buildOne report1 publisher FBI and Justice Department investigators seized seven domains that China-linked Flax Typhoon used to scan and in some cases infiltrate critical infrastructure. The risk remains, and with no patch to install, exposed operators have to hunt the group's tradecraft themselves.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence45
FBI Director Kash Patel says agents arrested another ShinyHunters suspect, at least the third detained in two weeks since the FBIjobs.gov breach. The group says it is leaving Telegram as members are arrested, and it has promised not to publish the FBI staff data it stole.
Perspective Coverage
11 publishers
- Builder
- Builder 15%
- Operator
- Operator 70%
- Investor
- Investor 15%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence58
Integrity Technology Group, a government-linked Chinese firm, enables China-linked hackers to breach US and foreign networks, ten agencies said. The advisory treats the firm and its crews as one set of actors, so a single hunt can span sectors.
Perspective Coverage
14 publishers
- Builder
- Builder 14%
- Operator
- Operator 72%
- Investor
- Investor 14%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+12
- Incentives60
- Confidence74
State Department offers $10 million for information on the whereabouts of Zhang Yu, a Shanghai company director charged in the Hafnium hacking campaign. The bounty keeps the US case against two named men moving years after June 2021, when the indictment says the charged intrusions ended.
Perspective Coverage
6 publishers
- Builder
- Builder 14%
- Operator
- Operator 81%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives55
- Confidence70
Alleged ShinyHunters member Saif al-Din Khader, detained in Jordan on Tuesday, is helping the FBI find other members, two sources told Reuters. A new ShinyHunters leak site went up two days later, suggesting other members still run the extortion.
Perspective Coverage
13 publishers
- Builder
- Builder 14%
- Operator
- Operator 74%
- Investor
- Investor 12%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence62
FBI said a contractor's failure to apply a security patch on a third-party platform let ShinyHunters steal personal details of thousands of bureau employees. The patch had already been issued, so the breach came down to one missed update on a platform the Bureau did not manage itself.
Perspective Coverage
11 publishers
- Builder
- Builder 24%
- Operator
- Operator 60%
- Investor
- Investor 16%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+20
- Incentives65
- Confidence66
FBI's Brett Leatherman urged ShinyHunters members to surrender after the Dutch arrest of an alleged leader of a group tied to $70 million in extortion. Dutch police have not ruled out more arrests, though the public record so far shows one suspect in custody.
Perspective Coverage
9 publishers
- Builder
- Builder 17%
- Operator
- Operator 68%
- Investor
- Investor 15%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+30
- Incentives60
- Confidence64
FBI told staff in an internal memo to assume hacking group ShinyHunters stole data on every employee after a claimed 2 to 3 terabyte breach of FBIjobs.gov. Until the bureau confirms the scale, staff and the job applicants the hackers say are also in the files have reason to treat their home addresses as exposed.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+15
- Incentives70
- Confidence40
Dutch police detained an alleged ShinyHunters leader on September 15, seven days before the group defaced the FBI's jobs website. The FBI says it is still chasing the rest of the group, so the vendor services and web portals it has used to get in remain the exposure to manage.
Perspective Coverage
3 publishers
- Builder
- Builder 13%
- Operator
- Operator 69%
- Investor
- Investor 18%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence58
ShinyHunters says it will never publish or sell the 2TB to 3TB of FBI data it claims to hold and calls its one-week ultimatum a marketing campaign. The pledge leaves standing its unverified claim that an Oracle PeopleSoft zero-day got it in.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+45
- Incentives70
- Confidence40
Ardit Kutleshi, 28, pleaded guilty to running Rydox, which sold U.S. victims' data and fraud tools from 2016 to 2024 for at least $232,000 in revenue. Spread across 7,600-plus sales, the operators averaged about $30 each for data that buyers keep after the site is seized.
Perspective Coverage
5 publishers
- Builder
- Builder 12%
- Operator
- Operator 75%
- Investor
- Investor 13%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence75
Justice says Chinese state operators laundered intrusions through infected routers and cameras in more than 130 countries since 2018. Source geography has been unreliable for years.
Perspective Coverage
7 publishers
- Builder
- Builder 32%
- Operator
- Operator 54%
- Investor
- Investor 14%
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap+18
- Incentives58
- Confidence64
The four-pillar document published September 9 promises dismantled infrastructure, seized cryptocurrency and faster victim notification, with no deadline or metric attached. For victims, the nearest-term change is who picks up the phone.
Reality
- Evidence60
- Adoption30
- Hype gap+35
- Incentives55
- Confidence65
Two years of extradition work and a guilty plea produced a four-year sentence for one Conti developer, measured against a group that hit more than 1,000 organizations and reappeared under new names.
Perspective Coverage
5 publishers
- Builder
- Builder 20%
- Operator
- Operator 68%
- Investor
- Investor 12%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence75
The FBI says it is investigating unauthorized activity affecting FBIjobs.gov. 404 Media reports the intruders came in through an Oracle PeopleSoft applicant server and then reached a government cloud holding agent data.
Perspective Coverage
4 publishers
- Builder
- Builder 19%
- Operator
- Operator 69%
- Investor
- Investor 12%
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+35
- Incentives75
- Confidence60
The extortion crew defaced apply.fbijobs.gov on September 22 and told reporters it got remote code execution from a new Oracle PeopleSoft flaw, the same one it says it is now using against Fortune 500 targets. No technical details are public.
Perspective Coverage
14 publishers
- Builder
- Builder 20%
- Operator
- Operator 67%
- Investor
- Investor 13%
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+40
- Incentives75
- Confidence60
The bureau has not confirmed a breach and says it cannot yet tell whether its own systems or a third-party provider were the way in, while Reuters and 404 Media report that sample records match real personnel.
Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 63%
- Investor
- Investor 15%
Reality
- Evidence55
- Adoption45
- Hype gap+30
- Incentives80
- Confidence60
The Justice Department sentenced Oleksii Lytvynenko to four years over Conti, the ransomware the FBI ties to more than $150m in victim payouts as of January 2022 and to attacks in 47 states. Four others stand charged in the same district.
Reality
- Evidence64
- Adoption58
- Hype gap+28
- Incentives74
- Confidence66
Seizure warrants across 2025 and 2026 reached domains, servers and one hosted IP rather than a fixed set of wallets. That moves the detection burden from screening known addresses toward spotting the channel that mints new ones.
Reality
- Evidence56
- Adoption68
- Hype gap+14
- Incentives72
- Confidence54