FBI Director Kash Patel announced the arrest of a suspected co-conspirator linked to the ShinyHunters breach of the bureau’s jobs website.
FBI agents arrested a suspected co-conspirator linked to the cybercriminal group ShinyHunters earlier this week, FBI Director Kash Patel announced on Friday. The arrest follows an ongoing investigation into a breach of the bureau’s FBIjobs.gov website, where hackers stole personal data belonging to agency employees and job applicants.
The FBI didn’t release the suspect’s name or specify where the arrest took place, but CBS News reported that agents detained the individual in Pennsylvania, citing a U.S. official and another source briefed on the matter. A law enforcement source speaking on condition of anonymity told the network that the suspect is a Canadian citizen believed to have been directly involved in hacking the website. Other suspected co-conspirators remain at large. The New York Times had earlier reported Friday that the suspect was taken into custody in Pennsylvania on suspicion of participating in the theft of FBI data, though an FBI spokesperson declined to comment on those details. In a statement, the Royal Canadian Mounted Police confirmed it was aware that a Canadian had been arrested in the United States over the hack, adding that it doesn’t comment on foreign investigations.
What the breach exposed
The intrusion into the hiring portal happened in September and was first reported on Sept. 22 by 404 Media. ShinyHunters subsequently claimed credit for the attack, saying it took 2 to 3 terabytes of employee-related data. According to Fox News, the cybercrime network claimed it stole records belonging to nearly all FBI agents and people who applied for jobs at the bureau. A data sample shared with Reuters contained agents’ names, home addresses, Social Security numbers, job assignments, and in some cases, the names of family members. The FBI hasn’t independently confirmed the full scale of the alleged breach. Several veteran agents said the incident could amount to the worst breach of a federal system since the 2015 Office of Personnel Management hack, in which over 22 million records were stolen.
Vendor flaw and contractor removal
The hackers gained entry using a new vulnerability in Oracle PeopleSoft, a human resources management program. The FBI investigated whether the breach originated in its own network or through a third-party vendor running the jobs website. Earlier in the week, Brett Leatherman, assistant director of the FBI’s Cyber Division, said an internal review determined that an outside contractor failed to apply a security patch to the targeted software. Leatherman said the bureau took steps to mitigate risks and removed the contractor, which Reuters identified as Accenture. Jason Pack, a retired FBI supervisory special agent and CEO of Media Rep Global Strategies, noted that obtaining personnel files differs significantly from accessing classified investigative systems. “Based on what we know right now, there is no indication they have the keys to the kingdom,” Pack said.
International arrests tied to the group
Patel said the Pennsylvania arrest was part of a broader effort to break up the hacking ring. “This arrest demonstrates the strength and reach of our efforts to protect Americans from cybercrime,” Patel said in an Oct. 9 statement, adding that investigators are pursuing additional leads to dismantle what remains of the group. The operation follows other international detentions. On Sunday, CBS News reported that Pennsylvaniaian authorities detained Saif al-Din Khader, who used the online handle “Rey” and is suspected of involvement in ShinyHunters. Dutch authorities also arrested 24-year-old Pepijn van der Stap in Amsterdam on Sept. 15, about a week before the cybercriminal group claimed credit for breaching the FBI jobs site.
