FBI Vows to Pursue ShinyHunters Hackers After Federal Personnel Data Theft
The bureau's public statement signals a shift toward naming and pressuring cybercriminal groups operating from foreign jurisdictions, though the legal path to prosecution remains constrained by...
The Federal Bureau of Investigation pledged Tuesday to continue pursuing the hacking group known as ShinyHunters following a theft of federal personnel data, with a senior FBI cyber official delivering a direct warning to the group in a publicly released video statement.
Brett Leatherman, identified by the New York Times as a senior cyber official at the FBI, said in the video statement: "We know how to find you." The statement was released Tuesday, September 29, 2026.
ShinyHunters is a cybercriminal group that has previously been linked to large-scale data breaches targeting both private companies and government systems. The group has been the subject of prior law enforcement actions in multiple countries. In 2022, French national Sebastien Raoult, identified by the U.S. Department of Justice as a ShinyHunters member, was extradited from Morocco to the United States and later pleaded guilty to wire fraud and aggravated identity theft in the Western District of Washington, according to DOJ records.
The specific federal personnel data involved in the theft referenced in Leatherman's Tuesday statement has not been fully detailed in publicly available records as of the publication of this article. The FBI has not released a formal criminal complaint or indictment in connection with this specific incident in publicly searchable federal court dockets as of September 29, 2026. What records would clarify the scope include any unsealed indictment filed in a U.S. District court and any official FBI or Cybersecurity and Infrastructure Security Agency (CISA) incident report made public.
Federal personnel data has been a recurring target for both nation-state actors and criminal groups. The most widely documented prior incident was the 2015 breach of the Office of Personnel Management (OPM), which the OPM Inspector General and congressional oversight committees attributed to a foreign state actor and which compromised records for approximately 21.5 million current and former federal employees and contractors, according to OPM's own report to Congress.
The FBI's decision to release a direct video statement naming the group reflects a tactic the bureau and the Department of Justice have used with increasing regularity since at least 2014, when the DOJ unsealed an indictment against five members of a Chinese military unit for economic cyber espionage, according to DOJ records. Security researchers and government officials have described this approach as intended to impose reputational and legal costs on hacking groups even when physical arrest is not immediately possible.
The Netherlands connection referenced in the Times headline is consistent with prior reporting that at least some individuals associated with ShinyHunters have operated from or through European jurisdictions. Extradition from the Netherlands to the United States is governed by the 1980 Netherlands-U.S. Extradition Treaty, which covers computer fraud offenses included under U.S. Federal statute 18 U.S.C. 1030, the Computer Fraud and Abuse Act. Whether any specific individual has been identified and is subject to an extradition request in this case is not confirmed by any publicly available court or State Department record as of this writing.
Congressional oversight of federal cybersecurity falls primarily under the Senate Committee on Homeland Security and Governmental Affairs and the House Committee on Homeland Security. Neither committee had released a public statement specific to this incident as of September 29, 2026, according to a review of both committees' official press release archives.
Federal agencies are required under the Federal Information Security Modernization Act (FISMA) to report significant cybersecurity incidents to CISA and to Congress. Whether a FISMA report has been filed in connection with this personnel data theft is not publicly confirmed. A FISMA incident report, a CISA advisory, or a congressional notification letter would be the documents most likely to detail the scope of the breach, the number of records affected, and the specific agencies involved.
What remains unknown includes the total number of federal employees or contractors whose data was accessed, the specific federal agency or agencies whose personnel records were involved, whether charges have been filed under seal in any U.S. District court, and whether a formal extradition request has been transmitted to the Netherlands or any other government. Public disclosure of any unsealed indictment through PACER, the federal court records system, would be the primary mechanism by which those facts would become available.