# Brett Leatherman

Type: Person

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/brett-leatherman
Canonical HTML page: https://getcyberbrief.com/entity/brett-leatherman

## Timeline

- **2026-09-30**: FBI confirms aggressive investigation — An FBI spokesperson tells NPR the bureau is working around the clock to investigate the FBIJobs.gov cyber incident and is in regular communication with potentially impacted individuals.
- **2026-09-29**: FBI cyber chief issues public warning — Assistant Director Brett Leatherman posts a video directly addressing ShinyHunters, vowing to find group members and urging them to come forward while the choice remains theirs.
- **2026-09-25**: ShinyHunters defaces FBIJobs.gov — Late last week, ShinyHunters posts a defacement message on FBIJobs.gov claiming responsibility for stealing sensitive FBI employee data; the site is temporarily taken down.
- **2026-09-24**: FBIJobs.gov remains offline — The FBI jobs website was still down as of Thursday afternoon as the bureau worked with third-party providers to mitigate risk.
- **2026-09-23**: ShinyHunters claims FBIJobs.gov compromise — ShinyHunters claimed responsibility for breaching FBIJobs.gov and said it held very sensitive data on almost all FBI agents and job applicants.
- **2026-09-23**: FBI confirms investigation — The FBI confirmed it was investigating the claims and said the point of breach remained undetermined, whether a third-party provider or the FBI's enterprise.
- **2026-05**: FBI advisory characterizes ShinyHunters — The FBI issued an advisory describing ShinyHunters as threat actors who often use real or exaggerated claims of access to sensitive information to prompt payment and may falsely claim to have compromising information.

## Recent coverage (3 stories)

### FBI hunts ShinyHunters after FBIJobs.gov breach of employee data
2026-09-30 15:16:01 · Sentiment: Strongly negative · Impact: 8/10 · Sources: 2

The FBI's cyber division publicly vowed to hunt down ShinyHunters after the group defaced FBIJobs.gov and claimed to steal sensitive employment records. Security teams should watch how the bureau determines whether a third-party vendor or internal system was the initial access point.
Full story: https://getcyberbrief.com/story/fbi-shinyhunters-fbijobs-breach-employee-data

### ShinyHunters suspect held: 140+ breaches, $70M extortion
2026-09-30 00:36:55 · Sentiment: Neutral · Impact: 7/10 · Sources: 2

Dutch police have arrested the alleged leader of ShinyHunters, the extortion group behind 140+ breaches and at least $70 million in payments since 2025. The suspect, identified as Pepijn van der Stap, was working at a Dutch security firm and is now linked to two alleged murder plots. The arrest hands investigators a seized laptop likely to expose infrastructure, affiliates, and additional victims.
Full story: https://getcyberbrief.com/story/shinyhunters-alleged-leader-arrest-netherlands-cyber

### ShinyHunters Claims Data on 1,000s of FBI Agents and Applicants
2026-09-25 00:08:24 · Sentiment: Strongly negative · Impact: 9/10 · Sources: 2

The cybercrime group ShinyHunters claims it compromised FBIJobs.gov and stole sensitive personally identifiable information on thousands of agents and applicants. The FBI says the breach point is undetermined and is investigating. Security leaders should treat the claim as unverified but operationally significant.
Full story: https://getcyberbrief.com/story/shinyhunters-fbijobs-breach-claim

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.