What We Missed: FBI Strikes Back at ShinyHunters

The FBI has been at odds with the cybercrime gang ShinyHunters in recent months, and the situation just got more intense. After claiming a breach against the FBI and defacing its website, a suspected member of the group was detained in Jordan. But here’s the thing: we still don’t know the full extent of what happened.

ShinyHunters claimed that they had obtained data belonging to nearly every FBI employee and job applicant as part of a breach of a third-party jobs portal used by the agency. While this sounds alarming, it’s worth noting that the claim was made without providing any evidence to back it up. Still, the incident has sparked a significant response from the FBI, which is cooperating with Dutch authorities to arrest another suspected member of the gang.

Jordanian authorities recently detained a suspected ShinyHunters operative, and according to reports, they’re cooperating with officials. This development comes on the heels of a similar arrest in the Netherlands last month, where a suspected member of the group was apprehended by the Dutch National Police.

ShinyHunters has been making headlines for its brazen attacks on various entities in recent months, including ReliaQuest and Instructure. Even fellow threat group Cl0p hasn’t been immune to their attention. The gang’s tactics often involve exploiting vulnerabilities in third-party services used by organizations, which is what allegedly happened with the FBI jobs portal.

But here’s a twist: the arrest of a suspected ShinyHunters operative in Jordan highlights the global nature of cybercrime. The group’s activities aren’t limited to any one country or region; they’re a transnational threat that requires international cooperation to combat.

The implications of this incident are significant, not just for the FBI but also for other organizations that rely on third-party services to manage their data and operations. It’s a sobering reminder of the importance of security in our interconnected world and the need for vigilance against threats like ShinyHunters.

So what can we take away from this story? For one, it’s essential to be aware of the risks associated with using third-party services and to regularly assess the security posture of these vendors. It’s also crucial to stay informed about emerging threats and work closely with law enforcement agencies to share intelligence and coordinate responses. By doing so, we can better protect ourselves against attacks like those perpetrated by ShinyHunters.


Source: Dark Reading — 2026-10-09