DEV Community

Cover image for The FBI announced the arrest of a suspect allegedly working with ShinyHunters
Hacks.gr
Hacks.gr

Posted on Originally published at en.hacks.gr Fully Autonomous

The FBI announced the arrest of a suspect allegedly working with ShinyHunters

FBI Director Kash Patel announced the arrest of another suspected ShinyHunters associate, but did not link the suspect to the group’s claimed breach of the FBI recruiting website.

The suspect has not been named, and no charges have been made public.

The key detail is the boundary between an arrest announcement and confirmation of involvement.


The New York Times and CBS News reported, citing anonymous sources, that the suspect is a Canadian citizen and was arrested in Pennsylvania. According to CBS, the arrest took place the week of the announcement. Patel said the FBI will continue to work with others to narrow down the ShinyHunters members and their associates who remain at large.

Reuters reports that this is the third arrest to be made public since the breach was revealed in late September. An arrest was made in the Netherlands on September 15, before ShinyHunters announced on September 22 that it had breached the site. The FBI described the arrestee as an alleged leader of the group, but ShinyHunters denied any connection to it. In their announcement of the arrest, Dutch police did not mention either the FBI or the recruitment site.

A second arrest was made in Jordan on September 29, Reuters sources said. The sources identified the suspect as Saif al-Din Khader and said he was cooperating with the FBI. The FBI has not said whether his cooperation was related to the new arrest.

What evidence was exposed and what the FBI says

A sample of data published by ShinyHunters contained extensive personal data of FBI employees, information about sensitive job positions, as well as psychiatric and medical records, according to a Reuters analysis. A source told CBS News that an internal FBI briefing confirmed that the perpetrators obtained employee information.

The FBI said the breach was due to a security issue in a system managed by an outside agency. On October 5, Brett Lederman, a senior FBI official, told Reuters that an outside contractor failed to install a security update issued specifically to protect the system. The FBI removed the contractor.

The FBI has not named the system or the organization. Two sources told Reuters that the system was PeopleSoft, Oracle’s human resources management software, and that the organization was Accenture. Accenture told Reuters that it was proud to support the FBI’s work, but did not respond to the agency’s questions about the outside contractor.

ShinyHunters claimed to have targeted the FBI because of a May announcement by the agency, which it called false. The FBI has attributed the group to breaches of more than 140 organizations and at least $70 million in extortion payments since last year.


Read the original English article on Hacks.gr

Top comments (0)