// 2 ZERO-DAY · 6 CVE · 8 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
The FBI arrested a Canadian citizen in Pennsylvania on October 9, 2026, identifying them as a primary co-conspirator in the ShinyHunters intrusion of FBIJobs.gov. The arrest follows the detention of Saif al-Din Khader ("Rey") in Jordan and Pepijn van der Stap in the Netherlands, marking three apprehensions across three continents in under two weeks. The breach exploited an unpatched Oracle PeopleSoft vulnerability (CVE-2026-35273) on a third-party vendor platform. The FBI says ShinyHunters has extorted over $70 million from more than 140 organizations since 2025.

The FBI arrested a Canadian citizen in Pennsylvania on October 9, 2026, identifying them as a primary co-conspirator in the intrusion of FBIJobs.gov attributed to the ShinyHunters group. The capture follows those of Saif al-Din Khader, known as "Rey," detained in Jordan in late September, and Pepijn van der Stap, 24, arrested in the Netherlands. In less than two weeks, authorities have stopped three figures linked to the group across three continents.

Key Takeaways
  • The FBI arrested a Canadian citizen in Pennsylvania as a primary co-conspirator in the FBIJobs.gov breach; authorities have not disclosed the name
  • Saif al-Din Khader ("Rey"), 16, is detained in Jordan and is cooperating with the FBI; the precise extent of cooperation is unknown
  • Pepijn van der Stap, 24, was arrested in the Netherlands; the ShinyHunters group denied his involvement
  • The intrusion was caused by a known vulnerability in Oracle PeopleSoft (CVE-2026-35273) left unpatched by a contractor, who was subsequently removed
  • According to the FBI, ShinyHunters has extorted over $70 million from more than 140 organizations since 2025

The Chain of International Arrests

FBI Director Kash Patel announced the Canadian citizen's arrest in a statement on X, describing the individual as "another suspected co-conspirator" linked to the incident that occurred "on a platform managed by a third-party vendor." The New York Times, citing "two people familiar with the matter," confirmed the suspect is considered a primary co-conspirator in the intrusion.

The capture fits into an accelerated sequence. Rey was detained in Jordan in late September: The Record indicates September 28, other sources September 29. The brief flags the discrepancy as minor; the exact date does not alter the substance of the investigative coordination. Van der Stap was arrested in the Netherlands shortly before. The speed of operations suggests authorities were waiting for the opportune moment to strike in succession.

According to Reuters, citing "three people familiar with the matter," Rey's cooperation with the FBI is "critical to ongoing efforts to arrest these hackers." However, the precise extent of cooperation and how many members he has identified remain uncertain.

How They Got In: CVE-2026-35273 and the Vendor Failure

The FBIJobs.gov breach was caused by a vulnerability in Oracle PeopleSoft identified as CVE-2026-35273. Oracle released a patch; the contractor responsible for the platform did not apply it. The contractor has been removed.

Mandiant and Google Threat Intelligence Group confirmed the mass-exploitation pattern of this vulnerability. The brief mentions "WAF bypass" in SOURCE 10 but does not specify the technique used.

The FBI removed the contractor from management of the platform. According to Nextgov, a sample of exposed data contained over 5,000 records of federal personnel, including names, home addresses, phone numbers, close relatives, and roles in intelligence units. An internal agency memo, reported by BleepingComputer and the New York Times, established that the FBI operates on the assumption that all employees have been compromised.

"Our agents in the field have arrested another suspected co-conspirator of the ShinyHunters group – the group believed to be responsible for the recent incident, which occurred on a platform managed by a third-party vendor." — Kash Patel, FBI Director

The Stolen Data and the Political Claim

ShinyHunters claimed to have exfiltrated 2-3 TB of data from FBIJobs.gov. The files included, according to the group's claim, home addresses, Social Security numbers, sensitive job assignments, as well as medical and psychiatric records of FBI employees.

The group asserted the attack was not financially motivated but represented a response to an FBI advisory from May 2026. This statement, reported by Malwarebytes and The Hacker News, is not independently confirmed. The dossier does not rule out concurrent financial objectives in other group operations.

The data has not been published or sold, at least publicly. The group declared it does not intend to release the information, but the risk of disclosure remains. The brief places in UNKNOWN/LIMITS the question of whether the data was shared with foreign intelligence services.

Different Profiles, Same Network

The arrest of van der Stap, 24, and the detention of Rey, 16, show different age profiles and roles within the same network. According to investigative sources, van der Stap is contested by the group itself, which denied his involvement. Rey operationally controlled the group according to KrebsOnSecurity. The Canadian citizen's role is defined as "primary co-conspirator" by the New York Times, but is not necessarily that of a technical hacker.

Brett Leatherman, Assistant Director of the FBI Cyber Division, issued an appeal to other group members: "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."

"Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments." — Brett Leatherman, FBI Cyber Division

What Changes

The sequence of arrests does not allow conclusions about the current state of ShinyHunters' infrastructure or how many members remain active. The brief explicitly lists these elements as uncertain. Rey's cooperation could enable the FBI to identify other participants, but the exact number is unknown.

The name and specific identity of the arrested Canadian citizen have not been disclosed. The specific charge is unknown. It is unclear whether the suspect was extradited or arrested on a U.S. warrant.

For organizations using Oracle PeopleSoft, the source does not specify immediate actions beyond applying available patches. The brief does not report additional technical details on WAF configurations or cloud infrastructure.

Closing

The third arrest in twelve days confirms the intensification of the FBI investigation into ShinyHunters, but leaves open questions about the group's operational resilience. The fragmentation following the detention of Rey and van der Stap is not measurable with current data. Leatherman's appeal to other members remains an investigative opening, not a scenario confirmation.

Information is based on converging primary sources, with known limits: paywall on the New York Times, anonymous sources in some passages, name of the Canadian suspect not disclosed. The number of active ShinyHunters members and the state of its infrastructure remain uncertain.

Information has been verified against cited sources and updated at time of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. therecord.media
  3. krebsonsecurity.com
  4. malwarebytes.com
  5. thehackernews.com
  6. nytimes.com
  7. nextgov.com
  8. katv.com