Jordanian authorities detained a suspected member of the ShinyHunters extortion group this week. According to two U.S. officials and a third source who spoke to CBS News, the suspect is cooperating with investigators. Reuters first reported the arrest. CBS News's sources named the suspect as Saif al-Din Khader. Reports that the suspect is a teenager do not appear in the sources reviewed for this brief, so we treat that detail as unconfirmed. The FBI declined to comment on the arrest itself. In a statement, it said it had "already worked with partners to arrest multiple subjects" in connection with the September intrusion. In that intrusion, ShinyHunters defaced the bureau's jobs portal and claimed to have stolen 2TB to 3TB of data on current and former staff and job applicants. The FBI has not publicly confirmed the full scope of the breach. However, TechCrunch reports, citing MS Now, that an internal notification told staff their names, addresses, job titles and Social Security numbers were exposed.
What Happened
On September 22, ShinyHunters claimed it had breached FBI systems. 404 Media was first to report it. The group sent BleepingComputer a screenshot of apply.fbijobs.gov defaced with its Umbreon Pokémon logo and the message "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since '19 ;)". TechCrunch found the jobs portal and the special agent applicant portal showing "down for maintenance" soon afterward.
Accounts of the timing differ a little. BleepingComputer says the group described using the exploit "Monday night" (September 21), while CBC places the theft on Tuesday. Either way, the public claim came on September 22.
The group said the attack was "not financially motivated." It gave the FBI one week to retract or correct a May 15 FBI advisory, which warned that ShinyHunters uses harassment, threats and exaggerated claims about stolen data to pressure victims (Nextgov/FCW). As that deadline neared, the group told CBC, Nextgov/FCW and Hackread that it had "never intended" to publish the data. It called the episode a "marketing campaign to protect our business and actively combat disinformation." The group has not said it deleted the data. It also told CBC that samples already shared with journalists are "out of our control."
At first, the FBI said only that it was aware of the claim and that the point of breach and the data impact were "still undetermined" (Hackread, TechCrunch). By September 26, according to MS Now reporter Ken Dilanian as cited by TechCrunch, the bureau had declared a "cyber security incident" internally.
The Jordan detention is at least the second arrest linked to the group. Dutch National Police and the FBI previously announced that a 24-year-old was arrested in Amsterdam on September 15 on suspicion of ShinyHunters membership. CBS sources identified him as Pepijn van der Stap. He was therefore in custody days before the FBI hack was announced. Whether he played any role in it is unclear. A U.S. source told CBS it is not known how many other people are involved.
What Was Taken
Estimates of the volume and scope vary, and most of them come from the attackers:
- Volume: ShinyHunters claims 2TB to 3TB (BleepingComputer, Hackread, Nextgov/FCW, CBS). Nobody has independently verified this figure.
- Coverage: The group's claims range from "almost all FBI agents" and all job applicants (its leak site, via TechCrunch) to data on "every FBI employee" (CBS). TechCrunch describes it as data on "thousands" of agents and applicants. None of these figures has been verified.
- Verified sample: The group sent news outlets a sample of about 5,000 entries. It listed names, home addresses, phone numbers, and details about spouses and siblings (Nextgov/FCW). 404 Media checked part of the sample against public records.
- Officially acknowledged fields: According to the reported internal FBI notification, exposed data includes names, addresses, job titles and Social Security numbers (TechCrunch, citing MS Now). CBC also reports job assignments.
- Health data: Several outlets have confirmed that some records include medical information, such as blood and urine test records and psychiatric reports (TechCrunch, Nextgov/FCW).
- Sensitive roles: Two people familiar with the matter told Nextgov/FCW that the data covers hundreds of intelligence analysts. Their areas include China, Russia, Hezbollah and cartels. The data also covers staff in human intelligence, electronic surveillance, the Remote Operations Unit and the FISA Management Unit.
ShinyHunters also claims it compromised FBI Criminal Justice, HR, Medlink and other services (BleepingComputer). These claims are unverified.
Why It Matters
The data is a counterintelligence problem first and a privacy problem second. Home addresses, family details and role assignments for staff working on China, Russia and covert surveillance are exactly what a foreign intelligence service would want for targeting, coercion or recruitment (TechCrunch, Nextgov/FCW). ShinyHunters has promised not to publish the data, but that promise reduces little of this risk. Samples are already in circulation, and the group has not claimed it deleted anything.
The arrests show that law enforcement is putting pressure on the group. However, the FBI's reference to "multiple subjects" and the unknown size of the membership suggest the group can still operate. The incident also extends a pattern for ShinyHunters: going after high-value targets through HR and SaaS-adjacent systems rather than hardened core infrastructure. TechCrunch notes this is the second known breach of an FBI system this year.
The Attack Technique
ShinyHunters claims it gained initial access through an undisclosed remote code execution zero-day in Oracle PeopleSoft (BleepingComputer, Hackread). PeopleSoft is an HR platform that commonly stores applicant and employee records. The group told Hackread that apply.fbijobs.gov was its entry point. It says it then moved laterally into FBI-managed AWS GovCloud infrastructure (BleepingComputer, 404 Media via TechCrunch).
The group also told BleepingComputer it is using the same alleged zero-day against other organizations, including Fortune 500 companies. At the time of writing, none of the sources reports an Oracle advisory or a confirmed CVE. Neither the vulnerability nor the lateral movement has been independently verified.
What Organizations Should Do
- Treat Internet-facing PeopleSoft as exposed. Inventory every PeopleSoft instance, take recruiting and applicant portals off the open internet where possible, and apply Oracle Critical Patch Updates as soon as they are released. Watch for an out-of-band advisory.
- Hunt for RCE indicators on HR application servers. Look for unexpected child processes, web shells, new local accounts and outbound connections from PeopleSoft and WebLogic hosts.
- Break the path from HR systems to cloud. Audit IAM roles, access keys and trust relationships that let HR application servers reach cloud storage, including GovCloud tenants. Enforce least privilege and alert on unusual S3 or bulk data access.
- Segment and minimize HR data. Keep applicant data, employee PII and medical records in separate stores with separate access controls. Purge stale applicant records you have no need to keep.
- Prepare people-centric response. If staff in sensitive roles may be exposed, plan for credit monitoring, address-protection options, and briefings on social engineering and approaches by people seeking to coerce or recruit them.
- Watch for defacement and extortion signals. Monitor public portals for unauthorized changes. Brief communications and legal teams on ShinyHunters' pattern of pressure campaigns run through the media.
Sources: Suspected ShinyHunters hacker detained in Jordan, cooperating with... | ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach | Hacking group ShinyHunters claims it breached the FBI, stole agents... | ShinyHunters hackers say they won't leak sensitive FBI data CBC News | Stolen FBI data reveals employees’ roles in intelligence and survei... | ShinyHunters says it won’t publish FBI data - Nextgov/FCW | Exclusive: ShinyHunters Says FBI Data Won’t Be Leaked When Ultimatu... | FBI reportedly declares 'cyber security incident' after hackers ste...