FBI Arrests Another Suspected ShinyHunters Co-Conspirator in FBIJobs.gov Data Breach Investigation

The U.S. Federal Bureau of Investigation (FBI) has arrested another suspected co-conspirator linked to the ShinyHunters cybercrime group as part of its ongoing investigation into the breach of the FBI's jobs portal. FBI Director Kash Patel announced the arrest on October 9, 2026, but authorities have not publicly identified the suspect or announced charges.

According to reports from The New York Times and CBS News, the suspect is a Canadian citizen arrested in Pennsylvania on suspicion of involvement in the theft of FBI data. The FBI has not publicly confirmed these details.

FBI Announces Another Arrest

In a post on X, Patel said FBI agents had arrested another suspected co-conspirator of ShinyHunters, the group believed to be responsible for the recent FBIJobs.gov incident.

Patel said the breach occurred on a platform managed by a third-party vendor and emphasized that the FBI would continue working with international partners to identify and apprehend other individuals allegedly connected to the group.

The arrest is the latest development in a widening investigation. According to CBS News, other suspected co-conspirators may still be at large.

Neither Patel's announcement nor the FBI's public statements identified the newly arrested individual or confirmed whether the suspect directly participated in the FBIJobs.gov breach.

FBIJobs.gov Breach Exposed Sensitive Employee Information

In September 2026, ShinyHunters claimed responsibility for breaching the FBI's jobs portal and stealing sensitive information associated with FBI employees and job applicants.

An analysis of sample data published by the group reportedly revealed personal information, details about sensitive job roles, and medical and psychiatric information.

CBS News also reported that an internal FBI notice confirmed hackers had obtained employee information.

The full scope of the compromised information and the number of affected individuals have not been independently established in the public reporting.

Third-Party Platform Security Failure Under Investigation

The FBI's investigation has identified a security failure involving a platform managed by an outside organization.

On October 5, Brett Leatherman, assistant director of the FBI's Cyber Division, said a contractor had failed to implement a security patch explicitly issued to secure the platform. The FBI subsequently removed the contractor involved, according to reporting on the incident.

Reuters reported that the platform was Oracle PeopleSoft, an enterprise human resources software system, and that Accenture was involved in managing the relevant environment. Accenture said it was proud to support the FBI's mission but did not answer Reuters' specific questions about the contractor.

The FBI has not publicly named the platform or the organization in its own statements about the breach.

Earlier Arrests in the Netherlands and Jordan

The latest arrest follows two previously reported detentions involving suspected ShinyHunters members.

Netherlands: Dutch police arrested a 24-year-old man from Amsterdam on September 15, 2026, on suspicion of involvement with ShinyHunters. The FBI later described the individual as one of the group's alleged leaders. The Dutch police announcement did not specifically link the arrest to the FBIJobs.gov breach.

Jordan: Reuters reported on October 3 that Saif al-Din Khader, known online as “Rey” and “ReyXBF,” had been detained in Jordan on September 29. Sources familiar with the matter said he was cooperating with the FBI to help investigators identify other members of the group.

The FBI has not publicly confirmed whether Khader's reported cooperation contributed to the latest arrest.

ShinyHunters Faces Growing Law Enforcement Pressure

ShinyHunters has been associated with multiple large-scale data theft and extortion incidents. The FBI has alleged that the group and its co-conspirators breached more than 140 organizations and obtained at least $70 million in extortion payments since the previous year.

The group has also attracted attention for targeting third-party vendors and cloud-based platforms, where a single compromised service can expose information belonging to multiple organizations.

ShinyHunters previously said its attack against the FBI was intended to challenge allegations made about the group in an FBI public advisory. The bureau has described ShinyHunters as a cybercriminal organization involved in large-scale data breaches and extortion.

Investigation Remains Ongoing

The latest arrest represents another development in the FBI's international investigation into ShinyHunters and the FBIJobs.gov breach. Investigators are continuing to pursue leads and work with law enforcement partners to identify additional suspects.

However, the identity of the newly arrested individual, the specific charges they may face, and their precise role in the breach remain unconfirmed in public FBI statements.

Key takeaway: The FBI has announced another arrest linked to its investigation into ShinyHunters, but important details remain undisclosed. The investigation highlights the security risks associated with third-party platforms, particularly when critical security patches are not applied promptly.