FBI arrests another suspected ShinyHunters member over FBIjobs.gov breach

Canadian citizen held in Pennsylvania described as primary co-conspirator in the intrusion; name and charges not yet disclosed

By LineZotpaper
Published
Updated
Read Time2 min
Sources2 outlets
The FBI has arrested another suspected member of the ShinyHunters extortion group over last month's breach of the FBIjobs.gov platform, Director Kash Patel announced Friday. The suspect, a Canadian citizen arrested in Pennsylvania, has not been publicly identified.

FBI Director Kash Patel announced Friday that agents had arrested another suspected co-conspirator of ShinyHunters, the group he said is believed to be responsible for the recent FBIjobs.gov incident.

Patel said in a post on X that the incident occurred on a platform managed by a third-party vendor. "This is the latest arrest this FBI has made in a matter of days involving this network, as we work non-stop to dismantle the group, pursue new leads and evidence, and act quickly," he said.

Patel did not identify the suspect or disclose where the arrest occurred, but The New York Times reports that the individual is a Canadian citizen arrested in Pennsylvania and is considered a primary co-conspirator in the intrusion. Authorities have not publicly disclosed the suspect's name or the specific charges against him.

The arrest is the latest in a series of law enforcement actions since ShinyHunters breached FBI systems last month. The group told BleepingComputer in September that it accessed the systems by exploiting an alleged Oracle PeopleSoft zero-day vulnerability before moving laterally into FBI-managed AWS GovCloud infrastructure.

The threat actors claimed to have stolen between 2TB and 3TB of data, including information on current and former FBI employees, job applicants, medical and psychiatric records, and internal service records. Data samples shared with media outlets confirmed the exposure of home addresses, Social Security numbers, sensitive job assignments, information about employees' family members, and other personal data. The New York Times reported that an internal FBI memo said the agency assumed the breach had affected all employees.

The FBI has since said the incident stemmed from a third-party contractor-managed platform that failed to install a security update.

On September 15, Dutch police arrested Pepijn van der Stap, a 24-year-old Amsterdam man previously known online as "Umbreon," as part of the investigation. ShinyHunters denied that van der Stap was associated with the group, telling BleepingComputer: "That individual has no association with us. Frankly, we are laughing."

Soon afterward, the FBI publicly warned ShinyHunters members to turn themselves in, saying investigators were continuing to identify people involved with the group.

§

Analysis

Why This Matters

  • The breach exposed highly sensitive personal data of FBI employees, including home addresses, Social Security numbers, medical records and family information, and the agency reportedly assumed all employees were affected.
  • The arrests represent a significant law enforcement push to dismantle ShinyHunters, a hacking group linked to a long history of data theft incidents.
  • The case raises questions about security oversight of third-party vendors managing United States government platforms.

Background

The FBIjobs.gov incident came to light in September when ShinyHunters claimed responsibility, telling BleepingComputer it exploited an alleged Oracle PeopleSoft zero-day vulnerability and moved into FBI-managed AWS GovCloud infrastructure. The FBI attributed the breach to a third-party contractor-managed platform that failed to install a security update. Law enforcement has now made at least two arrests: a 24-year-old Dutch man in Amsterdam and a Canadian citizen in Pennsylvania. ShinyHunters has disputed the Dutch arrest, saying that individual had no association with the group.

Key Perspectives

FBI leadership: Director Kash Patel has described the arrests as part of a non-stop effort to dismantle the group, pursue new leads and act quickly, and has publicly warned remaining members to turn themselves in. ShinyHunters: The group has denied any connection to the previously arrested Dutch suspect while claiming responsibility for the FBI breach, saying it accessed the systems through a zero-day exploit. Affected employees and the public: An internal memo reportedly assumed the breach affected all FBI employees, and data samples confirmed exposure of personal information including Social Security numbers. The full scale of how the stolen data may be used remains unclear.

What to Watch

  • Whether US authorities publicly identify the Canadian suspect and reveal the specific charges.
  • Further arrests, as the FBI says it is continuing to identify people involved with the group's network.
  • Any disclosure of how the stolen data has been used or distributed, given the sensitivity of the material.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.

How we workSubscribe