Crime

FBI Arrests Suspect in Breach of Its Own Jobs Portal

FBI arrests another suspected ShinyHunters member in Pennsylvania over the September breach of its FBIjobs.gov portal. No name or charges yet public.

The FBI headquarters building in Washington, D.C.

On October 9, 2026, FBI Director Kash Patel announced on X that federal agents had arrested another suspected co-conspirator of the hacking group ShinyHunters, the cybercrime network accused of breaching the FBI’s own jobs portal, FBIjobs.gov, in September and stealing personnel records on nearly all bureau agents and job applicants. The suspect, whom the bureau has not publicly identified, was described by law enforcement sources cited by The New York Times and CBS News as a Canadian citizen taken into custody in Pennsylvania who is believed to have been directly involved in the intrusion. No charges have been made public, and the investigation remains active.

TL;DR: The FBI says it arrested another suspected ShinyHunters member on October 9 in a major advance in the investigation of the September breach of its FBIjobs.gov portal. The unnamed suspect, reportedly a Canadian citizen arrested in Pennsylvania, has not been formally charged. The arrest follows earlier arrests in the Netherlands and Jordan connected to the same alleged network.

What the FBI announced

Patel’s October 9 announcement said the arrest was the latest in a rapid series of actions targeting the network, describing a round-the-clock push to dismantle the group and chase new leads. The director did not release the suspect’s identity, and no criminal charges had been made public as of October 9.

According to The Hacker News, the New York Times and CBS News reported that the person arrested is a Canadian citizen apprehended in Pennsylvania, and a law enforcement source told CBS News he is believed to have been directly involved in the hack.

The September breach of FBIjobs.gov

In September, ShinyHunters publicly claimed it had breached the FBI’s jobs site and stolen sensitive data covering almost all FBI agents and job applicants. USA Today reported that an internal FBI memo obtained by Reuters showed officials assumed all current and former employees had been exposed. A Reuters analysis of a sample of the stolen data found employee personal information, details of sensitive job roles, and medical information, The Hacker News reported.

The FBI’s review found the breach resulted from a security failure on a platform managed by an outside organization. Assistant Director of the FBI’s Cyber Division Brett Leatherman told Reuters that a contractor failed to implement an explicitly issued security patch, and two sources told Reuters the platform was Oracle’s PeopleSoft human-resources software. The FBI has since removed the contractor, though it has not publicly named the platform or the organization.

Earlier arrests in the Netherlands and Jordan

The October 9 arrest is at least the third made public since the breach broke in late September. On September 15, Dutch National Police arrested a 24-year-old man suspected of playing a role in ShinyHunters; the FBI announced the arrest on September 29, calling him one of the group’s alleged leaders. Dutch police did not name him, but Reuters reported that Amsterdam-based cybersecurity firm Neo Security identified the suspect as Pepijn van der Stap, its offensive security lead. In late September, Reuters sources reported the detention of a man named Saif al-Din Khader, known as “Rey,” in Jordan, and that he is cooperating with the FBI.

Patel wrote on October 9 that the bureau will keep working with its partners to disrupt what remains of the ShinyHunters group and its associates. A law enforcement source told CBS News that other suspected co-conspirators are still free.

The scale of the alleged crime spree

According to USA Today, Leatherman said the cybercriminals have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments since 2025, frequently targeting third-party vendors and cloud-based platforms and extorting victims with threats to publish stolen data.

What happens next

Patel said the case remained under investigation as of October 9. With the suspect’s name and any charges still undisclosed, the Pennsylvania arrest opens a new phase of the case. If formal charges are filed, court filings should reveal the suspect’s identity and his alleged role in the intrusion.

Frequently asked questions

Who are the ShinyHunters?

The FBI describes ShinyHunters as a global cybercrime and threat-actor group linked to cyberattacks in the United States, the Netherlands, and around the world, specializing in large-scale data breaches and extortion.

What did the group allegedly steal from the FBI?

In September 2026, ShinyHunters claimed it had breached the FBI’s jobs portal, FBIjobs.gov, stealing personnel data covering almost all FBI agents and job applicants, including personal information and medical records.

Who was arrested on October 9?

The FBI has not named the suspect. The New York Times and CBS News, citing unnamed sources, reported the suspect is a Canadian citizen arrested in Pennsylvania believed to have been directly involved in the hack.

Has the suspect been charged?

No charges had been made public as of October 9, 2026, when FBI Director Kash Patel announced the arrest.

Who else has been arrested in the investigation?

A 24-year-old man arrested in the Netherlands on September 15, identified by cybersecurity sources as alleged ShinyHunters leader Pepijn van der Stap, and Saif al-Din Khader, detained in Jordan in late September and reportedly cooperating with the FBI.

How did the hackers get into the jobs portal?

The FBI’s review found a security failure on a platform managed by an outside organization. A contractor failed to implement an explicitly issued security patch, according to Assistant Director Brett Leatherman. Two sources told Reuters the platform was Oracle’s PeopleSoft software.

How many victims has ShinyHunters allegedly hit?

Leatherman said the group has allegedly breached more than 140 organizations and collected at least $70 million in extortion payments since 2025.

Is the investigation over?

No. Patel said on October 9 that the case remained under investigation, and other suspected co-conspirators are reportedly still free.

Featured image: Joe Miller (joemiller.us)

Leave a comment

Your email address will not be published.