Click here to sign up for our free daily newsletter.

FBI arrests Canadian in ShinyHunters hack of the bureau’s jobs portal

Oct 9, 2026 | 2:53 PM

OTTAWA — The RCMP says a Canadian has been arrested by the FBI in connection with an attack from a criminal hacking group which breached the bureau’s jobs portal and obtained sensitive and personal data on nearly all the FBI’s employees.

FBI Director Kash Patel confirmed on Friday the arrest of another co-conspirator in the ShinyHunters attack. He said the arrest had taken place earlier this week, related to a hack of FBIjobs.gov.

“This is the latest arrest this FBI has made in a matter of days involving this network, as we work non-stop to dismantle the group, pursue new leads and evidence, and act quickly,” Patel said. “This arrest demonstrates the strength and reach of our efforts to protect Americans from cybercrime. We will continue to work closely with our partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate.”

The arrest was the latest targeting ShinyHunters, the group that claimed responsibility for the hack, as the FBI continues a global investigation into the breach of its network, which Patel said “occurred on a platform managed by a third-party vendor.”

The identity of the person arrested was not immediately clear, nor what charges they might face. The FBI would provide no more details of the arrest.

RCMP spokesperson Ian Lordon said Friday “the RCMP is aware of the arrest of a Canadian in the U.S. in connection with the ShinyHunters hack,” but directed all further questions to the FBI.

“The RCMP does not comment on investigations being conducted by other countries,” Lordon said.

In a message taking responsibility for the hack and announcing the collection of sensitive information, ShinyHunters said it had taken action over false allegations contained in an FBI public advisory from May that described the organization as a “cyber criminal group specializing in large-scale data breaches and extortion.”

That advisory characterized ShinyHunters as “threat actors” who often “use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims,” commonly harass or threaten people and “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”

Experts said that although the data that appeared to be compromised was the type of personal information that is routinely accessed during a breach, the hack nonetheless had alarming national security implications given that it could expose agents and their families to extortion, swatting and other harassment and because the identities of spouses were also said to have been obtained.

This report by The Canadian Press was first published Oct. 9, 2026.

-With files from The Associated Press

The Canadian Press