The FBI arrested another suspected ShinyHunters member amid an international crackdown following a breach associated with FBIjobs.gov. News reports identified the suspect as a Canadian citizen arrested in Pennsylvania, but the bureau did not disclose his identity, charges or alleged role. Unnamed sources linked him directly to the breach; FBI Director Kash Patel's announcement did not establish that connection. The arrest follows the detention of suspected member Saif al-Din Khader in Jordan and the arrest of an alleged group leader in the Netherlands.
ShinyHunters claimed it stole sensitive information about FBI personnel and job applicants from a third-party-managed platform. An apparent sample of roughly 5,000 entries supplied to Nextgov/FCW contained employee and family information, including records identifying intelligence and surveillance personnel; Reuters also reported sensitive job details and psychiatric and medical information. The FBI attributed the intrusion to a contractor's failure to apply a security update, while Reuters sources identified the platform as Oracle PeopleSoft and the contractor as Accenture. Reporting indicated that the FBI removed an Accenture contractor in response. Although ShinyHunters said it would not publish the data, potential sale to foreign intelligence services or other buyers remains a concern, underscoring the importance of verifying patch compliance on vendor-managed systems.

See the reporting duties and controls this puts on the clock.
18 events from the most recent confirmed update back to the earliest known activity.
FBI Director Kash Patel announced another suspected ShinyHunters co-conspirator's arrest earlier that week; news outlets identified the suspect as a Canadian citizen detained in Pennsylvania. Unnamed sources alleged involvement in the FBI data theft, but the FBI did not identify the suspect, disclose charges or establish his role in the breach.
Brett Leatherman told Reuters that a contractor failed to implement a security patch explicitly issued to secure the affected platform. The FBI's review attributed the breach to this security failure on a platform managed by an outside organization.
In a statement reported by Reuters on October 3, the FBI said it had already worked with partners to arrest multiple subjects.
Reuters sources identified a suspect arrested in Jordan as Saif al-Din Khader and dated his arrest to September 29. Jordanian state media reported official confirmation of an arrest without naming the suspect.
The FBI announced the arrest of an alleged ShinyHunters leader by Dutch authorities. FBI cyber chief Brett Leatherman said the suspect and alleged co-conspirators had breached more than 140 organizations and collected at least $70 million in extortion payments since the previous year.
ShinyHunters announced that it had breached the FBI's jobs portal and claimed to have stolen sensitive information concerning almost all FBI agents and job applicants.
Dutch police arrested a 24-year-old Amsterdam man under Dutch law with FBI support. Sources identified him as Pepijn van der Stap, although Dutch police did not publicly name him.
Google's Mandiant reported that ShinyHunters exploited CVE-2026-35273 in Oracle PeopleSoft's Environment Management component and used URL encoding to bypass web application firewall rules blocking the vulnerable endpoint. The reference does not establish that this specific vulnerability was used in the FBI jobs-portal breach.
ShinyHunters said it would not publish the stolen FBI information. The reporting did not establish that the data had been sold or otherwise disposed of.
ShinyHunters told The Hacker News that the suspect arrested in the Netherlands had no association with the group, disputing the FBI's characterization of him as an alleged leader.
KrebsOnSecurity identified the Pennsylvania detainee as Edward Dubrovsky, a Cypfer co-founder associated with ransomware negotiation firm CyberSteward. Court records list conspiracy to threaten information confidentiality to extort money and interference with commerce by threats; an October 9 notice moved his case to the Eastern District of Texas, while the core complaint remains sealed.
The FBI removed a contractor in response to the intrusion. Nextgov/FCW and Reuters reporting linked the contractor to Accenture, while the bureau did not publicly identify the contractor.
Reuters sources said Saif al-Din Khader was cooperating with the FBI and other law enforcement agencies to locate fellow hackers. The FBI did not establish whether that cooperation led to the subsequent Pennsylvania arrest.
KrebsOnSecurity reported that ShinyHunters allegedly attempted to extort a navigation and digital aviation unit divested by Boeing in late 2025. Saif al-Din Khader, known as Rey, was reportedly apprehended while that attempt was underway.
ShinyHunters claimed it exploited a zero-day vulnerability in the FBI's Oracle PeopleSoft software, then pivoted into the bureau's AWS GovCloud environment and stole more than 2 terabytes of data. The FBI separately attributed the intrusion to a contractor's failure to apply an existing security patch.
ShinyHunters supplied Nextgov/FCW with an apparent sample containing roughly 5,000 entries, including names, home addresses, phone numbers, relatives' information and sensitive job roles. Reuters' analysis of a shared sample also found psychiatric and medical information.
An intrusion into a third-party-managed platform associated with FBIjobs.gov exposed employee personal information and details about sensitive assignments. Sources subsequently identified the affected platform as Oracle PeopleSoft.
An FBI advisory issued in May described ShinyHunters as specializing in large-scale data breaches and extortion. The group later cited allegedly false claims in that advisory as its reason for targeting the FBI.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
9 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourcemalware.news
Open sourcehackread.com
Open sourcemalware.news
Open sourcekrebsonsecurity.com
Open sourcethehackernews.com
Open sourcemalware.news
Open sourcenextgov.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.