HomeCybersecurityFBI Arrests Another Suspected ShinyHunters Member Over the FBIjobs.gov Breach

FBI Arrests Another Suspected ShinyHunters Member Over the FBIjobs.gov Breach

On 9 October 2026 FBI Director Kash Patel announced that agents have arrested another suspected member of ShinyHunters, the data-theft and extortion group believed to be behind the recent breach of the FBI’s jobs site. The arrest is confirmed. Almost everything else about the suspect comes from unnamed sources, and anyone arrested is presumed innocent until a court decides otherwise.

What the FBI has confirmed

Confirmed (FBI Director’s statement). Patel said agents “arrested another suspected co-conspirator of the ShinyHunters group – the group believed to be responsible for the recent FBIjobs.gov incident, which occurred on a platform managed by a third-party vendor” [4][5]. CNN and Fox News quote him as opening with “Earlier this week” [1][5]. He called it “the latest arrest this FBI has made in a matter of days involving this network” [2][4].

The FBI has not named the suspect, said where the arrest happened, or announced charges [2][4]. TSN found no Justice Department press release or court filing on this arrest, so there is no charging document to read yet. Charges, when they come, are allegations.

What is reported, and by whom

Reported (unnamed sources). The New York Times reported that the suspect is a Canadian citizen arrested in Pennsylvania and considered a “primary co-conspirator” in the intrusion, as relayed by BleepingComputer [4]. CBS News said a US official and another source told it the suspect was detained in Pennsylvania, and a law enforcement source said he is a Canadian citizen believed to be directly involved in the hack [2]. That source also said other suspected co-conspirators remain at large [2]. An FBI spokesperson declined to comment on the New York Times report [2]. These details are not from the FBI, and TSN has not confirmed them.

The wider case

Confirmed (FBI), as relayed by CBS. The FBI’s cyber division chief, Brett Leatherman, said a review found a contractor had failed to apply a security patch to the targeted system, and that the contractor was removed [2].

ShinyHunters’ own claim. The group told BleepingComputer it got in through an alleged Oracle PeopleSoft zero-day vulnerability and stole between 2TB and 3TB of data [4]. That is the group’s account, not a finding by the FBI. The FBI’s own explanation is the missed patch above.

Two other people have been publicly linked to the group in recent weeks. A 24-year-old was arrested in the Netherlands on 15 September, before the breach was made public, and the group denied he was a member [2][4]. Reuters, as relayed by The Record, reported that another suspect was detained in Jordan and is said to be cooperating with investigators [3]. Patel described the arrests as “involving this network”, but the FBI has not published how the individual cases connect.

What this does not prove

  • That the person arrested carried out the breach. “Suspected co-conspirator” is the FBI’s phrase. No charges have been announced, and an arrest is not a conviction.
  • That the reported details are right. Nationality, location and the “primary” role come from unnamed sources, and the FBI declined to confirm them.
  • That the group’s account of how it got in is correct. The PeopleSoft claim is ShinyHunters’ own.
  • That the group is finished. The group’s name has been used by different actors over the years, and BleepingComputer notes a new leak site appeared after earlier arrests [4].

The Bottom Line

The arrest is confirmed by the FBI Director himself. The suspect’s identity, charges and role are not public, and what has been reported about him comes from anonymous sources. The cause the FBI gives, a contractor’s missed patch, differs from the group’s claim of a zero-day. Treat each as a separate statement until a court filing settles it.

Related on TSN: Cyber Breaches, 9 October 2026: A Biotech’s Old Cloud, a Turkish University and a Louisiana Clinic · Cyber breaches this week: credential reuse, retail alerts, campus ransomware and edge-gear risk

Sources

  1. CNN, “FBI arrests key suspect in major hack of agents’ data”, 9 October 2026 (quotes Patel; names the New York Times as first to report). https://www.cnn.com/2026/10/09/politics/fbi-arrest-shinyhunters-hack
  2. CBS News, Sarah N. Lynch, “FBI arrests suspected member of ShinyHunters in connection with breach of bureau’s jobs website”, 9 October 2026 (Patel statement; unnamed US official and law enforcement sources; Leatherman statement; FBI declined comment on New York Times details). https://www.cbsnews.com/news/fbi-shinyhunters-arrest-jobs-website-hack/
  3. The Record from Recorded Future News, Jonathan Greig, “FBI touts another ShinyHunters arrest in response to data breach”, 9 October 2026 (Patel statement; Reuters-sourced detail on the Jordan detention). https://therecord.media/shinyhunters-arrest-fbi-data-breach-investigation
  4. BleepingComputer, Lawrence Abrams, “FBI arrests another suspected ShinyHunters hacker after agency breach”, 9 October 2026 (Patel’s post on X as quoted; New York Times detail; ShinyHunters’ claims to BleepingComputer). https://www.bleepingcomputer.com/news/security/fbi-arrests-another-suspected-shinyhunters-hacker-after-agency-breach/
  5. Fox News, Brittany Miller, “FBI arrests another ShinyHunters suspect in FBIjobs.gov data breach”, 9 October 2026 (Patel’s 9 October statement in full; notes the extent of the breach is not independently confirmed). https://www.foxnews.com/politics/kash-patel-announces-arrest-suspected-shinyhunters-co-conspirator-fbi-jobs-portal-breach
  6. Associated Press, Eric Tucker, “FBI arrests co-conspirator in hacking group breach of jobs site”, 9 October 2026 (search-result excerpt only; the page itself blocked automated access). https://apnews.com/article/shinyhunters-fbi-jobs-site-hack-kash-patel-b27bad3059c9ab93d1d7006d3af13c0a

Share this story

More in this category

Latest on TSN

Free TSN tools: crypto calculator, Flux dashboard and more.