FBI Arrests Suspect in ShinyHunters Hack That Breached Its Databases

By Aldgra Fredly
Aldgra Fredly
Aldgra Fredly
Aldgra Fredly is a freelance writer covering U.S. and Asia Pacific news for The Epoch Times.
October 10, 2026Updated: October 10, 2026

The FBI has arrested a suspect linked to ShinyHunters, the cybercriminal group believed to be responsible for the recent breach of the bureau’s jobs website, Director Kash Patel said on Oct. 9.

“This is the latest arrest this FBI has made in a matter of days involving this network, as we work non-stop to dismantle the group, pursue new leads and evidence, and act quickly,” Patel said in a post on X.

Patel said the FBI’s jobs website was hacked through “a platform managed by a third-party vendor.”

“We will continue to work closely with our partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate,” he added.

Patel did not provide any details about the suspect’s identity or where the individual was arrested.

Royal Canadian Mounted Police (RCMP) spokesperson Ian Lordon said on Oct. 9 that they are aware of the FBI’s arrest of a Canadian citizen in the United States in connection with the ShinyHunters alleged breach of the FBI’s website, but directed all further questions to the FBI.

“The RCMP does not comment on investigations being conducted by other countries,” Lordon said in a statement.

In September, ShinyHunters claimed to have carried out the breach and obtained sensitive information about current and former agents, as well as applicants seeking employment at the bureau.

ShinyHunters made the claim on its dark-web site on Sept. 22, and was questioned by Reuters in an online chat. Reuters said it could not verify the group’s claims, and that attempts to ​reach alleged victims whose data were already compromised in past hacks were ⁠unsuccessful.

The group said on its website and told Reuters that it targeted the FBI because the law enforcement agency made an announcement in May that detailed the group’s methods of operation and told victims not to pay extortion money.

The FBI described ShinyHunters as a cyber criminal group specializing in large-scale data breaches and extortion. The bureau said in its May public service announcement that the group targets major companies in the technology, finance, and retail sectors, often stealing millions of customer records in a single attack.

The bureau also warned that hackers may use their real or exaggerated claims of access to sensitive information to extort money from victims.

“The FBI understands the concerns of individuals and students impacted by recent SH activity,” the bureau said in its recommendations to victims. “Do not send payment or respond to their demands.”

On Sept. 29, the FBI said the Dutch National Police had arrested one of the alleged heads of ShinyHunters. FBI Assistant Director Brett Leatherman said the arrest in the Netherlands should serve as a warning to the group that other members may be next.

“Other groups believed anonymity ​or their friends would protect them, and they were wrong,” said Leatherman, ​head of the bureau’s Cyber Division, directly addressing ShinyHunters.

ShinyHunters has said that it did not intend to release the FBI data. The group’s website went offline on Sept. 30 after the deadline it set for the FBI to retract its May statement about the group’s tactics expired.

Tom Gantert, Jack Phillips, and The Canadian Press contributed to this report.