THE FBI GOT HACKED, AND HONESTLY, SAME: A CYBER SHADE SPECTACULAR
October 2026 — The week America's premier law enforcement agency had to Google "how to recover from embarrassment"
The organization that hunts hackers for a living just became the world's most ironic data breach victim. ShinyHunters — a cybercrime collective so brazen they described hacking the FBI as a marketing campaign — waltzed through a jobs portal, helped themselves to 60,000 employees' most sensitive records, and then had the audacity to not even ask for money. Meanwhile, one of their own is now singing to the feds in Jordan. This is the story of the most chaotic week in federal cybersecurity history, served with a side of institutional shade.
The Breach That Broke the Bureau
Let's set the scene. ShinyHunters, the same crew that has been robbing corporate America blind since 2019, spotted an Oracle PeopleSoft vulnerability in the FBI's jobs portal — FBIJobs.gov — and decided to treat it like an open buffet.
What they walked out with reads less like a data breach and more like a dossier on the entire federal law enforcement apparatus:
- Full names, addresses, badge numbers, and phone numbers of agents
- Blood and urine test results from fitness-for-work medical exams — yes, including notes about shellfish allergies and high cholesterol
- Psychiatric records of bureau personnel
- Details of a previously secret FBI hacking unit — the Remote Operations Unit — whose existence was barely known publicly
- Intelligence on agents working Russia, China, and drug cartel cases
- Records on ~60,000 current and former FBI staff — the group initially thought it was 38,000, then realized it had underestimated its own heist
Internal memos advised FBI staff to assume all employees may have been compromised. Every. Single. One.
Professor Ciaran Martin, former head of the UK's National Cyber Security Centre, called it "as serious as it gets when it comes to data breaches."
"Passwords can be reset if stolen, but medical records cannot — so once this data is out, it stays compromised for good." — Etay Maor, Cato Networks
The Audacity: "It's Just Marketing"
Here's where it gets genuinely unhinged. ShinyHunters issued a statement clarifying they never intended to sell the data.
Their demand? A retraction of an FBI advisory published in May that they felt "offended" them.
That's right. They didn't want Bitcoin. They didn't want a wire transfer to a Cayman account. They wanted the FBI — the Federal Bureau of Investigation — to say sorry.
The FBI's response, via Assistant Director Brett Leatherman in a social media video, was the federal equivalent of a mic drop:
"You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."
The FBI is now investigating whether the breach came through third-party software or its own internal systems. Officials and commentators have been less diplomatic, with one word appearing repeatedly in coverage: "incompetence."
Rey Gets Caught — Then Switches Teams
The plot thickened dramatically on September 29, 2026, when Jordanian authorities detained Saif al-Din Khader, known online as "Rey" or "ReyXBF" — a key administrator of ShinyHunters and one of three top figures in the broader Scattered LAPSUS$ Hunters (SLH) supergroup.
Here's the kicker: Rey is now helping the FBI hunt his own crew.
Sources told Reuters that Khader is allowing investigators to examine his devices and digital correspondence, and that "his cooperation is critical to ongoing efforts to arrest these hackers."
This isn't entirely surprising — Khader had reportedly been cooperating with law enforcement since at least June 2025, according to independent journalist Brian Krebs. He's also a former administrator of BreachForums and the Hellcat ransomware data leak site. The man has more cybercrime rรฉsumรฉ lines than most people have LinkedIn endorsements.
His arrest follows another bust the previous week: Pepijn van der Stap, a 24-year-old Amsterdam man and offensive security lead at a Dutch firm, was arrested for involvement in ShinyHunters operations. The group denied knowing him. Sure.
Who Exactly Is Scattered LAPSUS$ Hunters?
To understand the full scope of the chaos, you need to know what ShinyHunters has become. This isn't your 2020 database-theft crew anymore.
In 2025, three of cybercrime's most notorious brands merged into a single supergroup:
| Group | Specialty | Role in SLH |
|---|---|---|
| ShinyHunters | Mass data theft, SaaS extortion | Core engine, brand operator |
| Scattered Spider | Voice phishing, SIM-swapping, identity abuse | Initial access specialist |
| LAPSUS$ | Social engineering, insider recruitment, spectacle | Cultural DNA + chaos fuel |
Together, they became Scattered LAPSUS$ Hunters — a modular, distributed cybercrime franchise that operates more like a dark web McKinsey than a traditional hacking gang.
