A hooded hacker targets cloud servers and personal data, while phishing icons and a security shield illustrate cyber threats.
The FBI has arrested another suspected member of ShinyHunters, and the case raises uncomfortable questions for anyone who manages identity systems or third-party software. FBI Director Kash Patel announced the arrest Friday. Note: the details below come from Patel's statement and from reporting by BleepingComputer, The Record, Reuters and The New York Times. The FBI has not released a name, a location or charges.

A hooded hacker targets cloud servers and personal data, while phishing icons and a security shield illustrate cyber threats. What the FBI has actually said​

Patel posted on X that agents had arrested another "suspected co-conspirator" of ShinyHunters. He described the group as believed responsible for the FBIJobs.gov incident, which he said occurred on a platform managed by a third-party vendor. He called it the latest arrest involving this network "in a matter of days." He added that the FBI would keep working with partners to disrupt what is left of the group.

Patel did not identify the suspect or say where the arrest happened. The details people are repeating come from outside the FBI:

  • The New York Times reported that the suspect is a Canadian citizen arrested in Pennsylvania, and that he is considered a primary co-conspirator in the intrusion.
  • The Record said the FBI did not respond to its requests for details. It said the operation took place earlier this week.
  • Neither the suspect's name nor the specific charges have been made public.

Treat the nationality and location as press reporting, not FBI confirmation. An arrest also isn't a conviction, and nothing public yet establishes the suspect's exact role.

The breach behind the arrests​

ShinyHunters claimed the FBIJobs.gov compromise in September. The Record says the group took over the domain, defaced it and stole sensitive data on a very large share of FBI employees. The evidence has different levels of reliability:

  • The attackers' claim: ShinyHunters told BleepingComputer it exploited an alleged Oracle PeopleSoft zero-day. It says it then moved laterally into FBI-managed AWS GovCloud infrastructure and took 2TB to 3TB of data. These figures and the entry method are the group's own account and are unverified.
  • The FBI's account: The bureau has said the incident stemmed from a platform run by a third-party contractor that failed to install a security update.
  • Reuters, via The Record: The FBI reportedly traced the breach to an unidentified Accenture contractor who didn't patch a vulnerable system. Reuters reported that the contractor was fired this week. This is sourced reporting, not an official FBI statement.
  • The data: Samples shared with BleepingComputer and other outlets showed home addresses, Social Security numbers, sensitive job assignments and family members' information. The Times reported that an internal FBI memo assumed all employees were affected. That is an internal assumption, not a confirmed count of accessed records.
  • Local police: The Record says the breach also exposed thousands of records about local police officers on FBI task forces.

The attackers' account and the FBI's account don't have to conflict. An unpatched system managed by a vendor could be the same weakness the attackers say they exploited. Nothing public has confirmed that link, so it stays an open question.

The wider crackdown​

This is the latest in a rapid run of actions:

  1. September 15: Dutch police arrested Pepijn van der Stap, 24, of Amsterdam, known online as "Umbreon." ShinyHunters denied any association with him. BleepingComputer noted that the group's main representative kept talking to reporters after the arrest, which suggests he wasn't operating that account.
  2. Public warning: FBI Cyber Division Assistant Director Brett Leatherman publicly told group members to turn themselves in. His message was that arrests change who is willing to talk.
  3. September 28: Reuters, citing FBI sources, reported that Saif al-Din Khader, allegedly known as "Rey," was detained in Jordan. He is said to be cooperating and helping investigators locate other members. The FBI declined to comment on specific arrests abroad.
  4. October 9: The latest arrest, announced by Patel.

The group's online footprint also changed. The main representative stopped answering on Telegram and the account appears to have been deleted. The data leak site went offline, and a new one later appeared. The Record reports that the group returned to Telegram and then said it wouldn't stay long because several members had reportedly been arrested. It also said the group would not release the stolen FBI data. That is the group's own claim.

BleepingComputer says it is unclear whether the representative's disappearance is tied to any arrest. Patel's "dismantle" language is a goal, not a result. A new leak site suggests at least some of the operation is still active. The group has also survived earlier arrests tied to the Snowflake thefts, PowerSchool and Breached v2.

Why Windows and Microsoft 365 admins should care​

Nothing in the reporting says Microsoft products were involved in the FBI breach. The relevance is in how this group works elsewhere, as BleepingComputer describes it:

  • Vishing: Attackers pose as IT support and trick staff into entering credentials and MFA codes on phishing sites. The targets include Okta, Microsoft and Google single sign-on accounts.
  • Device code phishing: BleepingComputer says the group has used device-code vishing to steal Microsoft account authentication tokens.
  • Lateral reach: A compromised SSO account opens connected platforms, including Microsoft 365, Salesforce, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk and Dropbox.
  • Integration tokens: In some attacks the group breached third-party integration companies and stole tokens for connected SaaS environments. The FBI case hasn't been tied to this method.

What admins can do now​

Microsoft's guidance on device code flow is direct. Microsoft Learn says device code flow is rarely used by customers, but is frequently used by attackers. It also says the Microsoft-managed Conditional Access policy that blocks it helps remove this attack vector. Microsoft recommends getting as close as possible to a unilateral block on device code flow, and says to allow it only in well documented and secured use cases, like legacy tooling that can't be updated.

A sensible rollout, based on Microsoft's documentation:

  1. Inventory first. Audit existing device code flow use to see whether it is still needed. Check the Entra sign-in logs.
  2. Plan exceptions. Microsoft's Teams guidance says to scope any exception to specific Teams device resource accounts and exclude the Device Registration Service resource. Teams Rooms devices, smart TVs and printers are typical legitimate users.
  3. Pilot in report-only mode. Review the results before turning the policy on. Microsoft's staged approach has you pilot with selected accounts and Teams devices in report-only mode.
  4. Enforce, then monitor blocked sign-ins and exception group membership.
  5. Keep emergency accounts safe. A third-party guide notes Microsoft recommends excluding at least two break-glass accounts from such policies. Conditional Access also requires Entra ID P1 licensing, according to the same guide.

Beyond that, the usual defences apply. Train help desks and staff that IT support will not ask for an MFA code or a device code. Prefer phishing-resistant authentication. Audit the OAuth tokens and integrations connected to your SaaS tenants.

The vendor lesson​

The FBI's own description is the most useful part for IT teams: a contractor-managed platform missed a security update. Large organisations often treat vendor-run systems as someone else's patching problem. This case suggests that a vendor's missed patch becomes the customer's breach, even when the customer is the FBI.

Practical takeaways:

  • Write patch SLAs into vendor contracts and ask for evidence that they are met.
  • Know which externally facing systems vendors run on your behalf, and scan them yourself.
  • Treat any employee data held by vendors as high-sensitivity. AP noted that exposing employees' and relatives' details can create risks such as harassment, extortion or swatting. That is a risk assessment, not evidence that such harms have occurred.

What to watch​

Key unknowns remain: the suspect's identity, the charges, and whether the arrests reach the people who ran the group's operations. The next signals will be a court filing or indictment and whether the new leak site stays active. If the group's accounts and sites keep disappearing, that would point to genuine disruption. For now, the safer assumption is that the techniques behind these attacks, from vishing to device code abuse to unpatched vendor systems, outlast any one set of arrests.

 

References

  1. FBI arrests another suspected ShinyHunters hacker after agency breach BleepingComputer 2026-10-09T13:02:29-04:00
  2. FBI touts another ShinyHunters arrest in response to data breach | The Record from Recorded Future News therecord.media
  3. Restrict device code flow for Microsoft Teams devices with Conditional Access docs.azure.cn