FBI arrests key suspect in major hack of agents’ data
By Sean Lyngaas, Evan Perez, CNN
(CNN) — The FBI arrested a man in Pennsylvania who officials believe helped orchestrate a recent damaging hack that exposed sensitive data of current and former FBI personnel, according to two sources familiar with the matter.
FBI Director Kash Patel announced the arrest on Friday but did not disclose where it occurred or what role the man is suspected of playing in the hack.
“Earlier this week, our agents in the field arrested another suspected co-conspirator” of the cybercriminal group believed to be responsible for the hack, Patel said on Friday.
An investigation is ongoing into other people believed to be involved in the hack, the sources said.
Last week, the FBI announced that Dutch authorities arrested “one of the alleged leaders” of the criminal group, known as ShinyHunters.
The New York Times first reported on the arrest of the man in Pennsylvania.
The FBI declined to provide additional details to CNN.
The forceful FBI response comes after one of the most serious breaches of the bureau’s data in years. ShinyHunters last month claimed responsibility for breaking into an FBI jobs portal and gaining access to the personal data on thousands of current and former FBI employees. The identities of FBI personnel working in sensitive units on China and Russia were exposed, according to sources who have seen the data.
ShinyHunters used their dark-web site to demand that the FBI amend a previous advisory issued about the group, before the hack, saying it was “offended” over how the agency described its alleged tactics for extorting victim organizations. Many in the cybersecurity industry took the demand as a tacit threat that ShinyHunters would leak the stolen data. The hackers later claimed that was never their intention.
Some FBI employees felt underwhelmed by the security resources being offered to victims of the breach, CNN previously reported.
Amid the internal criticism and media scrutiny, Patel and a senior FBI cyber official, Brett Leatherman, put out a series of public statements and video messages with updates on the investigation. Some were addressed to the cybercriminals.
“Arrests have a way of changing who is willing to talk and seized infrastructure has a way of showing us who is left,” Leatherman said in a video posted after the arrest by Dutch authorities. “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
There has also been an inquest at the FBI over how such a critical security lapse happened. The FBI determined that a contractor managing the bureau’s jobs portal failed to update software “explicitly issued to secure the platform,” Leatherman said last week. The FBI has “removed the contractor,” he said.
The software in question is a human-resources platform made by Oracle, ShinyHunters has said. The hackers previously used a flaw in the software to attack targets in the education sector in May and June, according to Google’s Threat Intelligence Group. But months later, the FBI contractor apparently still had not applied a security patch that was available for the software.
The-CNN-Wire
™ & © 2026 Cable News Network, Inc., a Warner Bros. Discovery Company. All rights reserved.
