FBI Arrests Second Suspect Linked to ShinyHunters Hack of Its Own Jobs Portal
The extortion crew claims it stole data on nearly every FBI agent and applicant. A second arrest suggests investigators are working their way up the chain.

Key points
- FBI Director Kash Patel said on October 9 that agents arrested a second suspected co-conspirator of ShinyHunters, the extortion group that claimed in September to have stolen data on almost every FBI agent and job applicant from the bureau's careers website.
- The suspect has not been named, and no charging documents have been made public.
- Threat Vectr has published 33 stories on ShinyHunters, 25 of them in the past 90 days.
- The group is an extortion crew: criminals who steal data and demand payment to keep it offline, not a ransomware gang that locks files.
The FBI has arrested a second person it believes helped run ShinyHunters, the online extortion crew that said in September it had broken into the bureau's own jobs website and taken records on nearly every FBI agent and applicant.
FBI Director Kash Patel announced the arrest on 9 October in a post on X. He didn't name the suspect. No charges have been made public.
That's almost all we officially know. But the shape of the case is worth sitting with.
Who are ShinyHunters?
ShinyHunters is a long-running criminal group that steals large databases and then tries to sell them, or extort the victim into paying to keep the data quiet. They're not a ransomware gang. Ransomware, the kind of attack that scrambles a hospital's files until someone pays, is a different business. ShinyHunters deal in stolen data.
In September they claimed their boldest target yet: the FBI's careers portal, where people apply to work for the bureau. They said they'd taken sensitive information on nearly every current agent and nearly every applicant. The FBI hasn't confirmed the scope of that claim.
We first covered the group's breach claim on 28 September in "ShinyHunters Claims FBI Hack Exploiting Oracle Flaw", and on 4 October reported that Jordan detained an alleged member known as 'Rey' who is reportedly cooperating with U.S. Investigators.
How active is the group right now?
Active enough to keep posting while federal agents are picking off its members. Our 33 stories on ShinyHunters, 25 filed in the past 90 days, reflect a crew that has kept up a steady pace of claimed victims well into this investigation. These are claims, not confirmations. Criminals re-list old breaches and inflate numbers. But the volume tells you the group isn't lying low.
What should ordinary people do?
If you've ever applied for a job at the FBI, assume your application details may be in criminal hands, and treat any email claiming to be from the bureau about your application with suspicion. Phishing, where criminals send fake messages to lure you into typing a password or clicking a hostile link, tends to follow breaches like this within weeks.
For everyone else, the practical advice is unchanged. Turn on two-step login wherever your bank and email accounts offer it. Don't reuse passwords. If a breach notice arrives, read it.
My read
Two arrests in a few weeks, as first reported by The Hacker News, is unusual pace for a case this quiet. Patel isn't naming the suspects, which is standard when cooperators are being flipped. Our 7 October story on the Oracle PeopleSoft flaw tying the group's activity together suggests the technical thread is already well-documented. The thing to watch is whether the next announcement names a charge rather than a body, because that's when we find out how far up the group the bureau has actually got, and whether the September breach of its own jobs portal was really as bad as ShinyHunters claimed.



