Skip to content

FBI arrests another ShinyHunters suspect over FBIjobs breach

FBI Director Kash Patel says agents arrested another suspected ShinyHunters co-conspirator tied to the FBIjobs.gov breach. The New York Times reports a Canadian national held in Pennsylvania.

Published 3 min read

The FBI has arrested another suspected member of the ShinyHunters extortion group tied to the September breach of its own recruitment platform, Director Kash Patel said on October 9 in a post on X. The bureau has not named the suspect or disclosed charges. The New York Times, cited by The Record and BleepingComputer, reports the arrest happened in Pennsylvania and involved a Canadian national described as a primary co-conspirator.

What this relates to

ShinyHunters claimed in September it had breached FBIjobs.gov, defaced the domain, and stolen data on nearly every FBI employee. The bureau traced the intrusion to a third-party contractor — named by reporting as Accenture — that failed to apply a security patch; we covered the FBI's attribution of the breach to a missed Oracle PeopleSoft patch (CVE-2026-35273). Patel described it as "the recent FBIjobs.gov incident, which occurred on a platform managed by a third-party vendor."

Data samples the group shared with news outlets included home addresses, Social Security numbers, sensitive job assignments, and family-member information, along with records on local police officers serving on FBI task forces. An internal FBI memo reported by the Times said the agency assumed all employees were affected.

The arrests so far

This is at least the third detention in weeks tied to the group:

  • September 15 — Dutch police arrested 24-year-old Pepijn van der Stap ("Umbreon") in Amsterdam; ShinyHunters denied he was affiliated.
  • Late September — a suspected member known as "Rey," identified by Reuters as Saif al-Din Khader, was detained in Jordan and reportedly began cooperating with the FBI.
  • October 9 — this arrest, which Patel called "the latest arrest this FBI has made in a matter of days involving this network."

FBI Cyber Division Assistant Director Brett Leatherman framed the cascade bluntly: "Arrests have a way of changing who is willing to talk."

What to do today

  1. If you run Oracle PeopleSoft, confirm the vendor patch for CVE-2026-35273 is applied — not just a WAF rule. The FBI's own breach came from an unpatched instance reachable via a WAF bypass.
  2. Do not treat arrests as closure. ShinyHunters data from Salesforce-linked extortion campaigns remains in circulation; rotate any credentials or tokens exposed in prior claims regardless of who is in custody.
  3. Audit third-party patch accountability. The root cause here was a contractor-run platform where a patch was issued and never verified as applied.

Context

Attribution stays where it should: the suspect is a suspected co-conspirator, unnamed and uncharged publicly, and ShinyHunters has denied some prior arrests touched its core. What is verifiable is the pressure — multiple detentions across Europe, the Middle East, and now North America inside a month, with at least one cooperator. The group told outlets it "will not remain active on Telegram for much longer." Whether that signals a wind-down or a rebrand is the open question; ShinyHunters-affiliated extortion has outlived takedown claims before.

Related stories