News

FBI Arrests ShinyHunters Suspect in Pennsylvania — and Patel Says More Raids Are Coming

A Canadian citizen is in custody in Pennsylvania, the alleged Dutch ringleader is sitting in a Rotterdam cell, and a third suspect is reportedly cooperating with investigators from Jordan. Three weeks after the most humiliating hack in recent FBI history, the bureau's counterattack is moving fast — and Director Kash Patel wants the world to watch.

Advertisement
FBI Director Kash Patel with President Donald Trump at a White House press conference
FBI Director Kash Patel (left, with President Donald Trump) announced Friday that agents had arrested another suspected ShinyHunters member — the latest strike since the group breached the FBI's own jobs portal. Photo: The White House / Molly Riley / Wikimedia Commons (public domain)

FBI arrests ShinyHunters suspect

FBI arrests ShinyHunters suspect: FBI Director Kash Patel announced Friday that agents arrested another suspected member of the ShinyHunters cyber-extortion group earlier this week — the latest strike in a rapidly expanding international crackdown that began when the hackers humiliated the bureau by breaking into its own jobs portal last month and stealing the personal data of thousands of current and former agents. The New York Times first reported that the suspect is a Canadian citizen taken into custody in Pennsylvania; two sources familiar with the matter told CNN the man is believed to have helped orchestrate the hack. The FBI has not named him, described the charges, or said what role he allegedly played.

Patel announced the arrest in a post on X, writing that "our agents in the field have arrested another suspected co-conspirator of the ShinyHunters group," which he said was believed responsible for the break-in at FBIJobs.gov — a platform he noted was managed by a third-party vendor. "This is the latest arrest this FBI has made in a matter of days involving this network," Patel wrote, "as we work non-stop to dismantle the group, pursue new leads and evidence, and act quickly." An investigation into other people believed involved is ongoing, the sources told CNN, and the FBI declined to provide additional details.

What Patel announced Friday

The announcement was characteristically Patel: fast, public, and short on particulars. The arrest itself happened "earlier this week," meaning agents had the suspect in custody for days before the director went public — a gap that suggests investigators used the interval to exploit whatever devices, accounts, or cooperation the arrest produced before the target's associates knew he was gone. That is standard tradecraft in a conspiracy case, and it is also the point: Patel's message was aimed as much at the hackers still at large as at the public.

What we know is limited but specific. The suspect is a Canadian citizen, arrested on U.S. soil in Pennsylvania — which means extradition, the usual chokepoint in international cyber cases, is not an issue here. He was taken by FBI field agents, not a foreign partner. And he is described by two separate outlets' sourcing as a co-conspirator or orchestrator-level figure, not a peripheral money mule. What we do not know — the name, the charges, the precise role — is presumably being held for an indictment or a cooperation deal. In federal cyber prosecutions, silence about the charges usually means one of two things: the paperwork is still being finalized, or the defendant is already talking.

FBI Director Kash Patel at the White House
FBI Director Kash Patel. He announced the arrest on X without naming the suspect or describing the charges. Photo: The White House / Molly Riley / Wikimedia Commons (public domain)

The hackers who hacked the FBI

To understand why this arrest matters, you have to sit with the absurdity of the underlying crime. Last month, ShinyHunters — a cyber-extortion crew the FBI now calls "a global cybercrime and threat actor group linked to cyberattacks in the United States, the Netherlands, and around the world" — claimed it had broken into FBIJobs.gov, the bureau's own employment portal, and walked out with the personal data of thousands of current and former FBI employees. According to sources who reviewed the stolen data, it identified personnel working in sensitive units focused on China and Russia. An internal FBI memo, reported by Reuters, operated on the assumption that all current and former employees had been exposed. The group even supplied reporters with an apparent sample of roughly 5,000 entries — names, home addresses, phone numbers, information about relatives.