Their 2025–2026 greatest hits include:
- A Salesforce OAuth-token compromise hitting 39 companies including Google, Cisco, FedEx, and Disney — nearly 1 billion records allegedly stolen
- The Canvas education platform breach, disrupting US schools nationwide
- A Carhartt hack in mid-August 2026 leaking ~50GB of data on nearly 13 million customers — now the subject of a class-action lawsuit
- And, of course, the FBI itself
Why Arresting Them Is Like Playing Whack-a-Mole in the Dark
The day after Rey's detention, a brand new dark web data leak site went live under the ShinyHunters brand. The group didn't skip a beat.
This is the defining feature of SLH's architecture: it's modular by design. Individual arrests don't kill the operation — they just reshuffle the org chart. When Telegram banned their main channel, backup channels appeared within days. When BreachForums was seized, successor sites emerged. When one member flips, the rest keep moving.
The real defense burden, experts note, falls not on law enforcement catching hackers after the fact — but on organizations hardening their identity and SaaS layers before the phone call comes.
Because with SLH, the attack often starts with a voice. A fake IT support call. A consent screen. An OAuth token. No malware. No implants. Just a very convincing person on the phone asking you to click approve.
The Damage Ledger (So Far, This Year)
| Target | What Happened | Scale |
|---|---|---|
| FBI (FBIJobs.gov) | PII, medical, psychiatric records stolen via Oracle PeopleSoft vuln | ~60,000 current & former staff |
| Carhartt | Data breach → class-action lawsuit | ~13 million customers, ~50GB |
| Canvas / Instructure | Education platform breach, school disruptions | Up to 275M records claimed |
| Salesforce ecosystem | OAuth-token vishing campaign | 39 companies, ~1B records claimed |
The Takeaway
ShinyHunters hacking the FBI is the cybersecurity equivalent of a pickpocket robbing a police precinct — and then leaving a note saying they did it for brand awareness. The arrest of Rey in Jordan is a real win for law enforcement, and his cooperation could unravel significant threads of the SLH network.
But the new leak site that appeared hours after his detention tells the real story: the brand is bigger than any one member. The FBI is hunting them. Kash Patel has promised "no safe haven." And somewhere, a ShinyHunters Telegram channel is probably already posting a meme about it.
The most dangerous hackers in 2026 don't need zero-days. They need a phone, a convincing accent, and an enterprise that hasn't trained its help desk. That's the actual vulnerability — and no arrest in Jordan fixes it.
Sources: BBC News, NPR, Cybernews, The Hacker News, MSNBC, HackRead, Reuters, The New York Times, BleepingComputer, Top Class Actions
Sources & Links
Here's a full reference list for every source cited in the article, organized by outlet.
๐ด Primary News Coverage
BBC News — Special agents' blood and urine test results stolen in FBI hack https://www.bbc.com/news/articles/cw62me2vlj07o
NPR — FBI hunting the hackers who stole its employees' sensitive data https://www.npr.org/2026/09/30/nx-s1-5985202/fbi-hack-shinyhunters
MSNBC / MS Now — 'Incompetence': Massive FBI hack hit most employees and extends to local officials https://www.ms.now/news/fbi-hack-shinyhunters-breach-data
๐ต Cybersecurity & Tech Press
Cybernews — ShinyHunters hacker detained in Jordan – now he's helping FBI hunt down his own crew https://cybernews.com/news/shinyhunters-hacker-detained-in-jordan-fbi/
The Hacker News — ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members https://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html
HackRead — ShinyHunters FBI breach & Oracle PeopleSoft vulnerability details https://hackread.com
BleepingComputer — ShinyHunters ongoing activity, new dark web leak site, corporate campaigns https://www.bleepingcomputer.com
⚖️ Legal & Consumer
- Top Class Actions — Carhartt class-action lawsuit following ShinyHunters breach https://topclassactions.com
๐ฐ General & Investigative
The New York Times — ShinyHunters communications & breach statement analysis https://www.nytimes.com
Reuters (via Investing.com) — Rey detention and cooperation reporting https://www.investing.com
GV Wire — ShinyHunters corporate & academic hacking campaigns, Canvas breach https://gvwire.com
๐️ Official Government
FBI Official Statement — FBI statement on compromise of FBIJobs.gov portal https://www.fbi.gov/news/press-releases/fbi-statement-on-compromise-of-fbijobsgov-portal-and-alleged-impact-to-fbi-employee-pii
FBI Cyber Division — Official FBI cyber investigations page https://www.fbi.gov/investigate/cyber
All links verified as of October 4, 2026. Some outlet homepages are listed where specific article URLs were not provided in the original source material.

