Skip to content
feed: live
0dayNews
ransomware
● Breaking

FBI Arrests ShinyHunters Suspect in FBI Breach Case

FBI Director Kash Patel announced Oct. 9 the arrest of a ShinyHunters co-conspirator tied to the September breach of FBI systems.

FBI Arrests ShinyHunters Suspect in FBI Breach Case
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·1 min read

If your organization used a third-party ransomware recovery or negotiation firm in the past three years, that engagement needs a due-diligence review. FBI Director Kash Patel announced Friday the arrest of a ShinyHunters co-conspirator, and Krebs on Security reports the person is co-founder of a Canadian cybersecurity firm that operated in the ransomware recovery space. The firm has not been named in public charging documents.

What changed

FBI Director Patel announced the arrest on October 9 via X. The suspect is believed to be involved in ShinyHunters’ breach of FBI systems that the group claimed in September, BleepingComputer and The Hacker News confirmed.

This is the second ShinyHunters enforcement action this week. Saif al-Din Khader was detained in Jordan on October 6 and is cooperating with federal authorities.

The pattern DOJ is pursuing

The recovery-firm angle connects directly to last week’s MonsterCloud case. In that matter, prosecutors allege MonsterCloud CEO Zohar Pinhasi secretly paid ransomware operators while billing victims for proprietary recovery services. Two different firms, same alleged model: operate as a legitimate intermediary while routing money to the adversary. DOJ is now pursuing this on multiple tracks.

Priority action items

Check this first: If your organization paid a third-party ransomware recovery firm in any incident over the past three years, obtain written confirmation of how that firm handled payments. Specifically: did fees go to actual decryption key procurement, or were they marked as “proprietary recovery services” with no disclosed ransom payment? If you cannot get that documentation, brief your legal team now. DOJ cases have shown that victims in these arrangements face legal and regulatory exposure alongside the intermediaries.

Second priority: For any active or past ShinyHunters extortion contact, report to the FBI via ic3.gov without engaging a negotiation intermediary. Request that any incident response or negotiation firm disclose in writing whether they have ever made ransom payments on a client’s behalf before you engage them.

Deprioritize: The FBI breach specifics are not yet public. There is no defensive action to take against the ShinyHunters FBI intrusion until IOCs are published. Monitor CISA and FBI advisories and act when indicators are available.

Found this useful? Share it.