The FBI has arrested multiple suspects linked to a September cyberattack by the ShinyHunters group that targeted the bureau itself and claimed stolen employee data.
Federal investigators say they have already taken several people into custody in connection with the alleged breach, working with overseas partners as the probe continues. The operation hit at a moment when the same crew was also tied to a major corporate attack that halted production at a major automaker.
Breitbart News reported that the FBI moved on suspects connected to the September hacking activity attributed to ShinyHunters, the group that publicly claimed it had compromised bureau systems and held sensitive records on employees and applicants.
An FBI spokesperson framed the response in blunt terms.
"The bureau continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects and we will spare no resource in bringing each of the responsible individuals to justice."
That statement puts the arrests in the center of a wider push against a hacking outfit known for high-profile claims and real-world damage. The bureau declined to discuss specific cases in detail, including one overseas detention.
One of the key names in the case is Saif al-Din Khader, who used the alias “Rey.” Reuters reported he was detained in Jordan on September 29.
Security journalist Brian Krebs has described Khader as the “technical operator and public face” of a related group. Khader confirmed his real identity to Krebs last year. Reporting now says he is cooperating with the FBI to help identify other members.
Security researcher Kevin Beaumont reacted after news of the arrest broke, writing that “Rey got picked up finally” and calling him “one of the kids who got into JLR.” That short comment linked Khader to the Jaguar Land Rover breach that hit systems in late August 2025.
The FBI would not comment on Khader’s detention specifically. Still, the sequence is clear enough: a public-facing operator gets scooped up abroad, then starts talking while agents keep hunting the rest of the crew.
Roughly two weeks before Khader’s detention in Jordan, Dutch National Police arrested a 24-year-old man the FBI has described as “one of the alleged leaders of ShinyHunters.”
Krebs and other reports identified that suspect as Pepijn van der Stap. Dutch authorities have not officially named him. Van der Stap had been working as a software engineer at Hadrian, an Amsterdam-based cybersecurity startup, and had volunteered as a security researcher with the Dutch Institute for Vulnerability Disclosure.
His record is not clean. He was convicted in 2023 for hacking and extorting numerous organizations, served three years, and was on supervised release when the new arrest came. The pattern is familiar: someone with deep technical skill, prior time for cybercrime, and a day job on the defensive side of the industry ends up back in handcuffs over offensive work.
That mix of white-hat credentials and black-hat history is exactly why these cases matter to taxpayers and companies. Skills that should protect systems get turned against them, and the bill lands on workers, suppliers, and customers.
Before the arrests piled up, a representative for ShinyHunters took credit for hitting the bureau. The claim came with a defacement of the FBI jobs site and Special Agent Applicant Portal at apply.fbijobs.gov. The sites were listed as “currently unavailable.”
A group representative told 404 Media the crew had pulled off the hack. The defacement message was styled like a seizure notice and read that “this site has been seized by ShinyHunters.” The same message pushed a broader data claim.
"We hacked the FBI. We hold data on all FBI employees and applicants,"
The notice went further, asserting that “All FBI data was compromised including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.”
The group said the defacement happened Monday night, with the public claim landing Tuesday. The FBI has treated the episode as an alleged incident under active investigation. It has not publicly confirmed that employee or applicant personal data was actually taken in the way the hackers described.
That gap matters. Hackers thrive on spectacle. Law enforcement has to sort theater from theft. Multiple arrests signal agents are not treating the claims as empty noise.
The same ecosystem of actors was blamed for the late August 2025 breach at Jaguar Land Rover. That attack halted manufacturing, knocked out dealer systems, canceled or delayed supplier orders, and led to the theft of personal payroll data for thousands of employees.
Reporting has described the JLR hit as among the most costly cyberattacks in UK history. When a carmaker’s production lines stop and payroll files walk out the door, the damage is not abstract. Workers wait. Dealers scramble. Suppliers eat delays. Taxpayers and customers eventually feel the cost one way or another.
Beaumont’s comment tying “Rey” to the JLR intrusion is one of the threads pulling the FBI case and the corporate breach into the same picture. ShinyHunters and related groups got the attribution. Khader’s detention and the Dutch arrest of an alleged leader now put real names and real custody next to those claims.
Last week, Brett Leatherman, assistant director of the FBI’s Cyber Division, released a video message aimed at remaining members of ShinyHunters. The tone was direct.
"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left,"
He continued with a clear warning.
"The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."
The FBI declined further questions about the video, including whether any infrastructure had actually been seized or whether any remaining members had made contact. The message still does the job: arrests change incentives, and silence gets harder the longer the manhunt runs.
Exact charges, full identities of every arrestee, and a complete count of suspects remain undisclosed in public reporting so far. The bureau has said only that it worked with partners to arrest multiple subjects and will keep pressing.
What is already on the table is enough to show a working model. International partners lock up a public operator in Jordan. Dutch police grab a 24-year-old alleged leader with a prior extortion conviction. A cyber division chief goes on camera and tells the rest of the crew the window to surrender on their own terms is closing.
Cybercriminals who treat federal systems and major manufacturers as soft targets count on distance, aliases, and the slow grind of cross-border cases. Arrests in more than one country, plus active cooperation from at least one detained operator, punch holes in that bet.
Americans who fill out federal job applications, draw a paycheck at a plant, or simply expect basic security from institutions that hold their data have a right to see this kind of pressure applied. Hackers who brag about seizing FBI portals and vacuuming employee files should meet the same standard of accountability as any other crook who steals and disrupts for sport or profit.
When federal agents and foreign partners put names in cuffs and invite the rest to come in first, the message is simple: the internet is not a free-fire zone, and the people who treat it that way can be found.