FBI arrests another suspected ShinyHunters hacker after agency breach

Hacker prison

The FBI has arrested another suspected member of the ShinyHunters extortion group believed to be involved in the recent breach of FBI systems, Director Kash Patel announced Friday.

"Our agents in the field have arrested another suspected co-conspirator of the ShinyHunters group – the group believed to be responsible for the recent http://FBIjobs.gov incident, which occurred on a platform managed by a third-party vendor.," Patel said on X.

"This is the latest arrest this FBI has made in a matter of days involving this network, as we work non-stop to dismantle the group, pursue new leads and evidence, and act quickly."

While Patel did not identify the suspect or disclose where the arrest occurred, The New York Times reports that the suspect is a Canadian citizen who was arrested in Pennsylvania and is considered a primary co-conspirator in the intrusion.

Authorities have not publicly disclosed the suspect's name or the specific charges against him.

The arrest is the latest in a series of law enforcement actions against ShinyHunters after the hacking group breached FBI systems last month.

ShinyHunters told BleepingComputer in September that it accessed FBI systems by exploiting an alleged Oracle PeopleSoft zero-day vulnerability before moving laterally into FBI-managed AWS GovCloud infrastructure.

The threat actors claimed they stole between 2TB and 3TB of data, including information on current and former FBI employees, job applicants, medical and psychiatric records, and internal service records.

Data samples shared with BleepingComputer and other media outlets confirmed that the breach exposed a variety of employee information, including home addresses, Social Security numbers, sensitive job assignments, information about employees' family members, and other personal data.

The NY Times also reports that an internal FBI memo said the agency assumed the breach had affected all employees.

The FBI has since said the incident stemmed from a third-party contractor-managed platform that failed to install a security update.

Since the FBIJobs hack, the bureau has significantly increased pressure on identifying and apprehending the ShinyHunters extortion gang

On September 15, Dutch police arrested a 24-year-old Amsterdam man as part of an investigation into the hacking group. The suspect was identified as Pepijn van der Stap, a Dutch hacker previously known online as "Umbreon."

ShinyHunters denied that van der Stap was associated with the group, telling BleepingComputer at the time, "That individual has no association with us. Frankly, we are laughing."

Soon afterward, the FBI took the unusual step of publicly warning ShinyHunters members to turn themselves in, saying investigators were continuing to identify people involved with the group.

"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left," FBI Cyber Division Assistant Director Brett Leatherman said at the time.

"The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."

Days later, a suspected ShinyHunters member known online as "Rey" was reportedly detained in Jordan and began cooperating with the FBI and international law enforcement agencies.

Reuters reported that Jordanian authorities detained Rey, identified as Saif al-Din Khader, and that sources said he was aiding investigators in finding other alleged members of the group.

Signs of disruption also began appearing within ShinyHunters around the same time.

The group's main representative, who had regularly communicated with BleepingComputer and other reporters and had intimate knowledge of ShinyHunters' attacks over the past two years, stopped responding on Telegram last Tuesday.

That Telegram account now appears to have been deleted.

The same representative continued communicating with BleepingComputer after van der Stap's arrest, suggesting van der Stap wasn't the person operating the account.

Around the same time as Rey's arrest, another alleged ShinyHunters affiliate with intimate knowledge of the FBI hack shut down an online messaging account, and the group's data leak site went offline.

A new ShinyHunters leak site later launched, suggesting at least some members of the operation remained active.

It is unclear whether the disappearance of the group's main representative is connected to any of the recent arrests.

"We will continue to work closely with our partners to disrupt what's left of the ShinyHunters group and their associates, no matter where they operate," Patel said Friday.

Who is ShinyHunters?

ShinyHunters is an extortion group known for stealing data from web applications and cloud-based SaaS platforms, then demanding ransom payments from victim organizations under threat of leaking the stolen data.

The ShinyHunters name has been tied to numerous threat actors involved in data breaches dating back to at least 2018.

Over the past two years, hackers operating under the ShinyHunters name have become particularly active, conducting data theft and extortion campaigns against organizations worldwide.

Recent campaigns have targeted Salesforce and other cloud SaaS environments, with the threat actors linked to breaches affecting companies including Google, Cisco, PornHub, and online dating giant Match Group.

In some attacks, the group breached third-party integration companies and stole authentication tokens that attackers could then use to access connected SaaS environments and steal customer data.

More recently, ShinyHunters has run voice phishing (vishing) campaigns targeting Okta, Microsoft, and Google single sign-on (SSO) accounts, impersonating IT support personnel to trick employees into entering credentials and multi-factor authentication (MFA) codes into phishing sites.

As BleepingComputer first reported, the group has also used device code vishing attacks to steal Microsoft account authentication tokens.

Once they obtain credentials and authentication codes, the attackers use compromised SSO accounts to access connected enterprise platforms, including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.

ShinyHunters was also behind a massive data-theft attack on Instructure Canvas in May that caused significant outages across the platform. Instructure later reached an "agreement" with the threat actors to prevent them from publishing data stolen in the breach.

In addition to conducting its own breaches, ShinyHunters also operated as an extortion-as-a-service group, helping other threat actors extort organizations they had compromised.

Law enforcement has arrested numerous suspects over the years in cases tied to the ShinyHunters name, including individuals connected to the Snowflake data-theft attacks, breaches at PowerSchool, and the operation of the Breached v2 hacking forum.

Despite these arrests, cybercriminals continued to operate under the ShinyHunters name while conducting data theft and extortion attacks against organizations worldwide.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Dive deeper

Free tools to verify and analyze what this article covers:

source: BleepingComputer