Skip to content
ShinyHunters Hackers Arrested After FBI Data Breach

ShinyHunters Hackers Arrested After FBI Data Breach

First seen 9 Oct 2026, 17:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 18:40 UTC
  • •ShinyHunters exploited a critical vulnerability in Oracle's PeopleSoft software.
  • •The breach exposed sensitive data of FBI employees, including medical and personal information.
  • •Multiple arrests have been made, including a teenager in Jordan and a Canadian national in Pennsylvania.

The FBI has arrested multiple suspected members of the ShinyHunters hacking group following a significant breach of its jobs portal, which exposed sensitive data of FBI employees. The group exploited a vulnerability (CVE-2026-35273) in Oracle's PeopleSoft software to gain access to the FBI's systems, reportedly stealing between 2TB and 3TB of data. Arrests include a teenager from Jordan, Saif al-Din Khader, who is cooperating with authorities, and a Canadian citizen detained in Pennsylvania. The breach has raised serious concerns about the security of personal information, including medical records and addresses of FBI personnel. The FBI has attributed the breach to a contractor's failure to apply a necessary security patch. ShinyHunters has claimed responsibility for the attack and has threatened to publish the stolen data, although they later stated they would not escalate the situation with the FBI. The FBI continues to investigate and dismantle the group's operations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-11
CVE-2026-35273 published
Oracle's PeopleSoft vulnerability was disclosed, with a CVSS score of 9.8, leading to active exploitation.
Krebsonsecurity
2026-09-15
Dutch police arrest Pepijn van der Stap
A 24-year-old Dutch hacker was arrested, suspected of aiding ShinyHunters in multiple breaches.
Bleepingcomputer
2026-09-28
Saif al-Din Khader arrested in Jordan
The teenager was detained and is reportedly cooperating with the FBI to identify other members of ShinyHunters.
Govinfosecurity
2026-10-06
FBI confirms contractor failure led to breach
The FBI stated that a contractor's failure to apply a security patch resulted in the breach of its jobs portal.
Nbcnews
2026-10-09
FBI arrests another ShinyHunters member
A Canadian citizen was arrested in Pennsylvania, marking the latest action against the ShinyHunters group.
Nextgov

More articles in this cluster (9)

Following this threat?

Track ShinyHunters, FBI and CVE-2026-35273 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What data was compromised in the breach?
The breach exposed sensitive information including addresses, Social Security numbers, and medical records of FBI employees.
How did the hackers gain access to FBI systems?
The hackers exploited a critical vulnerability in Oracle's PeopleSoft software, allowing them to breach the FBI's jobs portal.
What actions is the FBI taking in response?
The FBI is actively arresting suspected members of ShinyHunters and investigating the breach, including addressing contractor failures.