FBI Director Kash Patel announced on Friday that agents have arrested "another suspected co-conspirator" of ShinyHunters during an operation earlier this week. The arrest comes as the bureau deals with the group's theft of data on nearly its entire workforce, according to The Record.
Patel described it as the newest in a run of arrests tied to the network over a few days. He said the FBI is working with partners to take apart what remains of the group and follow fresh leads wherever its members are based.
The FBI did not answer requests for details. The New York Times reported that the arrest took place in Pennsylvania and that the suspect is a Canadian national. The FBI has not confirmed either point.
Earlier detentions
The Record says at least two other suspected members have been taken into custody in the past two weeks. It does not say whether that figure includes Saif al-Din Khader.
Multiple FBI sources told Reuters on Saturday that Khader was arrested in Jordan on September 28. Journalists and researchers had earlier named him as a key figure in the group. According to those anonymous sources, he has allegedly agreed to help the FBI and other agencies find other members.
The FBI and the Dutch National Police also publicly announced the arrest of Pepijn van der Stap, another alleged member. The Record gives no date for that arrest.
What the intruders took
ShinyHunters seized the FBIjobs.gov domain and defaced it. The Record says the group also exfiltrated large amounts of sensitive information about almost every FBI employee, but it gives no record count.
The group first advertised the intrusion by passing samples to news outlets. According to The Record, the samples were meant to prove it held details on agents: medical records, home addresses, phone numbers and the FBI areas where they work. The Record does not say it examined the samples itself.
Officers from local police departments who serve on joint task forces with the FBI were also caught up. MS NOW reported that thousands of records about these officers were exposed, without an exact figure.
Last week the FBI sent employees an internal memo about the breach. It warned of possible danger to staff and their families.
Reported cause: an unpatched system
Reuters, citing anonymous sources, reported that the FBI traced the breach to an unnamed Accenture contractor who failed to patch a vulnerable system. The contractor was dismissed this week, the same report said. These details come from unnamed sources and are not confirmed on the record.
The hackers have offered a different account. They previously claimed they got in through a flaw in Oracle software, one that cybersecurity experts highlighted in June, per a prior Record article. The coverage cites no CVE identifier.
What the group is saying
ShinyHunters told several news outlets in messages that it will not publish the stolen data and does not want the dispute with the FBI to escalate. It traced the conflict to an FBI advisory about its activity, IC3 PSA260515, which it disputes.
The Record reports that the FBI has dismantled much of the group's infrastructure over the past two weeks, and that law enforcement has frustrated attempts to bring its platforms back. The group returned to Telegram this week. On Friday morning it posted there that it would not stay long, saying "several of our members have reportedly been arrested by the FBI."




