FBI Arrests Third ShinyHunters Suspect Over FBI Breach
FBI arrested a Canadian national in Pennsylvania, its third ShinyHunters arrest in two weeks, after the group breached FBIjobs.gov and stole data on nearly every FBI employee.

Executive Summary
The FBI has arrested a third suspected member of the ShinyHunters cybercriminal group in connection with the breach of the bureau's jobs portal, FBIjobs.gov, according to a statement from FBI Director Kash Patel released Friday. The arrest, first reported by The New York Times, took place in Pennsylvania and involved a Canadian national.
The detention follows two earlier arrests in a two-week span: Saif al-Din Khader, taken into custody in Jordan on September 28, and Pepijn van der Stap, arrested by Dutch authorities. Khader has reportedly agreed to cooperate with investigators. The FBI has not released the identity of the suspect arrested this week and did not respond to requests for additional detail.
The breach itself exposed sensitive records on nearly every FBI employee, including medical information, home addresses, phone numbers, and internal work assignments. Thousands of records belonging to local police officers who serve on FBI task forces were also compromised. The bureau sent an internal memo last week warning employees of the exposure and the potential risk to them and their families.
Technical Analysis
ShinyHunters claimed responsibility for the intrusion and initially shared samples of stolen data with news outlets to substantiate the claim. In public messages, the group said it accessed FBI systems through a vulnerability in Oracle software that cybersecurity researchers had flagged in June. The FBI's own investigation reportedly traced the breach to an unidentified contractor at Accenture who failed to patch a vulnerable system. Reuters reported that the contractor was fired this week.
The group has since claimed it would not release the stolen data and did not want to escalate its conflict with the FBI, which it said began over a bureau advisory the group disagreed with. The FBI has spent the past two weeks dismantling ShinyHunters infrastructure, and the group said in a Friday message on Telegram that it no longer plans to remain on the platform because several members have been arrested.
Mitigations & Recommendations
Defenders should treat the ShinyHunters breach as a third-party risk case study: the intrusion reportedly originated with an unpatched system at a contractor, not within the FBI's own perimeter. Organizations that rely on external vendors for application hosting or maintenance should verify patch cadence and asset inventory for contractor-managed systems, particularly any Oracle software exposed to the internet. Because the group exfiltrated employee personal data — including medical records and home addresses — affected personnel face elevated risk of targeted phishing and physical threats, and should be enrolled in identity monitoring. The FBI's internal memo to employees is a useful template for breach notifications that go beyond credential resets to address personal safety exposure.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.

