Skip to main content

Morning Overview

The FBI arrested another suspected ShinyHunters hacker after the breach of its own systems

FBI Director Kash Patel announced on Friday, October 9, 2026 that agents had arrested “another suspected co-conspirator” of ShinyHunters, the data-extortion group that claims to have stolen up to 3 terabytes from the bureau’s own recruiting platform. The New York Times reported that the suspect is a Canadian citizen arrested in Pennsylvania and treated as a primary co-conspirator, though neither Patel nor the authorities have released a name or charges.

The systems at the center of the case belong to the FBI itself. The bureau’s FBIjobs.gov portal, run on a platform managed by an outside vendor, is the target ShinyHunters says it hit on or before September 22.

The FBIjobs.gov breach and the missed patch

ShinyHunters said on September 22 that it had hacked FBI systems through the bureau’s jobs site and claimed data on every employee, according to SecurityWeek’s report on the FBI’s explanation. The group told BleepingComputer it used an alleged Oracle PeopleSoft zero-day and then moved sideways into FBI-managed AWS GovCloud infrastructure, and it claims 2 to 3 TB of data covering current and former employees, job applicants, medical and psychiatric records and internal service records. Samples shared with reporters showed home addresses, Social Security numbers, sensitive job assignments and family details.

The bureau’s own account is less dramatic about the entry point. In a statement quoted by SecurityWeek, Brett Leatherman, who leads the FBI’s cyber division, said the incident resulted from “a security failure of a platform managed by a third-party organization” and that “a contractor failed to implement a security patch explicitly issued to secure the platform.” Reuters’ sources, as relayed there, say the platform is Oracle’s PeopleSoft human-resources system and the contractor is Accenture, which said only that it was “proud to support the mission of the FBI.”

Per the New York Times, an internal FBI memo assumes every employee was affected, a worst-case planning assumption that is separate from the group’s own boast of holding data on all current and former staff.

Three arrests in three weeks

The Friday announcement is the latest of several. Dutch police arrested a 24-year-old Amsterdam man on September 15; Patel announced it on September 29 as the arrest of “one of the alleged leaders of ShinyHunters,” made by the Dutch High-Tech Crime Unit in coordination with FBI investigators. Reuters identified him as Pepijn van der Stap; ShinyHunters denies any link and calls the Dutch police incompetent.

On October 3, Reuters reported that Saif al-Din Khader, who goes by “Rey,” had been detained in Jordan, with Hackread dating the detention to September 29, and is cooperating with investigators. Malwarebytes’ October 7 recap, citing security blogger Brian Krebs, describes him as the technical and public-relations lead of the Scattered LAPSUS$ Hunters collective, which merged Scattered Spider, LAPSUS$ and ShinyHunters.

On October 5, an FBI spokesperson told The Register the bureau had “already worked with partners to arrest multiple subjects,” without naming them or saying whether Khader was among them, as Hackread summarized the next day. The same coverage carries the FBI’s statement that ShinyHunters had compromised more than 140 organizations and obtained at least $70 million in extortion payments since 2025, and Patel’s remark that “more arrests are on the table.” Brett Leatherman said arrests could reveal who else remains involved.

The Pennsylvania arrest differs from the first two because it happened on U.S. soil and was announced as an FBI operation. Patel did not say where or when it took place, and he closed by saying the bureau will work with partners to disrupt “what’s left of the ShinyHunters group and their associates, no matter where they operate.”

A group under pressure, and how much of the claim is verified

BleepingComputer’s October 9 report notes signs of disruption. The group’s main spokesperson, who had talked regularly to reporters on Telegram, stopped responding and the account appears deleted, another affiliate closed a messaging account, and the data leak site went offline before a new one appeared. Whether those changes follow from the arrests is unclear, and the appearance of a new leak site suggests some members remain active.

Much of what is known about the stolen data rests on ShinyHunters’ own claims and the samples it released. The FBI has confirmed the third-party platform failure, and sources told Reuters the review points to the missed patch, but the bureau has not published its own count of affected employees or applicants, and the 2 to 3 TB figure is the group’s.

The group has said the hack was a response to a May 2026 FBI advisory about it, which ShinyHunters calls false. Patel’s announcement leaves open whether the arrested suspect is tied to the FBIjobs.gov intrusion itself, only that the person is a suspected co-conspirator of the group the bureau believes responsible.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview


Morning Overview is reader-supported. Some links in our articles are affiliate links, and we may earn a commission at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. Full disclosure.