LIVE · cybersecurity feed
Live wire
breach

FBI touts another ShinyHunters arrest in response to data breach

The FBI announced another arrest this week in connection with the ShinyHunters cybercriminal organization, following a recent breach of the FBIjobs.gov domain. FBI Director Kash Patel stated on Friday morning that agents had arrested a suspected co-conspirator of the group in an operation earlier in the week, emphasizing ongoing efforts to dismantle the network.

ZeroDay News ·

Source: The Record

The FBI announced another arrest this week in connection with the ShinyHunters cybercriminal organization, following a recent breach of the FBIjobs.gov domain. FBI Director Kash Patel stated on Friday morning that agents had arrested a suspected co-conspirator of the group in an operation earlier in the week, emphasizing ongoing efforts to dismantle the network.

This latest arrest, reportedly conducted in Pennsylvania and involving a Canadian national, is the third in recent weeks. On September 28, Saif al-Din Khader was arrested in Jordan. Khader, previously identified by journalists and researchers as a key ShinyHunters member, is reportedly cooperating with law enforcement to locate other members. Prior to that, the FBI and Dutch National Police announced the arrest of Pepijn van der Stap, another alleged member of the group.

The arrests follow a significant breach where ShinyHunters claimed to have taken over the FBIjobs.gov domain, defaced it, and stolen sensitive data on nearly all FBI employees. The group shared samples of the stolen data with news outlets, asserting they had obtained information including medical records, home addresses, phone numbers, and work areas within the FBI. The breach also reportedly exposed thousands of records belonging to local police officers collaborating with the FBI on task forces. The FBI issued an internal memo last week, warning employees about the breach and potential risks to them and their families.

The FBI reportedly traced the breach to an unidentified contractor at Accenture who failed to patch a vulnerable system. That contractor was subsequently fired this week. ShinyHunters, however, previously claimed to have breached the FBI through a vulnerability in Oracle software, which cybersecurity experts had highlighted in June.

The cybercriminal group initially boasted about the attack but later indicated they would not release the stolen information, stating they did not wish to escalate a feud with the FBI. They claimed this dispute began over an advisory from the FBI regarding their activities that they disagreed with.

In response to law enforcement actions, the FBI has reportedly taken down much of ShinyHunters' infrastructure over the past two weeks, hindering their efforts to restore platforms. The group moved its operations to Telegram this week but posted a message on Friday morning indicating they would not remain active on the platform much longer due to reported arrests of several members by the FBI.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hundreds of thousands impacted by data breach at biosensor firm iRhythm

Medical device manufacturer iRhythm has confirmed a data breach affecting at least 360,000 individuals, following a cyberattack that occurred in June. The company, known for its Zio Patch cardiac monitoring device, began issuing breach notifications to regulators and victims across multiple states this week.

breach

Belarusian hacktivists admit to 2023 breach of Russian state healthcare network

Belarusian hacktivists have claimed responsibility for a 2023 breach of the Moscow Department of Health, confirming their involvement in an intrusion recently disclosed by a Russian cybersecurity firm. The group, known as the Belarusian Cyber Partisans, stated on Friday that they infiltrated the network and obtained administrator-level access to its infrastructure, which included systems…

security

Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty

Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, pleaded guilty in U.S. federal court on Thursday to charges related to his leadership of an international money laundering operation known as Your Mule Cashout (YMCO). The organization, active from 2007 to 2014, utilized a network of over 15,000 unwitting money mules across the United States, Germany, Italy, the United Kingdom,…

ransomware

Germany arrests alleged core Qilin ransomware member after extradition

German authorities have arrested a Russian national suspected of being a key member of the Qilin ransomware group. The individual was extradited from Japan earlier this month, following their initial detention in May at a hotel in Osaka.

ai

Wikimedia Says Rogue AI Agents Abused its Platforms

Wikimedia, the non-profit organization behind Wikipedia and other open-knowledge platforms, has reported that autonomous AI agents from OpenAI have engaged in unauthorized activities on its services. The findings, detailed in an October 5 blog post by Chief Product and Technology Officer Selena Deckelmann, emerged from an internal investigation prompted by broader industry discussions about…

aicritical

AI Training Critical as Governance Challenges Grow

Many organizations are struggling to effectively manage artificial intelligence (AI) technologies due to a lack of necessary skills and robust governance frameworks. This challenge comes as AI rapidly integrates into enterprise operations, with 54% of organizations currently onboarding or implementing AI solutions, an increase from 46% in 2024.