LIVE · cybersecurity feed
Live wire
breach

FBI arrests another suspected ShinyHunters hacker after agency breach

The FBI has announced the arrest of another individual suspected of involvement with the ShinyHunters extortion group, believed to be responsible for a recent breach of the agency's systems. FBI Director Kash Patel confirmed the arrest on Friday, stating it was the latest in a series of actions aimed at dismantling the group.

ZeroDay News ·

Source: BleepingComputer

The FBI has announced the arrest of another individual suspected of involvement with the ShinyHunters extortion group, believed to be responsible for a recent breach of the agency's systems. FBI Director Kash Patel confirmed the arrest on Friday, stating it was the latest in a series of actions aimed at dismantling the group.

While Director Patel did not disclose the suspect's identity or the location of the arrest, reports indicate the individual is a Canadian citizen apprehended in Pennsylvania. This suspect is considered a primary co-conspirator in the intrusion.

The breach, which occurred last month, targeted the FBIJobs.gov platform, managed by a third-party vendor. ShinyHunters claimed in September to have exploited an alleged Oracle PeopleSoft zero-day vulnerability to gain access, subsequently moving laterally into FBI-managed AWS GovCloud infrastructure. The group asserted it stole between 2TB and 3TB of data, including information on current and former FBI employees, job applicants, medical and psychiatric records, and internal service records. Data samples shared with media outlets confirmed the exposure of sensitive employee information, such as home addresses, Social Security numbers, job assignments, and details about family members. An internal FBI memo reportedly indicated the agency assumed all employees were affected. The FBI has since stated the incident stemmed from the third-party contractor's failure to install a security update.

This arrest follows increased pressure from the FBI to identify and apprehend ShinyHunters members. On September 15, Dutch police arrested 24-year-old Pepijn van der Stap in Amsterdam in connection with the group. ShinyHunters, however, denied any association with van der Stap.

Following the Dutch arrest, the FBI issued an unusual public warning to ShinyHunters members, urging them to surrender. Brett Leatherman, Assistant Director of the FBI Cyber Division, stated that investigators were actively identifying individuals involved and that seized infrastructure would reveal remaining members.

Days later, a suspected ShinyHunters member known online as "Rey," identified as Saif al-Din Khader, was reportedly detained in Jordan and began cooperating with the FBI and international law enforcement. Around the same time, signs of disruption appeared within ShinyHunters, with the group's main representative, who had regularly communicated with reporters, ceasing responses on Telegram, and that account subsequently appearing to be deleted. Another alleged affiliate with knowledge of the FBI hack also shut down an online messaging account, and the group's data leak site went offline. A new ShinyHunters leak site later emerged, suggesting some members remained active. It is not clear if the disappearance of the main representative is linked to the recent arrests.

ShinyHunters is an extortion group known for stealing data from web applications and cloud-based SaaS platforms, then demanding ransom to prevent data leaks. The name has been associated with various threat actors since at least 2018, with increased activity in the past two years. Recent campaigns have targeted Salesforce and other cloud SaaS environments, with the group linked to breaches affecting companies such as Google, Cisco, PornHub, and Match Group.

The group has also engaged in voice phishing (vishing) campaigns targeting Okta, Microsoft, and Google single sign-on (SSO) accounts, impersonating IT support to trick employees into providing credentials and multi-factor authentication (MFA) codes. They have also used device code vishing attacks to steal Microsoft account authentication tokens, which are then used to access compromised SSO accounts and connected enterprise platforms like Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.

ShinyHunters was also behind a significant data theft attack on Instructure Canvas in May, which caused platform outages. Instructure later reached an "agreement" with the threat actors to prevent the publication of stolen data. Beyond conducting its own breaches, ShinyHunters has also operated as an extortion-as-a-service provider, assisting other threat actors in extorting compromised organizations. Law enforcement has made numerous arrests over the years in cases tied to the ShinyHunters name, including individuals connected to the Snowflake data theft attacks, breaches at PowerSchool, and the operation of the Breached v2 hacking forum. Despite these arrests, cybercriminals have continued to operate under the ShinyHunters name.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

FBI Arrests Founder of Ransomware Negotiation Firm

Federal agents have arrested a Canadian cybersecurity professional in Pennsylvania, linking him to an ongoing investigation into the ShinyHunters hacking group. Edward Dubrovsky, co-founder of the Canadian firm CyberSteward, was taken into custody on October 8, facing charges of conspiracy to threaten to impair the confidentiality of information with intent to extort money, and interference…

saashigh

ASOS Breach Reveals the Risks in Customer-Facing SaaS

A recent security incident involving the British online fashion retailer ASOS has brought to light the inherent risks associated with customer-facing Software-as-a-Service (SaaS) platforms. The breach reportedly showcased how the compromise of a single user identity could serve as an initial access vector, subsequently allowing attackers to achieve broad penetration into a company's internal…

patch

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

A new malvertising campaign, dubbed "Adception" by security researchers at Push Security, is leveraging Google Ads and Bing redirects to distribute fake Claude installers that deploy "ClickFix" attacks. The campaign was identified after researchers observed malicious Google ads targeting users searching for "claude mac."

cybersecurity

AI Fuels Cybersecurity Mergers and Acquisitions

The cybersecurity industry is currently undergoing a substantial wave of mergers and acquisitions (M&A), with 117 deals reported in the most recent quarter. A key driver behind this heightened activity appears to be the increasing integration of artificial intelligence (AI) across various sectors, leading to a broader range of companies seeking to acquire cybersecurity capabilities.

cloud

AWS AgentCore security undone by prompt requesting credentials

Researchers have identified a critical vulnerability in Amazon Bedrock AgentCore that could allow an attacker to compromise all agents within an AWS account and region by exploiting insufficient network isolation and overly permissive default IAM roles. The flaw, disclosed by Zenity Labs, centers on an attacker's ability to extract temporary AWS credentials from an agent through a single prompt.

security

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have reported an active credential-theft campaign leveraging GitHub Actions workflows, which has led to the compromise of tens of thousands of repositories. The campaign reportedly exploited two high-profile open-source maintainer accounts to propagate a malicious workflow into over 340 repositories directly. One notable instance involved the account of Takashi Kitao,…