The FBI has arrested another suspected member of the ShinyHunters extortion group, who is believed to have taken part in the recent breach of FBI systems. Director Kash Patel announced the arrest on Friday, saying agents had taken another suspected co-conspirator into custody. Patel linked the suspect to the incident at FBIjobs.gov, which he said occurred on a platform run by a third-party vendor.
Patel did not name the suspect or say where the arrest was made. The New York Times reported that the suspect is a Canadian citizen who was arrested in Pennsylvania and is seen as a primary co-conspirator in the intrusion. Authorities have not publicly released the suspect's name or the specific charges against him. The arrest is the latest in a series of law enforcement actions against ShinyHunters since the group breached FBI systems last month.
ShinyHunters told BleepingComputer in September that it accessed FBI systems by exploiting an alleged Oracle PeopleSoft zero-day vulnerability, then moved laterally into FBI-managed AWS GovCloud infrastructure. The group claimed it stole between 2TB and 3TB of data, including information on current and former FBI employees, job applicants, medical and psychiatric records, and internal service records. Data samples shared with BleepingComputer and other outlets confirmed the breach exposed employee information such as home addresses, Social Security numbers, sensitive job assignments, details about employees' family members, and other personal data. The New York Times also reported that an internal FBI memo said the agency assumed the breach had affected all employees.
The FBI has said the incident stemmed from a third-party contractor-managed platform that failed to install a security update. Since the FBIJobs hack, the bureau has sharply increased pressure to identify and apprehend the ShinyHunters gang. On September 15, Dutch police arrested a 24-year-old Amsterdam man, identified as Pepijn van der Stap, a Dutch hacker previously known online as "Umbreon," as part of an investigation into the group. ShinyHunters denied that van der Stap was associated with the group, telling BleepingComputer that he had no association with them and that they were laughing.
Soon afterward, the FBI took the unusual step of publicly warning ShinyHunters members to turn themselves in, saying investigators were continuing to identify people involved with the group. FBI Cyber Division Assistant Director Brett Leatherman said at the time that arrests change who is willing to talk and that seized infrastructure shows who is left, adding that the longer members stay in, the more the FBI learns about them. Days later, a suspected ShinyHunters member known online as "Rey" was reportedly detained in Jordan and began cooperating with the FBI and international law enforcement agencies. Reuters reported that Jordanian authorities detained Rey, identified as Saif al-Din Khader, and that sources said he was aiding investigators in finding other alleged members.
Signs of disruption also appeared within ShinyHunters around the same time. The group's main representative, who had regularly communicated with BleepingComputer and other reporters and had detailed knowledge of ShinyHunters' attacks over the past two years, stopped responding on Telegram last Tuesday. The same representative continued communicating with BleepingComputer after van der Stap's arrest, suggesting van der Stap was not the person operating the account. A new ShinyHunters leak site later launched, suggesting at least some members of the operation remained active. It is unclear whether the disappearance of the group's main representative is connected to any of the recent arrests.
More cybersecurity news from TechManNews.






