After ShinyHunters claimed a breach against the FBI and defaced its website, a suspected member of the cybercrime gang was detained in Jordan.
In this episode of “What We Missed,” Dark Reading’s Rob Wright and Alex Culafi discuss some of the recent news events and topics that didn’t make it into the publication, starting with ShinyHunters‘ supposed breach against the FBI.
The group recently claimed, without evidence, that it obtained data belonging to nearly every FBI employee and job applicant. This purportedly happened as part of a breach of a third-party jobs portal used by the FBI, in which the gang vandalized the site and claimed to have stolen the aforementioned data.
Earlier this month, Jordanian authorities detained a suspected member of ShinyHunters; as first reported by Reuters, the alleged member is apparently cooperating with officials. The FBI has responded aggressively to this recent incident involving the bureau, cooperating with Dutch authorities to arrest another suspected member of the gang last month.
ShinyHunters, a loose collective of financially motivated threat actors, has claimed a swath of attacks in recent months against entities including ReliaQuest, Instructure, and even fellow threat group Cl0p.
Also discussed on this episode: Hackers gained access to a reportedly unencrypted Defense Manpower Data Center file-sharing system for roughly nine months, from October 2025 until this past July 16, exposing Pentagon records on nearly 2.8 million living people and 294,000 deceased people tied to the US military; and the Dutch Institute for Vulnerability Disclosure (DIVD) disclosed a hack involving several unidentified zero-day vulnerabilities.
For all of our Dark Reading news videos, please check out our YouTube channel and our curated video articles.
What We Missed With Rob Wright & Alex Culafi: Full Transcript
This transcript has been edited for clarity and length by Informa TechTarget’s internal AI assistant. For the full experience, please watch the video.
Dark Reading’s Rob Wright: Hi, I’m Rob Wright with Dark Reading.
Dark Reading’s Alex Culafi: And I’m Alex Culafi with Dark Reading.
DR’s Rob Wright: And this is “What We Missed.” This is a discussion about some of the recent stories that we did not cover in the pages, pods, or videos of Dark Reading. And first up, Alex, our old friends at ShinyHunters, back again.
DR’s Alex Culafi: Yes.
DR’s Rob Wright: This is a big one. FBI versus ShinyHunters, back and forth. There’s a lot to cover here, so I’ll try to zoom through it as quickly as I can. But basically, ShinyHunters claimed to have breached the FBI. I believe the first report on this was from 404 Media. They contacted members of the media, including 404, saying they had breached the FBI and that they had obtained data on every single FBI employee, which is not great. And then the situation developed from there. More recently, there was allegedly a ShinyHunters hacker who was detained in Jordan, of all places. And according to Reuters, the first to report this, they’re cooperating with the FBI. And I believe there was another hacker that was also arrested recently that was connected to ShinyHunters, arrested by the Dutch National Police a couple of weeks ago. So, Alex, what do you think is going on here?
DR’s Alex Culafi: I think it’s interesting, and it seems like there’s some validity to the ShinyHunters claim. Data was accessed somewhere. There was that thing where it was one of the FBI sites that they put the Umbreon on it [a Pokemon and alias/symbol of the group member arrested by the Dutch].
DR’s Rob Wright: Yes. Mm-hmm.
DR’s Alex Culafi: It’s a little surprising to me that they’re going after the US government in this way because historically (and say what you want about the competency of certain members of this administration), it’s generally a bad idea. To target one of the most powerful governments on Earth if you are a financially motivated threat actor, especially if you want to keep making money and you want to stay free? So, OK, maybe you saw an opportunity for this target, but it also seems very ill-advised given how big our military and defense budget is. I don’t know. What do you think?
DR’s Rob Wright: Well, the coverage on this has been pretty interesting. I encourage people to check out 404’s coverage. I guess the motive here is that the ShinyHunters members were upset with the way they were being portrayed by the FBI. There was a recent FBI alert that alluded to them engaging in swatting and threats of physical violence, and contacting victims directly and harassing them. And apparently they took umbrage at that, which is neither here nor there. I don’t really care why they went after the FBI. I do think it’s interesting that they kind of turned around and said, “We’re not gonna release the data.”
I don’t know if you saw the FBI’s response to this. They put out a video where Brett Leatherman, assistant director of the FBI’s cyber division, basically said, “Hey, if you do this again, you’re gonna be in real trouble” in so many words — the video is really interesting, and I think on one hand it’s good that the authorities are taking a hard line and going after these guys. And I don’t know how they got this individual in Jordan so quickly. They must have been investigating this person for a while. It’s great that the Jordanian authorities are assisting. But I also kind of wonder: Is this going to be another case where these hackers know that if they, quote unquote, “cooperate,” they’re probably goget off easy and get a slap on the wrist and maybe even go work for the authorities? So, I’m hoping that is not the case, but I think that these guys, especially hackers associated with the Com, are operating in that way with that sort of confidence that they’re gonna get off.
DR’s Alex Culafi: And it also raises questions about the provenance of another breach that happened this month.
