Friday, October 9, 2026 Updated through the day
Previously.
Maine Crime
Exterior of the J. Edgar Hoover Building, FBI headquarters in Washington, D.C.
(Photo: ajay_suresh, CC BY 2.0, via Wikimedia Commons)
Maine · Crime

Another ShinyHunters Suspect in Custody as the FBI Dismantles the Crew That Hacked Its Own Jobs Site

FBI Director Kash Patel announced Friday that agents arrested another suspected member of the ShinyHunters hacking network tied to the September breach of FBIJobs.gov, the recruiting portal where personnel data of current and former employees was stolen.

Share

The short version: FBI Director Kash Patel says federal agents arrested another suspected member of the ShinyHunters hacking network earlier this week, the latest in a string of takedowns the bureau has made in just a matter of days. The arrest is tied to the September breach of FBIJobs.gov, the FBI's recruiting portal, in which hackers stole personnel data belonging to current and former bureau employees.

The breach that started it all

Back in September, the FBI found itself on the receiving end of the kind of incident it usually investigates: a data breach inside one of its own systems. FBIJobs.gov — the portal the bureau uses to recruit and hire new talent — runs on a third-party vendor's platform, and attackers got in through that door. The intrusion exposed personnel data belonging to people who had applied to or worked for the bureau, and an internal FBI memo reportedly assumed the worst: that data belonging to all current and former employees was potentially exposed.

ShinyHunters, the extortion-driven hacking group whose name has been echoing through cybersecurity circles for years, took credit for the breach. To prove it, the group shared a roughly 5,000-entry sample of the stolen data with the outlet Nextgov — names, home addresses, phone numbers, information about relatives, and even identifiers tied to intelligence and surveillance roles. For a workforce built around operational security, that kind of leak isn't just embarrassing; it's genuinely dangerous. Knowing where an agent lives, who their family members are, and what classified-adjacent role they hold is the kind of detail that gets people targeted.

The breach raised immediate questions about how a federal law enforcement agency with the largest cyber division on the planet let its own recruiting infrastructure get plundered through a contractor. The FBI said it would find out who was behind it. It turns out they meant it.

An arrest in Pennsylvania

On Friday, Patel announced that FBI agents had arrested another suspected ShinyHunters co-conspirator earlier in the week, describing it as "the latest arrest this FBI has made in a matter of days involving this network." According to reporting from The New York Times, the suspect is a Canadian citizen who was arrested in Pennsylvania — though Patel did not name the person or specify what charges they face.

It's worth pausing on that detail, because it says a lot about how this investigation is moving. Arrests tied to a hacking crew in a matter of days suggest the FBI has been sitting on intelligence — possibly gathered from the group's own stolen data troves, from seized infrastructure, or from cooperating insiders — and is now acting on it quickly, one target at a time. Patel's announcement also reads like a deliberate message to anyone else in the network: you're next.

For Maine readers, the story carries a straightforward lesson about the stakes here. The FBI's recruiting portal collects applications from aspiring agents in every state, including Maine. If you've ever applied to the bureau — or if a family member has — your information may have been in the mix that was exposed in September. This is not a hypothetical concern anymore; it's an active criminal investigation with arrests happening in real time.

Who ShinyHunters is

ShinyHunters is not a new name in cybercrime. The group's alleged operations stretch back years, built around breaking into corporate databases and extorting the victims for millions. The scale is staggering: FBI cyber division chief Brett Leatherman said the group allegedly breached more than 140 organizations and collected at least $70 million in extortion payments since last year alone.

The takedown campaign against the network kicked into high gear on September 29, when Dutch National Police arrested Pepijn van der Stap, 24, of Amsterdam — identified as the alleged leader of the group. Around the same time, Reuters reported that a second alleged participant, a Jordanian teenager known online as "Rey" whose real name is Saif al-Din Khader, had been detained in Jordan and was cooperating with investigators.

That sequence matters. When one alleged leader is in custody and another alleged member is cooperating, investigators tend to learn a great deal in a hurry — names, handles, communication channels, infrastructure, who did what in which intrusion. Friday's arrest in Pennsylvania may well be the first fruit of that intelligence. The pattern here is one the FBI knows well from dismantling organized crime groups: work from the outside in, flip the cooperators, and let the network unravel.

It's also a reminder that ShinyHunters, despite its playful branding, is alleged to be a serious criminal enterprise. Seventy million dollars in extortion. One hundred forty organizations. And now, a breach of the FBI's own hiring system — a move that reads less like smart crime and more like poking a sleeping giant with a stick.

What comes next

The investigation is clearly still moving. Patel's "matter of days" language implies the bureau is on an arrest streak, and there is no public indication that the string of takedowns is over. Prosecutors will now have to build cases: converting arrests into indictments, charges, and eventually trials, all while respecting the presumption of innocence. Everyone arrested so far is a suspect or alleged participant, not a convicted defendant, and the actual charges against the Pennsylvania suspect have not yet been disclosed.

The larger questions will take longer to answer. How did attackers get through a third-party vendor into a system holding FBI personnel data? What exactly was taken, and how much of it has already been sold or shared? The 5,000-entry sample handed to Nextgov may be only a fraction of the full haul, and extortion groups rarely leave money on the table. Current and former FBI employees — and anyone who applied through FBIJobs.gov — will likely be watching for follow-on reporting about whose data was actually in the stolen set.

There's also the question of what happens to the vendor. When a government agency's contractor gets breached, the fallout doesn't stop at the agency's front door. Expect congressional scrutiny of how the FBI vets and monitors the companies that handle its sensitive systems — and of whether a recruiting portal for the nation's premier law enforcement agency was held to the security standard it deserved.

For now, though, the takeaway is simple: the FBI took a hit in September, and it's hitting back. An alleged leader in a Dutch jail, a cooperating teen in Jordan, and now a Canadian citizen arrested in Pennsylvania — the network that allegedly plundered the bureau's own hiring portal is shrinking fast.

Previously's Maine crime desk is tracking the ShinyHunters investigation as it develops. Read more local crime and news from every state.

Sources

  • USA Today, FBI makes new arrest in ShinyHunters hacking case, Kash Patel says, October 9, 2026
  • Reuters, FBI Director Patel says bureau has arrested another person tied to ShinyHunters hackers, October 9, 2026
  • Nextgov, FBI arrests another ShinyHunters suspect after massive breach of employee data, October 9, 2026
  • CNN, FBI arrests key suspect in major hack of agents' data, October 9, 2026
  • The New York Times, reporting identifying the Pennsylvania arrestee as a Canadian citizen, October 9, 2026
  • Bangor Daily News, Maine crime coverage candidate for local follow-up, October 2026
Share this story