FBI Arrests Suspected ShinyHunters Member Linked to Bureau Breach
The FBI has arrested a suspected member of the ShinyHunters extortion group who is believed to have been involved in a recent breach of FBI systems, Director Kash Patel announced Friday.
“Our agents on the scene arrested another suspected co-conspirator from the ShinyHunters group, which is believed to be responsible for recent incidents that occurred on platforms controlled by third-party vendors,” Patel said on X.
“This is the latest arrest the FBI has made within days of involvement with this network, and we are working tirelessly to dismantle the group, pursue new leads and evidence, and move quickly.”
Canadian national arrested in Pennsylvania
Patel did not identify the suspect or say where he was arrested. The New York Times reported that the suspect is a Canadian national who was arrested in Pennsylvania and is considered a key co-conspirator in the break-in.
Authorities have not released the suspect’s name or the specific charges against him.
The arrest is the latest in a series of law enforcement actions against ShinyHunters after the group breached FBI systems last month.
ShinyHunters claims FBI breach exploited Oracle PeopleSoft flaw
ShinyHunters told BleepingComputer in September that it gained access to FBI systems by exploiting an alleged zero-day vulnerability in Oracle PeopleSoft. The attackers claimed they later moved laterally into FBI-managed AWS GovCloud infrastructure.
The attackers claimed to have stolen between 2TB and 3TB of data, including information about current and former FBI employees, job applicants, medical and psychiatric records, internal service records, and more.
Data samples shared with BleepingComputer and other media outlets confirmed that the breach exposed a range of employee information, including home addresses, Social Security numbers, sensitive job assignments, information about employees’ families, and other personal data.
The New York Times also reported that an internal FBI memo said the bureau assumed the breach affected all employees.
The FBI later announced that the incident was caused by a platform managed by a third-party contractor that had failed to install security updates.
FBI increases pressure on ShinyHunters
Since the FBI Jobs hack, the bureau has significantly increased pressure to identify and arrest members of the ShinyHunters extortion gang.
On September 15, Dutch police arrested a 24-year-old man from Amsterdam as part of an investigation into a hacker group. The suspect was identified as Dutch hacker Pepin van der Stapp, who was previously known online as “Umbreon.”
ShinyHunters denied that van der Stapp was associated with the group. The group told BleepingComputer at the time: “That person has nothing to do with us. Frankly, we’re laughing.”
Shortly afterward, the FBI took the unusual step of publicly warning ShinyHunters members to turn themselves in. The bureau said investigators were continuing to identify people associated with the group.
“Arrests are a way to change who is willing to talk, and seized infrastructure is a way to show who’s left behind,” FBI Cyber Division Deputy Director Brett Leatherman said at the time.
“The longer you stay in here, the more we will know about you. You know how to find us, and we know how to find you. We recommend that you contact us first while the choice is still yours.”
Days later, reports said that a suspected ShinyHunters member known online as “Ray” had been detained in Jordan and had begun cooperating with the FBI and international law enforcement agencies.
Reuters reported that Jordanian authorities had detained the suspect, Saif al-Din Kader, and that sources said he was cooperating in the search for other alleged members of the group.
ShinyHunters activity appears disrupted
Around the same time, signs of confusion began to appear within ShinyHunters.
A key group representative who had been in regular contact with BleepingComputer and other reporters—and who was familiar with ShinyHunters’ attacks over the past two years—stopped responding on Telegram last Tuesday.
That Telegram account now appears to have been deleted.
The same representative continued communicating with BleepingComputer after van der Stapp’s arrest, suggesting that van der Stapp was not the person operating the account.
Around the time of Ray’s arrest, another ShinyHunters suspect with knowledge of the FBI hacking operation shut down his online messaging account, and the group’s data leak site went offline.
A new ShinyHunters leak site has since been launched, suggesting that at least some members remain active.
It is unclear whether the disappearance of key group representatives is connected to the recent arrests.
“We will continue to work closely with our partners to destroy what is left of the ShinyHunters group and its associates wherever they operate,” Patel said Friday.
Who are ShinyHunters?
ShinyHunters is an extortion group known for stealing data from web applications and cloud-based software-as-a-service (SaaS) platforms. The group demands ransom payments from victim organizations by threatening to publish stolen data.
The ShinyHunters name has been associated with numerous threat actors involved in data breaches dating back to at least 2018.
Over the past two years, hackers operating under the ShinyHunters name have become particularly active, conducting data theft and extortion campaigns against organizations around the world.
Recent campaigns have targeted Salesforce and other cloud SaaS environments. The attacks have impacted companies including Google, Cisco, PornHub, and online dating giant Match Group.
In some attacks, the group compromised third-party integration companies and stole authentication tokens. The attackers could then use those tokens to access connected SaaS environments and steal customer data.
Most recently, ShinyHunters conducted voice-phishing, or vishing, campaigns targeting Okta, Microsoft, and Google single sign-on (SSO) accounts. The attackers impersonated IT support personnel and tricked employees into entering their credentials and multifactor authentication (MFA) codes into phishing sites.
As first reported by BleepingComputer, the group is also using device-code vishing attacks to steal Microsoft account authentication tokens.
After obtaining credentials and authorization codes, attackers use compromised SSO accounts to access connected enterprise platforms such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.
ShinyHunters was also behind a large-scale data theft attack against Instructure Canvas in May, causing a major outage across the platform. Instructure then reached an “agreement” with the attackers to avoid publication of the stolen data.
In addition to conducting its own breaches, ShinyHunters has operated as an extortion-as-a-service group, helping other threat actors extort compromised organizations.
Over the years, law enforcement has arrested numerous suspects in cases related to the ShinyHunters name, including individuals associated with the Snowflake data theft attack, the PowerSchool breach, and the operation of the Breached v2 hacking forum.
Despite those arrests, cybercriminals have continued to operate under the ShinyHunters name, conducting data theft and extortion attacks against organizations around the world.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



