FBI Arrests Another Suspected ShinyHunters Member After Agency Breach

Summary
The FBI says it arrested another suspected ShinyHunters co-conspirator linked to the breach of a third-party-managed FBI platform. The suspect's identity and charges have not been publicly disclosed.
Key points
- FBI Director Kash Patel announced the arrest, but authorities have not named the suspect or disclosed charges.
- The New York Times reported that the suspect is a Canadian citizen arrested in Pennsylvania and considered a primary co-conspirator.
- ShinyHunters claimed it exploited an alleged Oracle PeopleSoft zero-day to access the platform, then moved into FBI-managed AWS GovCloud infrastructure.
- The FBI said the breach stemmed from a third-party contractor-managed platform that had not installed a security update.
- Data samples reportedly confirmed exposure of employee information, including home addresses, Social Security numbers, sensitive job assignments, and family information.
- The arrest follows other law-enforcement actions and reported disruption to ShinyHunters accounts and leak sites; the group's new leak site suggests some members remain active.
Article Details
- Event Type
- Arrest of a suspected ShinyHunters co-conspirator believed to be involved in the FBI systems breach.
- Impact
- The FBI breach exposed personal and sensitive information belonging to current and former employees and job applicants. ShinyHunters claimed to have stolen 2TB to 3TB of data; samples shared with media confirmed exposure of information including home addresses, Social Security numbers, sensitive job assignments, family-member information, and medical and psychiatric records.
People
Brett LeathermanFBI Cyber Division Assistant Director who publicly warned ShinyHunters members to turn themselves in.Kash PatelFBI Director who announced the arrest and described the group's suspected responsibility for the recent breach.Pepijn van der StapDutch suspect arrested on September 15 in an investigation into ShinyHunters; previously known online as "Umbreon." ShinyHunters denied he was associated with the group.Saif al-Din KhaderIdentified by Reuters as the person known online as "Rey," reportedly detained in Jordan and aiding investigators.
Threat Actors
Products
Adobeaccess connected enterprise platforms, including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.Atlassianenterprise platforms, including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.AWS GovCloudShinyHunters told BleepingComputer in September that it accessed FBI systems by exploiting an alleged Oracle PeopleSoft zero-day vulnerability before moving laterally into FBI-managed AWS GovCloud infrastructure.Dropboxincluding Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.Google WorkspaceSSO accounts to access connected enterprise platforms, including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.Instructure CanvasShinyHunters was also behind a massive data-theft attack on Instructure Canvas in May that caused significant outages across the platform.Microsoft 365use compromised SSO accounts to access connected enterprise platforms, including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.OktaMore recently, ShinyHunters has run voice phishing (vishing) campaigns targeting Okta, Microsoft, and Google single sign-on (SSO) accounts, impersonating IT support personnel to trick employees into entering credentialsOracle PeopleSoftShinyHunters told BleepingComputer in September that it accessed FBI systems by exploiting an alleged Oracle PeopleSoft zero-day vulnerability before moving laterally into FBI-managed AWS GovCloud infrastructure.PowerSchoolShinyHunters name, including individuals connected to the Snowflake data-theft attacks, breaches at PowerSchool, and the operation of the Breached v2 hacking forum.SalesforceRecent campaigns have targeted Salesforce and other cloud SaaS environments, with the threat actors linked to breaches affecting companies including Google, Cisco, PornHub, and online dating giant Match Group.SAPaccounts to access connected enterprise platforms, including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.Slackto access connected enterprise platforms, including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.Snowflakesuspects over the years in cases tied to the ShinyHunters name, including individuals connected to the Snowflake data-theft attacks, breaches at PowerSchool, and the operation of the Breached v2 hacking forum.Zendeskplatforms, including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.