FBI Director Announces Third Arrest Tied to ShinyHunters' Breach of the Bureau Itself
The FBI has arrested another suspected member of the ShinyHunters extortion group believed to be involved in the breach of the bureau's own systems, Director Kash Patel announced on Friday, October 9, 2026. Patel said on X that "agents in the field have arrested another suspected co-conspirator of the ShinyHunters group — the group believed to be responsible for the recent FBIjobs.gov incident, which occurred on a platform managed by a third-party vendor." According to The New York Times, the suspect is a Canadian citizen who was arrested in Pennsylvania and is considered a primary co-conspirator in the intrusion. Neither Patel nor the FBI has publicly named the suspect or disclosed specific charges.
This is a distinct, newer development from CosmicBytez Labs' prior coverage of the case — it is not the same individual as "Rey" (reportedly Saif al-Din Khader), the ShinyHunters-linked teenager detained in Jordan and reported to be cooperating with the FBI as of October 1, 2026. This Pennsylvania arrest marks the third known arrest publicly tied to the FBI breach since news of the intrusion broke in late September.
What Happened
The Announcement
Patel's statement, posted to X on October 9, framed the arrest as part of an accelerating enforcement push: "This is the latest arrest this FBI has made in a matter of days involving this network, as we work non-stop to dismantle the group, pursue new leads and evidence, and act quickly." He added that the bureau would "continue to work closely with our partners to disrupt what's left of the ShinyHunters group and their associates, no matter where they operate."
Incident Details
| Attribute | Value |
|---|---|
| Group | ShinyHunters (part of the "Scattered Lapsus$ Hunters" alliance) |
| Latest suspect | Unnamed Canadian citizen, arrested in Pennsylvania |
| Announcement | October 9, 2026, by FBI Director Kash Patel |
| Breached system | FBIjobs.gov, hosted on a platform managed by a third-party vendor |
| Breach window | September 2026 |
| Method | Alleged exploitation of an Oracle PeopleSoft zero-day, followed by lateral movement into FBI-managed AWS GovCloud infrastructure |
| Data allegedly stolen | 2 to 3 terabytes, including current/former employee records, job applicant data, medical and psychiatric records, home addresses, and Social Security numbers |
| Prior arrests in case | Pepijn van der Stap ("Umbreon"), Amsterdam, September 15, 2026; Saif al-Din Khader ("Rey"), detained in Jordan, reported October 1, 2026 |
| Other fallout | An Accenture contractor was removed by the FBI after allegedly failing to implement a required security patch |
Who Named the Suspect
Authorities have not released the suspect's name, nationality details beyond "Canadian citizen," or the specific statute(s) under which he may be charged. Reporting attributes the identification of his citizenship and the Pennsylvania arrest location to The New York Times; CosmicBytez Labs has not independently verified those details beyond what multiple outlets, including BleepingComputer and CBS News, have corroborated.
The FBI's Own Breach
ShinyHunters first told BleepingComputer in September 2026 that it had accessed FBI systems by exploiting an alleged Oracle PeopleSoft zero-day vulnerability — PeopleSoft being the human-resources management platform the bureau's jobs site relies on. From there, the group claimed to have moved laterally into FBI-managed AWS GovCloud infrastructure, stealing between 2TB and 3TB of data.
The exposed material reportedly includes records on current and former FBI employees, job applicants, medical and psychiatric records, home addresses, Social Security numbers, sensitive job assignments, and family-member information. An internal FBI memo reportedly told staff the bureau was operating on the assumption that the breach affected all employees. Some reporting has characterized the incident as potentially the most damaging federal personnel-data breach since the 2015 Office of Personnel Management (OPM) hack.
In the aftermath, the FBI removed an Accenture contractor responsible for the FBIjobs.gov platform after the contractor allegedly failed to apply a required security patch — underscoring that the root-cause failure sat with third-party vendor patch management rather than internal FBI infrastructure.
ShinyHunters' 2026 Activity
ShinyHunters has been one of the most prolific extortion operations tracked by CosmicBytez Labs through 2026, with a cadence of breaches spanning retail, telecom, healthcare, automotive, SaaS platforms, and now federal law enforcement. Beyond the FBI intrusion, the group has separately claimed to have breached the Clop ransomware gang's own leak site and threatened to extort Clop in turn — an unusual extortion-of-an-extortionist maneuver. Dutch police statements tied to the September 15 Amsterdam arrest linked the broader group to breaches at 140-plus organizations and more than $70 million in extortion payments since 2025.
Enforcement pressure through late September and early October 2026 has visibly rattled the group: its main Telegram representative reportedly stopped responding and deleted their account, and a ShinyHunters-linked data-leak site briefly went offline before relaunching with its remaining active members. The Pennsylvania arrest is the third publicly known arrest tied specifically to the FBI breach in a matter of weeks, following the Amsterdam arrest of Pepijn van der Stap and the Jordan detention of Saif al-Din Khader.
Why This Matters for Security Teams
- Third-party vendor risk is the actual attack surface. The FBI's own breach originated on a vendor-managed platform (FBIjobs.gov) and was compounded by an unapplied patch at a contractor (Accenture) — a reminder that an organization's security posture is only as strong as its weakest outsourced dependency.
- Patch cadence on enterprise HR/ERP platforms deserves the same urgency as internet-facing edge devices. The alleged Oracle PeopleSoft zero-day shows that back-office HR systems are now a viable initial-access vector into cloud infrastructure, not just a compliance afterthought.
- Cloud lateral movement from an on-prem or SaaS foothold remains a core ShinyHunters TTP. The claimed pivot from PeopleSoft into AWS GovCloud infrastructure illustrates why segmentation between HR/application platforms and broader cloud environments matters, even inside federal government networks.
- Arrests do not retire stolen data. Organizations and individuals previously named in ShinyHunters breaches, or anyone affected by the FBI incident, should continue to assume exposed data remains tradeable and exploitable regardless of ongoing prosecutions.
- Expect continued multi-country enforcement activity, not a single decisive takedown. With three arrests in roughly three weeks across the United States, the Netherlands, and Jordan, ShinyHunters' loosely affiliated, pseudonymous membership model means additional arrests — and additional leaks from remaining members racing to monetize data before they're next — are both plausible in the near term.
- Verify vendor patch-management SLAs now, not after a breach notification. Contractors managing internet-facing HR or recruiting platforms should be contractually required to apply critical vendor patches (e.g., Oracle security alerts) within a defined window, with audit rights to confirm compliance.