FBI arrested a Canadian suspect linked to the ShinyHunters extortion group in Pennsylvania, following a breach of FBI systems via a third‑party vendor that exploited an Oracle PeopleSoft zero‑day, leaking 2‑3 TB of employee data. Recent law‑enforcement actions include arrests of Dutch hacker Pepijn van der Stap and Jordanian operative Saif al‑Din Khader, while ShinyHunters continues aggressive extortion campaigns targeting cloud SaaS platforms through vishing and credential theft. The group’s tactics involve initial exploitation, credential harvesting, lateral movement into AWS GovCloud, and large‑scale data exfiltration.
| IOC Type | Value | Description | Relevant MITRE ATT&CK Techniques |
|---|---|---|---|
| Domain |
http://FBIjobs.gov
|
Third‑party platform used in the FBI breach; exploited for initial access | T1190 |
| Vulnerability | Oracle PeopleSoft zero‑day vulnerability | Exploited to gain initial access to FBI systems | T1190 |
| Code | Title |
|---|---|
| T1190 | Exploit Public-Facing Application (Oracle PeopleSoft zero‑day) |
| T1078 | Valid Accounts (stolen credentials / SSO tokens) |
| T1566.004 | Vishing (voice‑phishing to obtain credentials) |
| T1552 | Unsecured Credentials (credential theft and harvesting) |
| T1021 | Remote Services (lateral movement to cloud infrastructure) |
| T1048 | Exfiltration Over Alternative Protocol (large‑scale data theft) |
| T1071 | Application Layer Protocol (data exfiltration via SaaS services) |
| Type | Value |
|---|---|
| Country | United States |
| Sector | government |
The FBI has arrested another suspected member of the ShinyHunters extortion group believed to be involved in the recent breach of FBI systems, Director Kash Patel announced Friday. "Our agents in the field have arrested another suspected co-conspirator of the ShinyHunters group – the group believed to be responsible for the recent
The FBI has since said the incident stemmed from a third-party contractor-managed platform that failed to install a security update. Since the FBIJobs hack, the bureau has significantly increased pressure on identifying and apprehending the ShinyHunters extortion gang On September 15, Dutch police arrested a 24-year-old Amsterdam man as part of an investigation into the hacking group. The suspect was identified as Pepijn van der Stap, a Dutch hacker previously known online as "Umbreon." ShinyHunters denied that van der Stap was associated with the group, telling BleepingComputer at the time, "That individual has no association with us. Frankly, we are laughing." Soon afterward, the FBI took the unusual step of publicly warning ShinyHunters members to turn themselves in , saying investigators were continuing to identify people involved with the group. "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left," FBI Cyber Division Assistant Director Brett Leatherman said at the time. "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours." Days later, a suspected ShinyHunters member known online as "Rey" was reportedly detained in Jordan and began cooperating with the FBI and international law enforcement agencies. Reuters reported that Jordanian authorities detained Rey, identified as Saif al-Din Khader, and that sources said he was aiding investigators in finding other alleged members of the group. Signs of disruption also began appearing within ShinyHunters around the same time. The group's main representative, who had regularly communicated with BleepingComputer and other reporters and had intimate knowledge of ShinyHunters' attacks over the past two years, stopped responding on Telegram last Tuesday. That Telegram account now appears to have been deleted.
The same representative continued communicating with BleepingComputer after van der Stap's arrest, suggesting van der Stap wasn't the person operating the account. Around the same time as Rey's arrest, another alleged ShinyHunters affiliate with intimate knowledge of the FBI hack shut down an online messaging account, and the group's data leak site went offline. A new ShinyHunters leak site later launched, suggesting at least some members of the operation remained active. It is unclear whether the disappearance of the group's main representative is connected to any of the recent arrests. "We will continue to work closely with our partners to disrupt what's left of the ShinyHunters group and their associates, no matter where they operate," Patel said Friday. Who is ShinyHunters? ShinyHunters is an extortion group known for stealing data from web applications and cloud-based SaaS platforms, then demanding ransom payments from victim organizations under threat of leaking the stolen data. The ShinyHunters name has been tied to numerous threat actors involved in data breaches dating back to at least 2018. Over the past two years, hackers operating under the ShinyHunters name have become particularly active, conducting data theft and extortion campaigns against organizations worldwide. Recent campaigns have targeted Salesforce and other cloud SaaS environments, with the threat actors linked to breaches affecting companies including Google , Cisco , PornHub , and online dating giant Match Group . In some attacks, the group breached third-party integration companies and stole authentication tokens that attackers could then use to access connected SaaS environments and steal customer data. More recently, ShinyHunters has run voice phishing (vishing) campaigns targeting Okta, Microsoft, and Google single sign-on (SSO) accounts , impersonating IT support personnel to trick employees into entering credentials and multi-factor authentication (MFA) codes into phishing sites.
As BleepingComputer first reported , the group has also used device code vishing attacks to steal Microsoft account authentication tokens. Once they obtain credentials and authentication codes, the attackers use compromised SSO accounts to access connected enterprise platforms, including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox. ShinyHunters was also behind a massive data-theft attack on Instructure Canvas in May that caused significant outages across the platform. Instructure later reached an "agreement" with the threat actors to prevent them from publishing data stolen in the breach. In addition to conducting its own breaches, ShinyHunters also operated as an extortion-as-a-service group, helping other threat actors extort organizations they had compromised. Law enforcement has arrested numerous suspects over the years in cases tied to the ShinyHunters name, including individuals connected to the Snowflake data-theft attacks , breaches at PowerSchool , and the operation of the Breached v2 hacking forum . Despite these arrests, cybercriminals continued to operate under the ShinyHunters name while conducting data theft and extortion attacks against organizations worldwide. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat