ShinyHunters Hacker Arrested, FBI Data Breach Under Investigation
Article Content
- •Saif al-Din Khader arrested in Jordan for ties to ShinyHunters.
- •FBI employee data breach involved sensitive information, including medical records.
- •Khader is cooperating with the FBI to identify other gang members.
Saif al-Din Khader, a 16-year-old linked to the ShinyHunters hacking group, was arrested in Jordan on September 29, 2026. He is reportedly cooperating with the FBI to identify other gang members following a significant breach of FBI employee data. Khader had previously admitted to being the technical operator for a group known as Scattered LAPSUS$ Hunters, which amalgamates several cybercrime groups. The breach involved the theft of sensitive information on FBI employees, including job assignments and medical records, and was acknowledged by the FBI in an internal memo. Following the breach, ShinyHunters threatened to release the data unless the FBI removed an advisory they disliked. However, they later claimed the hack was intended as a marketing campaign and stated they would not release the stolen data. The group's online communication channels have reportedly gone silent since Khader's arrest, indicating potential disruptions in their operations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Accenture in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What sensitive data was compromised?
Is the ShinyHunters group still operational?
What actions is the FBI taking?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…