FBI arrests Canadian ShinyHunters suspect in Pennsylvania
The arrest is the third law enforcement action against the group in under two weeks, as the bureau traces the breach of its own employee data to a contractor's missed patch.
TL;DR
The FBI has arrested a Canadian man in Pennsylvania suspected of being a ShinyHunters co-conspirator in the breach of the FBIJobs.gov portal, Director Kash Patel said Friday. The arrest follows the Dutch arrest of an alleged group leader and the detention of Saif al-Din Khader in Jordan, who Reuters reported is cooperating with investigators. The breach (traced to a contractor's failure to apply an available security patch on a third-party-managed platform) exposed names, home addresses, phone numbers, spouse information, and details about personnel in intelligence and surveillance roles. The FBI has removed the contractor.

FBI Director Kash Patel's announcement Friday pushes the ShinyHunters dismantlement into its third law enforcement action in under two weeks. Dutch authorities arrested an alleged leader of the group on September 29; Jordanian authorities detained Saif al-Din Khader, who Reuters reported is cooperating with investigators; and now a Canadian suspect is in U.S. custody in Pennsylvania.
The group is accused of breaching more than 140 organizations and collecting at least $70 million in extortion payments since last year, according to FBI cyber chief Brett Leatherman. But the breach that appears to have drawn the most sustained law enforcement response is the one against the bureau itself, the intrusion into FBIJobs.gov, a portal managed by a third-party vendor, that exposed roughly 5,000 entries of employee data.
That data included names, home addresses, phone numbers, and information about spouses and siblings. Multiple entries also identified employees involved in intelligence-gathering on Russia, China, and cartels, as well as personnel in electronic surveillance roles and the FBI's FISA Management Unit.
Leatherman confirmed the intrusion resulted from "a contractor failed to implement a security patch explicitly issued to secure the platform." A person with knowledge of the matter told Nextgov/FCW that the contractor worked for Accenture and that Oracle had provided the patches for its PeopleSoft platform, which ShinyHunters claimed as the initial access point. The FBI has removed the contractor.
ShinyHunters told Nextgov/FCW in late September that it never intended to publish the stolen data, describing the episode as a "marketing campaign." The group's statement didn't say the records had been deleted. The data could still be sold or transferred, and the exposure of intelligence personnel roles creates risks that don't disappear just because a public dump was never the plan.
Published ·Deep Fathom