Skip to main content
Threat IntelligenceEmerging Threats

FBI Disrupts ShinyHunters Network with Third Arrest

Courthouse exterior with blurred law enforcement officer in background.

"ShinyHunters, the group believed to be responsible for the recent FBIjobs.gov incident," FBI Director Kash Patel wrote on X on October 9.

FBI announces another arrest; suspect's identity not released

The FBI on October 9 said it had arrested another suspected co‑conspirator of the extortion group ShinyHunters, Director Kash Patel wrote on X. The bureau has not publicly named the suspect or filed charges, and Patel’s post did not say whether the arrested individual directly participated in the breach of the FBI jobs portal.

The New York Times and CBS News, citing unnamed sources, reported that the person arrested is a Canadian citizen taken into custody in Pennsylvania. An FBI spokesperson declined to comment to CBS News on the Times report, according to that outlet.

How the bureau framed its next steps

In his post, Patel said the FBI "will keep working with its partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate." A law enforcement source told CBS News that other suspected co‑conspirators remain at large.

Two earlier arrests — Netherlands and Jordan

Reuters counted the Pennsylvania arrest as the third made public since the breach became widely reported in late September. The first public arrest occurred in the Netherlands; Dutch police detained a man a week before ShinyHunters announced the FBI breach on September 22, though the Dutch police statement—published in Dutch—did not mention the FBI or its jobs portal.

The FBI, in a video statement, said the Dutch detainee is one of the group's alleged leaders and that Dutch police made the arrest under Dutch law with FBI support. ShinyHunters, speaking to The Hacker News, denied that the Dutch suspect had any association with the group.

The second public detention involved a suspect named Khader, who was detained in Jordan and, Reuters reported, is cooperating with the FBI. The bureau has not said whether the latest arrest in Pennsylvania resulted from that cooperation.

What was stolen and the FBI’s technical explanation

Reuters analyzed a sample of data shared by ShinyHunters and found it contained extensive personal information on FBI employees, details of sensitive job roles, and psychiatric and medical information. An internal FBI notice confirmed that hackers obtained employee information, a source told CBS News.

Brett Leatherman, assistant director of the FBI’s Cyber Division, told Reuters on October 5 that the bureau's review found the breach resulted from a security failure on a platform managed by an outside organization. Leatherman said the incident happened after "a contractor failed to implement a security patch explicitly issued to secure the platform." The FBI has removed the contractor, the agency told Reuters, but did not name the platform or the organization involved.

PeopleSoft and Accenture named by sources; ShinyHunters’ stated motive

Two sources told Reuters that the platform and organization involved were PeopleSoft—Oracle's human resources software—and Accenture. Accenture told Reuters it was "proud to support the mission of the FBI" and did not answer Reuters' questions about the contractor or the specific failure cited by the bureau.

ShinyHunters told The Hacker News it targeted the FBI over an advisory issued in May that the group says makes false claims about it. That advisory describes ShinyHunters as a cybercriminal group that specializes in large‑scale data breaches and extortion. The FBI alleges the group has breached more than 140 organizations and extracted at least $70 million in extortion payments since last year.

What this means for FBI employees, contractors, and investigators

  • FBI employees: The Reuters analysis and the internal notice reported by CBS News indicate personal, medical, and psychiatric information was exposed—data that could have immediate personal and operational consequences for affected employees.
  • Contractors and vendors: The bureau's statement that it removed a contractor after a patch was not applied highlights a procurement and patch‑management failure tied to the incident. Vendors named by sources—PeopleSoft (Oracle) and Accenture—are now focal points for scrutiny in how third‑party platforms are secured and managed.
  • Investigators and legal teams: Publicly disclosed arrests total at least three; cooperation from a detainee in Jordan has been reported to Reuters, and the FBI says it continues working with partners to "disrupt what’s left" of the group—steps that may produce additional detentions or charges.

The arrest announced on October 9 is the latest public development in a breach that combined an apparent third‑party patching failure, an extensive haul of sensitive personnel data, and an extortion group the FBI says has struck hundreds of targets. The bureau's removal of a contractor and its promise to continue disrupting ShinyHunters frame the immediate next steps; whether those actions will lead to criminal charges made public, further arrests, or a fuller accounting of how the platform was secured remains to be seen.

Original story — The Hacker News