DR’s Rob Wright: Yep. Yes.
DR’s Alex Culafi: Rolling right into our next story. Hackers gained access to an unencrypted data center, which is spun up by the Pentagon. It’s a file-sharing system that unnamed threat actors had access to through a vulnerability for roughly nine months, from October 2025 until July 2026, when the vulnerability, which we don’t know the exact status of, was patched. It exposed records of nearly 2.8 million people living and nearly 300,000 deceased, all tied to the US military in varying degrees.
The exposed information varied, but included Social Security numbers, names, birth dates, contact information, race, sex, and military occupational information. The Pentagon says there’s no indication the information has been misused. They’re offering free credit monitoring. The officials have not publicly identified the attackers, and the thing that’s been coming out is that this data appears to have been unencrypted that they pulled off of the server, which is a really big red flag since this is something tied to the Pentagon and the federal government.
And the reason why I connected this to the FBI case, even though they haven’t been publicly connected, is I’m like, what if ShinyHunters attacked this data center too? And then these back-channel conversations that the FBI is having. They’re like, “We are gonna be chill about this. You need to do nothing with this data, or we will destroy you.” And that’s conspiracy thinking. That’s not official information, but it does make me wonder given how close these things happen together.
DR’s Rob Wright: Yeah, no, I had the same thought. I thought maybe this was connected to ShinyHunters or another Com-adjacent group. It definitely seems odd that this happened so close to the FBI breach and that it was also personal data or personnel data. The thing that really bugs me about this is credit monitoring. Are you serious with this? Are you serious with unencrypted data? Are we still doing this?
DR’s Alex Culafi: This is very 2006 of them.
DR’s Rob Wright: This is so bad. And this is not a third-party system. This is their environment. They should have known about this. They should have been better prepared. And they weren’t. And it’s a horrendous look for them. So regardless of who did it — the government, the Pentagon, Department of Defense, I’m not gonna call it the other thing — I just think it’s a horrible look. Egg on their face. Big time.
DR’s Alex Culafi: Then there’s one other question I have. This attack started October 2025. And I’m not saying like the old administration would have done this better or not. I have no idea when the vulnerability started and when a lot of this stuff started. But it does make me wonder about all the budgetary cuts that have happened to US cyber defense since the start of 2025.
DR’s Rob Wright: Yeah.
DR’s Alex Culafi: It does make me wonder how much of this can be tied up or possibly attributed. That’s speculation on my part.
DR’s Rob Wright: I know. And how can it not? All right. Lastly, we have an interesting story that did not get a lot of play from what I saw out there in the cyber sphere, the news sphere. But apparently the Dutch Institute for Vulnerability Disclosure (DIVD) was breached recently. They put out an interesting blog post about this that was actually pretty candid. It really went into detail about what happened, but basically, an agentic AI attack used two zero-days in a platform called Zammad, which I guess is an AI-powered support and help desk platform. So this agentic AI attack got in there, got some data, got some employee data from this organization, which DVID is a good organization that’s done a lot of interesting research over the years. And used these two zero-days, got in, stole some data. They’re still investigating. There are more updates coming, but what do you think, Alex? Sound a little familiar?
DR’s Alex Culafi: So, is this a case of rogue AI, or is this a case of threat actors abusing another platform?
DR’s Rob Wright: I think it’s unclear at this point, but yeah, you’re not off-base to ask that question because we keep seeing information about other OpenAI agents or Anthropic agents probing or trying to hack other websites.
DR’s Alex Culafi: Yeah. And there’s an article that I just wrote about why we should stop calling it “rogue AI,” so I need to correct myself. The thing I will say is, if it is a case of, let’s say, underscoped, overpermissioned AI causing nonsense, it is the responsibility of the organization that sells that AI to make good on it. And they’re the ones who, whichever way, should probably be held accountable. But I don’t know if this is one of those cases, so I even feel weird saying that.
DR’s Rob Wright: No, you’re right. And it could be a threat actor, but again, I don’t think you’re wrong to suggest that after seeing what we’ve seen with Hugging Face and with other agentic AI models escaping and doing things that they shouldn’t be doing out there, you know, in terms of vulnerability research, finding zero-days, finding information to meet their goals. So, it’s certainly a possibility.
DR’s Alex Culafi: I guess the thing that is probably true, independent of, let’s say, the origin and the intention behind this incident, is that as the agents get more capable, as the vulnerability-hunting gets more widespread, this is gonna be a thing that a lot of small, medium, and large organizations are gonna have to deal with that they wouldn’t have had to before, because we have all these very capable non-human identities causing mayhem. And I hope I hope everyone involved takes that seriously.
DR’s Rob Wright: No, I know what you mean. Yeah. It’s a brave new world, Alex.
DR’s Alex Culafi: Yeah, not so new though.
DR’s Rob Wright: Yeah, that’s true. Well, thank you for joining me on this episode of “What We Missed.” I appreciate the time, Alex.
DR’s Alex Culafi: Thanks, Rob.