Then came the insult on top of the injury. ShinyHunters used its dark-web leak site to demand that the FBI amend a previous advisory the bureau had issued about the group — the hackers said they were "offended" by how the agency had described their extortion tactics. Read that again: a criminal crew that had just looted the FBI's personnel files was publicly grading the FBI's homework about them. Many in the cybersecurity industry read the demand as a tacit threat to leak the stolen data; the hackers later claimed leaking it was never their intention. Some bureau employees, CNN previously reported, felt underwhelmed by the security resources the FBI offered its own victims. The whole episode was, by any measure, one of the most serious breaches of the bureau's data in years — and a personal embarrassment for a director who had staked his tenure on restoring the FBI's fearsome reputation.

Amsterdam, Amman, Pennsylvania: the net tightens

Friday's arrest is the third visible move in a counteroffensive that has unfolded with unusual speed. On September 29, Patel announced that Dutch National Police had arrested "one of the alleged leaders" of ShinyHunters. Dutch police said the suspect, a 24-year-old man, had actually been detained two weeks earlier, on September 15, in a raid dramatic enough to involve flash-bang grenades. Reuters reported, via a former employer, that the man is Pepijn van der Stap, an offensive-security lead at an Amsterdam cybersecurity firm — a detail that, if true, means one of the alleged kingpins of a global extortion ring was employed to do legal hacking by day. (ShinyHunters has denied van der Stap is associated with the group, and Dutch authorities have not publicly named him.) The Dutch suspect is also wanted in a separate investigation over allegedly attempting to arrange two murders, and a Rotterdam court has ordered him held for another 90 days.

Then came the quieter, potentially more important development: Reuters reported that a suspected ShinyHunters member, Saif al-Din Khader, had been detained in Jordan and was cooperating with investigators — helping the FBI and other agencies locate fellow hackers. A cooperating insider changes the geometry of a conspiracy case entirely. Every chat log, every wallet address, every alias the cooperators can map becomes a lead, and "pursue new leads and evidence" — Patel's phrase Friday — reads in that light like a progress report rather than a platitude.

Now Pennsylvania. Three jurisdictions, three suspects, roughly 24 days from the Dutch detention to this week's arrest. For an international cyber investigation — a category famous for moving at glacial speed while suspects hop between non-extradition countries — that tempo is startling. It suggests the FBI entered this fight with more intelligence than it let on, and that the ShinyHunters network is considerably more mapped than its members believed.

Why this matters

This is not just another cybercrime bust, and the reason is the victim. When hackers breach a hospital chain or a pipeline operator, the FBI investigates from a position of institutional distance. Here the bureau is the victim, the investigator, and the press office all at once — and that triple role is exactly what makes the response so politically loaded. A slow or fruitless investigation would have confirmed every critic's claim that the FBI under Patel is better at social-media combat than at actual law enforcement. A fast, multinational string of arrests does the opposite: it converts the bureau's worst embarrassment of the year into a demonstration project.

Patel clearly understands the stakes, which is why every development arrives as a public announcement rather than a quiet court filing. The X posts, the "we work non-stop" language, the direct warnings to remaining members to turn themselves in — this is deterrence theater, and it is aimed at an audience of young hackers watching to see whether hitting the FBI carries a cost. The answer Patel is constructing, arrest by arrest, is that it carries the highest cost of all: the full weight of American law enforcement plus its Dutch and Jordanian partners, moving in weeks rather than years.

There is a subtler significance too. The ShinyHunters case is a live test of whether the FBI's post-breach playbook — assume total exposure, hunt the crew publicly, squeeze the network through cooperators — actually works against a modern, distributed extortion group. If the Pennsylvania suspect flips the way the Jordan detainee reportedly has, prosecutors could end up with the rarest thing in cybercrime: a complete organizational chart, from leadership to infrastructure to money flows. That would be worth more than any single conviction.

What the numbers actually say

140+. The number of organizations ShinyHunters and its alleged co-conspirators have breached since last year, according to FBI cyber chief Brett Leatherman — a pace of roughly one victim every two to three days.

$70 million. The minimum the group has collected in extortion payments over that period, per the FBI. For context, that is more than many Fortune 500 companies spend annually on cybersecurity — extracted by a crew whose alleged leader was 24 years old.

