FBI arrests another suspected ShinyHunters hacker after agency breach

The FBI has made another significant arrest in its ongoing pursuit of the ShinyHunters hacking group, which breached the agency’s systems last month and stole sensitive information from thousands of current and former employees. According to Director Kash Patel, agents have apprehended a suspected member of the gang who is believed to be involved in the high-profile breach of FBIJobs.gov, a platform managed by a third-party vendor.

The suspect, a Canadian citizen, was taken into custody in Pennsylvania and is considered a primary co-conspirator in the intrusion. While authorities have not disclosed the individual’s name or specific charges against them, this arrest marks the latest development in a series of law enforcement actions aimed at dismantling ShinyHunters. It’s worth noting that Patel’s statement suggests the FBI has made significant progress in identifying and apprehending those responsible for the breach.

The ShinyHunters hacking group made headlines earlier this month when it claimed to have accessed FBI systems by exploiting an alleged Oracle PeopleSoft zero-day vulnerability. The threat actors then moved laterally into FBI-managed AWS GovCloud infrastructure, resulting in the theft of between 2TB and 3TB of sensitive data, including information on current and former employees, job applicants, medical and psychiatric records, and internal service records.

The breach has had far-reaching consequences, not only for the affected individuals but also for the FBI itself. The agency has acknowledged that the incident stemmed from a failure to install a security update on a third-party contractor-managed platform. In response, the FBI has significantly increased pressure on identifying and apprehending ShinyHunters members.

In recent weeks, law enforcement agencies around the world have been working together to disrupt the group’s activities. Dutch police arrested a 24-year-old Amsterdam man in connection with an investigation into ShinyHunters, while Jordanian authorities detained a suspected member known online as “Rey” and reported that he was cooperating with investigators.

The pressure on ShinyHunters appears to be taking its toll. The group’s main representative stopped responding to messages last week, and their Telegram account has since been deleted. Another alleged affiliate shut down an online messaging account around the same time, while the group’s data leak site went offline – only to later relaunch with a new URL.

The FBI’s aggressive pursuit of ShinyHunters sends a clear message: law enforcement is committed to bringing cybercriminals to justice and will not tolerate such brazen attacks on sensitive systems. As this case continues to unfold, one takeaway for the security community is the importance of robust incident response planning and regular security updates – especially in third-party managed environments.


Source: Bleeping Computer — 2026-10-09