Skip to main content
Threat IntelligenceEmerging Threats

FBI Disrupts ShinyHunters Extortion Group with Latest Arrest

Law enforcement agent standing in front of a federal building with a badge and notebook.

"Our agents in the field have arrested another suspected co-conspirator of the ShinyHunters group – the group believed to be responsible for the recent http://FBIjobs.gov incident, which occurred on a platform managed by a third-party vendor.," Director Kash Patel said on X.

What the FBI announced about the new arrest

The FBI has confirmed another arrest tied to the ShinyHunters extortion network, Director Kash Patel said Friday. Patel did not name the suspect or disclose the arrest location in his public post; however, The New York Times reported the person is a Canadian citizen who was arrested in Pennsylvania and is considered a primary co-conspirator in the intrusion. Authorities have not publicly released a name or the specific charges.

Patel framed the arrest as part of an intensifying, multi-day campaign: "This is the latest arrest this FBI has made in a matter of days involving this network, as we work non-stop to dismantle the group, pursue new leads and evidence, and act quickly." He added that the bureau will "continue to work closely with our partners to disrupt what's left of the ShinyHunters group and their associates, no matter where they operate."

Scope of the FBIJobs breach and the exposed information

ShinyHunters has claimed responsibility for accessing FBI systems tied to the FBIJobs platform. According to the group’s statements to BleepingComputer, they exploited an alleged Oracle PeopleSoft zero-day vulnerability before moving laterally into FBI-managed AWS GovCloud infrastructure. The threat actors said they stole between 2TB and 3TB of data.

Samples of the stolen data shared with BleepingComputer and other media outlets corroborated that the breach exposed a wide range of sensitive employee information: home addresses, Social Security numbers, sensitive job assignments, information about employees' family members, and other personal data. The group also claimed the haul included information on current and former FBI employees, job applicants, and medical and psychiatric records. An internal FBI memo, reported by The New York Times, said the agency assumed the breach had affected all employees.

The FBI has attributed the incident, in part, to a third-party contractor-managed platform that failed to install a security update.

Alleged tactics: zero-days, lateral movement into AWS GovCloud, and vishing

The account of the intrusion combines multiple techniques the source attributes to ShinyHunters. BleepingComputer reported the group exploiting an alleged Oracle PeopleSoft zero-day, then using that foothold to reach systems hosted in AWS GovCloud under FBI management. Across other breaches, the group has used stolen authentication tokens from third-party integration companies and run voice phishing (vishing) campaigns targeting Okta, Microsoft, and Google single sign-on accounts; the source also described device code vishing to steal Microsoft authentication tokens.

Once attackers obtain credentials and authentication codes, the reporting says, they use compromised SSO accounts to access connected enterprise platforms such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox — a pattern consistent across multiple incidents attributed to the group.

International law enforcement actions and signs of disruption inside ShinyHunters

Law enforcement activity has accelerated globally. On September 15, Dutch police arrested a 24-year-old Amsterdam man identified as Pepijn van der Stap, previously known online as "Umbreon." ShinyHunters told BleepingComputer that van der Stap "has no association with us. Frankly, we are laughing." Around the same time, Reuters reported Jordanian authorities detained a suspected member known online as "Rey," identified as Saif al-Din Khader, who was said to be cooperating with investigators.

FBI Cyber Division Assistant Director Brett Leatherman warned publicly that arrests and seized infrastructure can change the group's internal dynamics and make remaining members more likely to be identified: "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left," he said. "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."

At the same time, the group's public footprint showed signs of strain: the main representative who had regularly communicated with BleepingComputer stopped responding on Telegram and that account now appears deleted. One affiliate with intimate knowledge of the FBI hack also shut down an online messaging account, and the group's data leak site went offline before a new leak site later launched. It remains unclear whether those disruptions are directly connected to the recent arrests.

What this means for the FBI, affected employees, and third‑party vendors

  • For the FBI: the agency faces an internal remediation and communications challenge. The breach reportedly affected FBI-operated AWS GovCloud resources and stemmed from a contractor-managed platform that missed a security update; the FBI has publicly signaled a sustained enforcement and investigative push.
  • For affected employees and applicants: data samples reviewed by media outlets included Social Security numbers, home addresses, medical and psychiatric records, and family-member information — a breadth of personal data that the FBI's internal memo said likely affected all employees.
  • For third‑party vendors and cloud integrators: the incident underscores the operational risk that a contractor-managed platform or unpatched enterprise application can create for a major federal entity, particularly when identity and SSO systems or integration tokens are involved.

The public record compiled from FBI statements and reporting by BleepingComputer, The New York Times, and Reuters shows an enforcement campaign that is active — arrests, international detentions, and disruption to the group's public channels — even as key questions remain about who within ShinyHunters held operational control and how broadly stolen data will be used or distributed. The FBI's continued arrests and the evolving cooperation reported by foreign authorities will be the immediate tests of whether investigators can translate seizures and detentions into lasting disruption.

Read the original BleepingComputer report