoft zero-day vulnerability and then moved laterally into FBI-managed AWS GovCloud infrastructure. The FBI later confirmed the incident originated on a third-party contractor-managed platform that had failed to install a security update. The threat actors claimed to have exfiltrated between 2TB and 3TB of data, and data samples shared with multiple media outlets confirmed the breach was real and wide in scope.

An internal FBI memo, reported by The New York Times, stated that the agency assumed the breach had affected all employees — not a subset. The compromised platform was FBIjobs.gov, described by Patel as a site "managed by a third-party vendor." The FBI has not named the contractor or specified which security update was skipped, but the admission that a patch was simply not applied points to a fundamental vendor management failure rather than a novel attack that could not have been stopped.

Who is exposed by FBI arrests another suspected ShinyHunters

FBI arrests another suspected ShinyHunters hacker after agency breach
Illustration · Pexels

Data samples confirmed by BleepingComputer and other outlets showed that the breach exposed home addresses, Social Security numbers, sensitive job assignments, information about employees' family members, and other personal data belonging to current and former FBI employees as well as job applicants. Medical and psychiatric records and internal service records were also among the categories of data the attackers claimed to hold. Because the FBI's own internal memo assumed the breach affected all employees, the potential victim count spans the entire workforce.

Job applicants who submitted information through FBIjobs.gov are also at risk, since the stolen data included applicant records. The exposure of home addresses and family information raises physical safety concerns beyond typical financial fraud scenarios, particularly for agents working sensitive assignments. No public notification process for affected individuals has been announced as of the arrest Friday.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

What to do now about FBI arrests another suspected ShinyHunters

Current and former FBI employees and anyone who applied for a position through FBIjobs.gov should assume their personal information — including Social Security numbers and home addresses — has been compromised and act accordingly. That means placing a credit freeze with the three major bureaus, enabling fraud alerts, and monitoring for any contact attempts that reference personal details an attacker could use for social engineering. ShinyHunters has a documented history of voice phishing campaigns impersonating IT support personnel, so employees at connected agencies should be on heightened alert for vishing calls.

More broadly, organizations relying on third-party platforms for sensitive data collection should audit vendor patch compliance immediately. The FBI breach was enabled by a missed security update on a contractor-managed system — a failure that standard vendor risk management processes are supposed to catch. FBI Cyber Division Assistant Director Brett Leatherman's public message to ShinyHunters members — "The longer you stay in this, the more we learn about you" — signals that the bureau believes it has sufficient intelligence to continue arrests and is pressing associates to cooperate before more infrastructure is seized.

How the FBI arrests another suspected ShinyHunters issue works

ShinyHunters operates as both a direct data-theft group and an extortion-as-a-service platform that assists other threat actors in monetizing breaches. In its own campaigns, the group exploits cloud and SaaS environments — recent targets have included Salesforce, Google Workspace, Microsoft 365, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox. Entry methods include exploiting third-party integration companies to steal authentication tokens, and running vishing campaigns against Okta, Microsoft, and Google SSO accounts by impersonating IT help desks to harvest credentials and MFA codes. The group has also used device code vishing to steal Microsoft account authentication tokens.

Once inside a connected environment, attackers pivot across enterprise platforms using the stolen SSO credentials. The FBIjobs.gov intrusion followed a similar lateral movement pattern — Oracle PeopleSoft to AWS GovCloud — demonstrating the group's consistent playbook of exploiting one trusted platform to reach another. ShinyHunters has been active under various operators since at least 2018, with recent campaigns linked to breaches at Google, Cisco, PornHub, Match Group, PowerSchool, and Instructure Canvas. The Instructure breach in May caused significant outages; Instructure later reached an undisclosed "agreement" with the threat actors to prevent data publication.

What is still unknown about FBI arrests another suspected ShinyHunters

Authorities have not released the Canadian suspect's name, the specific charges, or which court will handle prosecution. The FBI has also not identified the third-party contractor responsible for the FBIjobs.gov platform or named the precise security update that was not installed. It is unclear whether the suspect arrested in Pennsylvania is the same individual whose Telegram account — the group's main media-facing representative — went dark last Tuesday and subsequently appeared to be deleted. That representative had communicated regularly with BleepingComputer and other reporters after the Dutch arrest of Pepijn van der Stap, suggesting van der Stap was not the account's operator.

Saif al-Din Khader, known online as "Rey," was detained in Jordan and reportedly began cooperating with the FBI and international agencies, but the extent of that cooperation has not been disclosed. ShinyHunters denied any connection to van der Stap after his September 15 arrest in Amsterdam. Around the time of Rey's detention, another alleged affiliate with knowledge of the FBI hack shut down an online messaging account and the group's data leak site went offline — though a new leak site later launched, indicating at least some members remain active. Whether the internal disruption reflects successful law enforcement penetration or a precautionary reorganization is not yet known.

Developer Action Items

  • ☐ Inventory whether AWS / Oracle runs in prod, CI, staging, or on laptops before you debate severity.
  • ☐ Confirm the vendor's fixed build for AWS / Oracle from BleepingComputer, then schedule the patch window.
  • ☐ If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
  • ☐ Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.
  • ☐ Treat unexpected emails that mention AWS / Oracle (shipping, invoices, password resets) as phishing until verified.

FBI arrests another suspected ShinyHunters FAQ

What data was stolen in the FBI ShinyHunters breach?

ShinyHunters claimed to have stolen between 2TB and 3TB of data, including home addresses, Social Security numbers, sensitive job assignments, family member information, medical and psychiatric records, and internal service records belonging to current and former FBI employees and job applicants.

Who has been arrested in connection with the ShinyHunters FBI hack?

As of Friday, arrests include a 24-year-old Amsterdam man named Pepijn van der Stap (arrested September 15 by Dutch police), a Jordanian-detained suspect identified as Saif al-Din Khader ("Rey") who began cooperating with investigators, and an unnamed Canadian citizen arrested in Pennsylvania described as a primary co-conspirator.

How did ShinyHunters breach FBI systems?

The group told reporters it exploited an alleged Oracle PeopleSoft zero-day vulnerability to gain initial access, then moved laterally into FBI-managed AWS GovCloud infrastructure. The FBI confirmed the breach stemmed from a third-party contractor-managed platform that had not installed a security update.

Is ShinyHunters still active after the arrests?

Partially. The group's main Telegram representative stopped responding and the account appears deleted. A data leak site went offline but a new one later appeared. Kash Patel said the FBI will "continue to work closely with partners to disrupt what's left of the ShinyHunters group."

What organizations has ShinyHunters previously targeted?

Confirmed targets and linked breaches include Google, Cisco, PornHub, Match Group, Salesforce, Instructure Canvas, PowerSchool, and organizations whose data was traded on the Breached v2 hacking forum, as well as Snowflake-connected victims and entities targeted through Okta, Microsoft, and Google SSO vishing campaigns.

Sources

Dillip Chowdary

Author

Dillip Chowdary

Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.

Related on Tech Bytes

Advertisement

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →