Intelligence. Accountability. Analysis.
Est. 2022 · Washington, D.C.
The Congressional Times
★★★
We follow the data, not the narrative
◆ Live Intelligence
Loading...
Analysis Loading today's analysis...
Politics

FBI Vows to Pursue ShinyHunters Hackers After Federal Personnel Data Theft

FBI Vows to Pursue ShinyHunters Hackers After Federal Personnel Data Theft

The bureau's public statement signals a shift toward naming and pressuring cybercriminal groups operating from foreign jurisdictions, though the legal path to prosecution remains constrained by...

Gab-E Intelligence Platform · September 29, 2026

The Federal Bureau of Investigation pledged Tuesday to continue pursuing the hacking group known as ShinyHunters following a theft of federal personnel data, with a senior FBI cyber official delivering a direct warning to the group in a publicly released video statement.

Brett Leatherman, identified by the New York Times as a senior cyber official at the FBI, said in the video statement: "We know how to find you." The statement was released Tuesday, September 29, 2026.

ShinyHunters is a cybercriminal group that has previously been linked to large-scale data breaches targeting both private companies and government systems. The group has been the subject of prior law enforcement actions in multiple countries. In 2022, French national Sebastien Raoult, identified by the U.S. Department of Justice as a ShinyHunters member, was extradited from Morocco to the United States and later pleaded guilty to wire fraud and aggravated identity theft in the Western District of Washington, according to DOJ records.

The specific federal personnel data involved in the theft referenced in Leatherman's Tuesday statement has not been fully detailed in publicly available records as of the publication of this article. The FBI has not released a formal criminal complaint or indictment in connection with this specific incident in publicly searchable federal court dockets as of September 29, 2026. What records would clarify the scope include any unsealed indictment filed in a U.S. District court and any official FBI or Cybersecurity and Infrastructure Security Agency (CISA) incident report made public.

Federal personnel data has been a recurring target for both nation-state actors and criminal groups. The most widely documented prior incident was the 2015 breach of the Office of Personnel Management (OPM), which the OPM Inspector General and congressional oversight committees attributed to a foreign state actor and which compromised records for approximately 21.5 million current and former federal employees and contractors, according to OPM's own report to Congress.

The FBI's decision to release a direct video statement naming the group reflects a tactic the bureau and the Department of Justice have used with increasing regularity since at least 2014, when the DOJ unsealed an indictment against five members of a Chinese military unit for economic cyber espionage, according to DOJ records. Security researchers and government officials have described this approach as intended to impose reputational and legal costs on hacking groups even when physical arrest is not immediately possible.

The Netherlands connection referenced in the Times headline is consistent with prior reporting that at least some individuals associated with ShinyHunters have operated from or through European jurisdictions. Extradition from the Netherlands to the United States is governed by the 1980 Netherlands-U.S. Extradition Treaty, which covers computer fraud offenses included under U.S. Federal statute 18 U.S.C. 1030, the Computer Fraud and Abuse Act. Whether any specific individual has been identified and is subject to an extradition request in this case is not confirmed by any publicly available court or State Department record as of this writing.

Congressional oversight of federal cybersecurity falls primarily under the Senate Committee on Homeland Security and Governmental Affairs and the House Committee on Homeland Security. Neither committee had released a public statement specific to this incident as of September 29, 2026, according to a review of both committees' official press release archives.

Federal agencies are required under the Federal Information Security Modernization Act (FISMA) to report significant cybersecurity incidents to CISA and to Congress. Whether a FISMA report has been filed in connection with this personnel data theft is not publicly confirmed. A FISMA incident report, a CISA advisory, or a congressional notification letter would be the documents most likely to detail the scope of the breach, the number of records affected, and the specific agencies involved.

What remains unknown includes the total number of federal employees or contractors whose data was accessed, the specific federal agency or agencies whose personnel records were involved, whether charges have been filed under seal in any U.S. District court, and whether a formal extradition request has been transmitted to the Netherlands or any other government. Public disclosure of any unsealed indictment through PACER, the federal court records system, would be the primary mechanism by which those facts would become available.

Today's Analysis
Loading...
★
Latest Intelligence
Congressional Intelligence
Loading...
★
Financial Intelligence
Loading...
★
Geopolitical Intelligence
Loading...
★
Follow the MoneyGab-E Political Intelligence Investigation
Loading...
Opinion & Analysis
Loading...
Archive
Loading...
About
Our Mission

We Follow the Data, Not the Narrative

The Congressional Times exists because public records are public — and the analysis built from them should not be exclusive to those who can afford $60,000-a-year intelligence subscriptions.

Every story published in The Congressional Times is sourced to a verifiable public record: a court filing, a Senate lobbying disclosure, an FEC contribution record, a USASpending contract, or a verified news report. We state our sources inline. We show our math. When we are wrong, we say so publicly.

We do not editorialize in news coverage. We do not use loaded language. Both political parties are held to identical standards.

The Follow the Money investigations are the heart of this publication. Each begins with Gab-E Political Intelligence running against 10+ million government records before a single word of editorial is written.

Powered by Gab-E, an elite global intelligence platform built to democratize political and financial intelligence.

Editorial Policy
Editorial Standards & Corrections Policy

How We Source, Verify, and Correct Our Work

Every factual claim in a Congressional Times story is checked against a primary source: a government filing, a court record, a direct quote, before publication. When a claim can't be verified or doesn't hold up as originally reported, we drop it or reframe it. We do not publish disputed claims as settled fact.

When we get it wrong: we correct the story directly, note the correction and date at the bottom of the piece, and update the record. We do not quietly edit and move on.

Bylines: stories with a named byline are written and fact-checked by that person. Stories without a byline are sourced from Gab-E Political Intelligence, our automated research platform, and are labeled as such.

Ownership: The Congressional Times is published by Gab-E Holdings LLC. Gab-E, our intelligence platform, powers our sourcing and research pipeline.

Corrections or concerns: support@gab-e.com