Ask Finn← Discover
Trending

FBI Closes In on ShinyHunters With Third Arrest After Massive Agent Data Breach

By Riley Carter · Saturday, October 10, 2026
Finn's Take· TL;DR
  • FBI arrests third ShinyHunters suspect in Pennsylvania; hacking group breached FBI jobs portal stealing thousands of employees' personal data.
  • Breach exposed sensitive information on FBI staff working China and Russia cases; caused by contractor failure to patch Oracle PeopleSoft platform.
  • Coordinated global arrests in Jordan, Netherlands, Pennsylvania signal major law enforcement operation dismantling hacking network across multiple countries.
See this from any side — with sources:
Left takeNeutralRight take

Another Suspect in Custody as FBI Dismantles Hacking Network

The FBI's crackdown on the criminal hacking group ShinyHunters accelerated sharply this week, with FBI Director Kash Patel announcing yet another arrest tied to one of the most alarming cybersecurity breaches the bureau has ever faced. Patel announced on Friday, October 9, that agents arrested another suspected co-conspirator linked to the ShinyHunters hacking group earlier in the week, during the bureau's investigation of a cybersecurity incident involving its jobs website.

The FBI did not provide details on the individual's identity or the precise location of the arrest, but a U.S. official and another source briefed on the matter told reporters the suspect was detained in Pennsylvania — and that the suspect is a Canadian citizen believed to be directly involved in the hack of the FBI's website. That same source said other suspected co-conspirators remain at large.

A Breach That Shook the Bureau to Its Core

ShinyHunters claimed responsibility for breaking into an FBI jobs portal and gaining access to the personal data of thousands of current and former FBI employees — including the identities of personnel working in sensitive units focused on China and Russia, according to sources who have seen the data.

A sample of the data that ShinyHunters shared contained extensive personal information on FBI employees, details of sensitive job roles, and psychiatric and medical information, according to a Reuters analysis. Veteran agents are saying the breach may amount to the worst compromise of a federal government system since the infamous hack of the Office of Personnel Management in 2015, when more than 22 million government records were stolen.

The FBI's review found that the breach resulted from a security failure on a platform managed by an outside organization — specifically, after a contractor failed to implement a security patch explicitly issued to secure the platform. The FBI has since removed the contractor. Reuters sources identified the platform as Oracle PeopleSoft and the contractor as Accenture.

A Wave of International Arrests

This is the third publicly announced arrest since news of the breach broke in late September. Multiple FBI sources reported that Saif al-Din Khader was arrested in Jordan on September 28, after being identified by journalists and researchers as a key member of the group — and he allegedly agreed to cooperate with the FBI and other law enforcement agencies to help locate other members of ShinyHunters. That arrest came after the FBI and Dutch National Police announced the arrest of Pepijn van der Stap, another alleged member of the group.

Patel stated, "This is the latest arrest this FBI has made in a matter of days involving this network, as we work non-stop to dismantle the group, pursue new leads and evidence, and act quickly." The pace of arrests — spanning Jordan, the Netherlands, and now Pennsylvania — signals a coordinated global law enforcement effort to unravel the network before its remaining members can scatter further.

What Comes Next

Retired FBI supervisory special agent Jason Pack offered context on the severity of the breach, noting that "there is a meaningful difference between somebody obtaining personnel information and somebody gaining access to classified investigative systems" — suggesting the exposure, while serious for the employees and applicants involved, has not been shown to extend into the bureau's sensitive case files or operational systems.

There has also been an internal inquest at the FBI over how such a critical security lapse happened — a question with consequences that extend well beyond this case. Third-party vendor vulnerabilities have become one of the most exploited entry points for cybercriminals, and the FBIjobs.gov incident is a stark reminder that no organization, not even the nation's top law enforcement agency, is immune. Patel vowed that the FBI will "continue to work closely with our partners to disrupt what's left of the ShinyHunters group and their associates, no matter where they operate." With suspects still at large, that work is far from finished.

Have a question about this story?
Ask Finn — answers grounded in this article, from any viewpoint.