The FBI has arrested multiple suspects tied to a September hacking operation that targeted the bureau itself, allegedly perpetrated by the notorious hacking group known as ShinyHunters.
The Register reports that an FBI spokesperson stated, “The bureau continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects and we will spare no resource in bringing each of the responsible individuals to justice.”
Breitbart News previously reported on the hack of the FBI which ShinyHunters took credit for:
“We hacked the FBI. We hold data on all FBI employees and applicants,” a representative for the group told 404 Media. The claim came alongside the defacement of apply.fbijobs.gov on Tuesday, which a representative said was carried out Monday night. The FBI jobs site and its Special Agent Applicant Portal were listed as “currently unavailable” at the time of writing, with the site itself displaying the message: “Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable.”
The defacement message was styled after a law enforcement seizure notice. It read “this site has been seized by ShinyHunters,” then claimed a far broader compromise than the website alone: “All FBI data was compromised including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.”
The FBI declined to comment on specific arrests, including that of a suspect identified as Saif al-Din Khader. Khader, who reportedly goes by the alias “Rey,” was detained in Jordan on September 29, according to Reuters. He is reportedly cooperating with the FBI to help identify other members of the group.
Khader confirmed his real identity to security journalist Brian Krebs last year. Krebs described him as the “technical operator and public face” of a related group. Security researcher Kevin Beaumont, commenting after news of the arrest broke, said, “Rey got picked up finally.” Beaumont also tied the suspect to the breach of Jaguar Land Rover, calling him “one of the kids who got into JLR.”
That breach hit JLR’s systems in late August 2025. It halted manufacturing, knocked out dealer systems, and led to canceled or delayed supplier orders. Attackers also stole personal payroll data belonging to thousands of JLR employees. People have called it one of the most costly cyberattacks in UK history, and it’s been attributed to ShinyHunters and related groups.
Khader’s detention came roughly two weeks after Dutch National Police arrested a 24-year-old whom the FBI described as “one of the alleged leaders of ShinyHunters.” Dutch police haven’t officially named the suspect, but Krebs and other reports identify him as Pepijn van der Stap. Van der Stap was convicted in 2023 for hacking and extorting numerous organizations and was on supervised release after serving three years in prison. He’d been working as a software engineer at Hadrian, an Amsterdam-based cybersecurity startup, and volunteered as a security researcher with the Dutch Institute for Vulnerability Disclosure.
Brett Leatherman, assistant director of the FBI’s Cyber Division, released a video message last week aimed at “remaining members” of ShinyHunters. “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left,” he said. “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.” The FBI declined to answer further questions about the video, including whether any infrastructure had been seized or whether group members had made contact.
Read more at the Register here.
Lucas Nolan is a reporter for Breitbart News covering issues of AI, free speech, and online censorship.

