FBI arrests another suspected ShinyHunters hacker after agency breach

The ShinyHunters extortion gang has been making headlines for months after breaching FBI systems and stealing sensitive data from over 2TB of compromised files. The latest development in this ongoing saga is the arrest of another suspected member, who is believed to be involved in the breach.

According to a statement made by FBI Director Kash Patel on social media platform X, agents have arrested a Canadian citizen suspected of being a primary co-conspirator in the intrusion. While details about the suspect’s identity and specific charges are scarce, the arrest marks another significant step towards dismantling the ShinyHunters network.

The breach, which occurred last month, saw hackers exploit an alleged zero-day vulnerability in Oracle PeopleSoft software to gain access to FBI-managed AWS GovCloud infrastructure. The threat actors claimed they stole sensitive data, including information on current and former employees, job applicants, medical records, and internal service records. A review of the leaked data by cybersecurity experts confirms that it contains a range of personal and sensitive information, including home addresses, Social Security numbers, and details about employees’ family members.

The FBI has since acknowledged that the breach was linked to a third-party contractor-managed platform that failed to install security updates. In response, the agency has increased pressure on identifying and apprehending ShinyHunters members. This latest arrest is part of an ongoing effort by law enforcement agencies around the world to disrupt the gang’s activities.

Other notable developments in this case include the arrest of a 24-year-old Dutch hacker, Pepijn van der Stap, who was initially linked to ShinyHunters but later denied any association with the group. The FBI has also publicly warned ShinyHunters members to turn themselves in, stating that investigations are ongoing and that seized infrastructure will reveal more about their activities.

In a surprising move, one of the suspected ShinyHunters members known as “Rey” was detained in Jordan and began cooperating with law enforcement agencies. This has led to signs of disruption within the gang, including the shutdown of online messaging accounts and data leak sites. While it is unclear whether this marks the end of ShinyHunters’ activities, these developments suggest that authorities are making significant progress in dismantling their operations.

As a practical takeaway for readers, this case highlights the importance of staying vigilant about cybersecurity vulnerabilities and ensuring that third-party contractors manage sensitive systems with care. It also underscores the value of international cooperation in combating cybercrime and disrupting malicious groups like ShinyHunters.


Source: Bleeping Computer — 2026-10-09