Thousands. The current and former FBI employees whose personal data was exposed in the FBIJobs.gov breach, with a 5,000-record sample circulated to reporters. The exposure of China- and Russia-focused personnel is the kind of counterintelligence damage that takes years to fully assess.

3. The suspected ShinyHunters figures now in custody or cooperating across three countries — the Netherlands, Jordan, and the United States — within about three weeks of the Dutch raid.

90 days. The additional detention a Rotterdam court ordered for the alleged Dutch leader, giving investigators a long runway to work through his devices and associates.

Zero. The number of suspects publicly named by the FBI so far — a reminder that this is still the evidence-gathering phase, and that the bureau is protecting its cooperators and its case.

Hooded hacker silhouette against binary code
ShinyHunters has breached more than 140 organizations and collected at least $70 million in extortion payments since last year, the FBI says. Photo: David Whelan / Wikimedia Commons (CC0)

Who wins, who loses

Winners: Kash Patel and the FBI's cyber division. Every arrest is a proof point for a director whose tenure has been defined by controversy — loyalty-test allegations, the Epstein files fight, the Charlie Kirk investigation missteps. A multinational takedown of the crew that hacked the bureau is the strongest possible rebuttal, delivered in the language Patel speaks best: results, announced loudly.

Winners: the 140+ victim organizations. Deterrence is the only real remedy in cybercrime — stolen data cannot be un-stolen. A visible, fast-moving dragnet raises the perceived risk for every extortion crew weighing its next target.

Losers: the ShinyHunters network. A cooperating suspect in Jordan plus seized devices in the Netherlands plus a fresh arrest in Pennsylvania adds up to an intelligence picture that is likely far more complete than the remaining members realize. The group's dark-web bravado — grading the FBI's advisories — looks considerably less clever now.

Losers: the third-party vendor. Patel's careful note that the breach occurred "on a platform managed by a third-party vendor" points a finger that will not be withdrawn. Expect hard questions — from Congress, from the FBI's own inspectors, and from every federal agency using the same vendor — about how the bureau's front door was left open.

Losers: the agents whose data is already out there. This is the part no arrest can fix. Names, addresses, and family details of intelligence personnel do not become un-compromised when a hacker is handcuffed. The bureau's duty-of-care failure toward its own people — the underwhelming victim support CNN documented — remains the unresolved moral ledger of this whole affair.

What happens next

Watch for the indictment. The Pennsylvania suspect's name, charges, and alleged role will surface in court filings — and the charging document will reveal how much of the case rests on the Jordan cooperator, the Dutch seizure, or independent FBI work. If the charges include conspiracy counts reaching back to the FBIJobs.gov breach, it signals prosecutors believe they can tie this defendant directly to the bureau's humiliation.

Watch for the next arrest. Patel said the bureau is pursuing "new leads and evidence," and the tempo so far — three moves in 24 days — suggests the next one is already in motion. Cooperators produce cascades: each flipped suspect names two more. The question is whether the remaining leadership is in a cooperative jurisdiction or somewhere the FBI cannot reach.

Watch the vendor. The third-party platform behind FBIJobs.gov is about to become the most scrutinized federal contractor in America. A critical inspector-general report, a congressional hearing, or a contract cancellation would each be a logical next step — and each would ripple across every agency that outsources sensitive systems.

Watch the deterrence debate. If the dragnet keeps producing arrests, Patel will claim vindication for his loud, public style of law enforcement. If it stalls — or if a prosecution collapses over evidence problems — critics will say the announcements were the strategy rather than the result. Either way, the ShinyHunters case has become the defining test of whether the modern FBI can still do the thing it was built to do: find people who believed they could not be found, and prove them wrong in public.

Related coverage

Sources

Signal Post News · Published October 9, 2026Back to all stories
Topics#News#FBIArrests#ShinyHuntersSuspect#Pennsylvania

Disclosure: Signal Post News may earn a commission from qualifying purchases made through links on this page, at no extra cost to you. Learn more.

Advertisement
← Back to Signal Post News