Full Report
The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almost all FBI agents and job applicants. The FBI has not named the suspect, and no charges have been made public. The
Analysis Summary
# Incident Report: Breach of FBIjobs.gov by ShinyHunters
## Executive Summary
In September 2026, the extortion group "ShinyHunters" successfully breached the FBI's jobs portal (FBIjobs.gov), exfiltrating sensitive personal, medical, and professional data belonging to thousands of FBI agents and job applicants. The breach was attributed to a failed security patch on a platform managed by a third-party contractor. As of October 9, 2026, the FBI has arrested three suspected co-conspirators in a global law enforcement effort spanning the Netherlands, Jordan, and the United States.
## Incident Details
- **Discovery Date:** Late September 2026
- **Incident Date:** September 2026 (Ongoing activity through October)
- **Affected Organization:** Federal Bureau of Investigation (FBI)
- **Sector:** Government / Law Enforcement
- **Geography:** United States (Attacker reach: Global)
## Timeline of Events
### Initial Access
- **Date/Time:** September 2026
- **Vector:** Exploitation of an unpatched vulnerability.
- **Details:** Attackers targeted a platform managed by an outside contractor that facilitated the FBIjobs.gov portal.
### Lateral Movement
- **Details:** The attackers moved from the third-party managed platform into the database containing agent and applicant records.
### Data Exfiltration/Impact
- **Details:** ShinyHunters claimed to have stolen data on "almost all" FBI agents and applicants. A sample analysis confirmed the theft of PII, sensitive job role details, and psychiatric/medical information.
### Detection & Response
- **How it was discovered:** Public announcement by ShinyHunters on September 22, 2026; subsequent internal FBI verification.
- **Response actions taken:** Collaboration with international partners (Dutch Police, Jordanian authorities) to track and arrest key members.
## Attack Methodology
- **Initial Access:** Exploitation of unpatched software (Security failure on a third-party platform).
- **Persistence:** Not explicitly disclosed (Likely via compromised contractor credentials or backdoors).
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Not disclosed.
- **Discovery:** Target identification of FBIjobs.gov portal.
- **Lateral Movement:** Pivot from contractor-managed environment to sensitive FBI data stores.
- **Collection:** Gathering of agent dossiers, medical records, and application data.
- **Exfiltration:** Data posted/advertised on extortion forums.
- **Impact:** Data breach and reputational damage.
## Impact Assessment
- **Financial:** Significant costs associated with global investigation, forensics, and potential identity protection for thousands of employees.
- **Data Breach:** High-volume theft of PII, including medical and psychiatric evaluations of federal agents.
- **Operational:** Disruption to FBI recruitment and potential compromise of undercover/sensitive roles.
- **Reputational:** High; a high-profile breach of a premier law enforcement agency's infrastructure.
## Indicators of Compromise
- **Network indicators:** FBIjobs[.]gov (Targeted domain)
- **File indicators:** Not disclosed in public reports.
- **Behavioral indicators:** Unusual data transfer volumes from contractor-managed portals; unauthorized access to medical record databases.
## Response Actions
- **Containment measures:** Review of third-party contractor security protocols.
- **Eradication steps:** Deployment of missing security patches.
- **Recovery actions:** Global law enforcement operations resulting in the arrest of:
1. Pepijn van der Stap (Netherlands, Sept 15)
2. Saif al-Din Khader (Jordan, Sept 29)
3. Unnamed Canadian Citizen (Pennsylvania, Oct 9)
## Lessons Learned
- **Key takeaways:** Third-party vendors and contractors remain the "weakest link" in government cybersecurity.
- **What could have been done better:** Stricter enforcement of Patch Management Service Level Agreements (SLAs) for contractors handling sensitive government data.
## Recommendations
- **Prevention measures:** Implement a Zero Trust architecture for all third-party integrations. Require mandatory, automated vulnerability scanning and immediate patching for all internet-facing platforms managed by contractors. Perform regular third-party risk assessments (TPRM).