Back to Intelligence

FBI Arrests Negotiation Firm Co-Founder in ShinyHunters Probe: Third-Party IR Risk and Data Exfiltration Defense Guide

SA
Security Arsenal Team
October 10, 2026
11 min read

In my 15+ years running incident response engagements, I've told clients one uncomfortable truth more times than I can count: the moment you bring an external firm into a breach, you are extending your attack surface to include their people, their systems, and their integrity. This week's news makes that abstract risk brutally concrete.

The FBI on Thursday arrested the co-founder of a Canadian cybersecurity firm — a firm whose business model was negotiating with ransomware and data-extortion actors on behalf of victims — in connection with the investigation into the ShinyHunters hacking group. This is the same ShinyHunters operation that recently breached the FBI itself and exfiltrated sensitive data on thousands of federal agents, according to reporting by KrebsOnSecurity.

Let that sink in. An executive at a firm positioned inside the trust perimeter of active cyber incident response engagements is now accused of ties to one of the most prolific data-theft crews operating today. If your organization has ever engaged a breach coach, a negotiation firm, or an IR retainer provider, this story is about you.

Why This Matters to Every Defender

This incident sits at the intersection of three threats I see escalating in 2026:

  1. Insider threat within the incident response supply chain. Negotiation firms, IR consultants, and breach coaches receive extraordinary access: forensic images, victim impact assessments, cyber insurance policy limits, legal strategy, and often direct visibility into what data was stolen. A malicious insider in that position doesn't need to breach you — you handed them the keys.

  2. ShinyHunters' ongoing data-theft-and-extortion campaigns. Unlike encryption-first ransomware crews, ShinyHunters specializes in stealing data at scale and monetizing it through extortion and resale. Their 2025–2026 tradecraft has leaned heavily on social engineering — voice phishing (vishing) against help desks and employees, abuse of OAuth consent flows to plant malicious connected apps in SaaS tenants, and use of valid stolen credentials to walk through the front door of cloud environments.

  3. Data theft from law enforcement itself. If a group can exfiltrate sensitive personnel data on thousands of FBI agents, your organization's controls are not the benchmark. Assume determined social engineering will eventually succeed somewhere in your environment and design for containment, not just prevention.

Technical Analysis: The ShinyHunters Attack Chain

No CVE is associated with this story — because there doesn't need to be one. This is the defining lesson of the current extortion economy: the most damaging breaches of 2025 and 2026 have overwhelmingly abused identity, trust, and legitimate tooling rather than software vulnerabilities.

The attack pattern defenders should model against, based on ShinyHunters' documented tradecraft:

Stage 1 — Initial access via social engineering (MITRE T1656 / T1566). Operators call help desks or employees impersonating IT staff, often with detailed reconnaissance from LinkedIn and prior breach corpora. The objective is a password reset, MFA enrollment of an attacker-controlled device, or guiding the victim to authorize a malicious OAuth application (frequently disguised as a legitimate data utility).

Stage 2 — Persistence through valid accounts and OAuth grants (T1078, T1550, T1528). Rather than deploying malware that EDR will catch, the actor operates through legitimate SaaS sessions and consented API access. This is why traditional endpoint telemetry goes quiet during these intrusions — the action is in your identity provider and SaaS audit logs.

Stage 3 — Bulk collection and exfiltration (T1530, T1567.002). Data is pulled from cloud storage, CRM platforms, code repositories, and file shares — frequently using legitimate administrative tools such as rclone, MEGAcmd, or WinSCP scripted against attacker-controlled cloud storage. Volume is the tell: gigabytes to terabytes leaving in hours.

Stage 4 — Extortion (T1657). Victims are contacted with proof of theft. And this is precisely where a compromised negotiation firm becomes catastrophic: an insider advising both sides can steer victims toward paying, leak victim details to the crew, or monetize confidential engagement data.

Exploitation status: Confirmed active, in-the-wild campaign activity by a named threat actor with a successful breach of a federal law enforcement agency. This is not theoretical.

Detection & Response

The detections below target the observable behaviors in this attack chain: OAuth abuse, exfiltration tooling, bulk data staging, and insider-style bulk access to sensitive case data. Tune thresholds to your baselines — the goal is catching the pattern, not generating a flood.

YAML
---
title: Exfiltration Tool Execution with Cloud Storage Target
id: 4c8e2a71-3b5d-4f9e-a1c6-7d2e8f3b9a01
status: experimental
description: Detects execution of common dual-use data transfer tools with command lines consistent with bulk exfiltration to cloud storage, as observed in ShinyHunters-style data theft operations.
references:
  - https://attack.mitre.org/techniques/T1567/002/
  - https://krebsonsecurity.com/2026/10/fbi-arrests-founder-of-ransomware-negotiation-firm/
author: Security Arsenal
date: 2026/10/16
tags:
  - attack.exfiltration
  - attack.t1567.002
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\rclone.exe'
      - '\megacmd.exe'
      - '\MEGAclient.exe'
      - '\winscp.com'
      - '\winscp.exe'
      - '\filezilla.exe'
  selection_cli:
    CommandLine|contains:
      - 'copy '
      - 'sync '
      - 'move '
      - '/script='
      - 'put '
      - '--transfers'
      - '--config'
  condition: selection_img and selection_cli
falsepositives:
  - Legitimate backup administrators using rclone for sanctioned cloud backup
  - Managed file transfer workflows
level: high
---
title: Suspicious OAuth Application Consent Grant
id: 9f1d3c52-7e4a-4b8d-b2f5-1a9c6e3d7f02
status: experimental
description: Detects user consent grants to OAuth applications, a technique used in vishing-driven SaaS intrusions where victims are guided to authorize attacker-controlled connected apps for persistent data access.
references:
  - https://attack.mitre.org/techniques/T1528/
  - https://attack.mitre.org/techniques/T1656/
author: Security Arsenal
date: 2026/10/16
tags:
  - attack.persistence
  - attack.t1528
  - attack.credential_access
logsource:
  product: azure
  service: auditlogs
detection:
  selection:
    OperationName:
      - 'Consent to application'
      - 'Add OAuth2PermissionGrant'
      - 'Add app role assignment to service principal'
  condition: selection
falsepositives:
  - Normal business application onboarding; alert on grants to unapproved or newly registered publishers, especially with Mail.Read, Files.Read.All, or full_access scopes
level: medium
---
title: Tor Browser Execution on Corporate Endpoint
id: 2b7e5d14-8c3f-4a6e-91b2-5d8f3a6c9e04
status: experimental
description: Detects execution of the Tor Browser bundle on corporate endpoints. Extortion actors and complicit insiders use Tor for anonymized communication with criminal infrastructure and leak sites.
references:
  - https://attack.mitre.org/techniques/T1090/003/
  - https://attack.mitre.org/techniques/T1071/001/
author: Security Arsenal
date: 2026/10/16
tags:
  - attack.command_and_control
  - attack.t1090.003
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|contains:
      - '\Tor Browser\'
      - '\tor.exe'
    CommandLine|contains:
      - 'torrc'
      - 'SocksPort'
  condition: selection
falsepositives:
  - Rare legitimate privacy research; should be near-zero on standard corporate builds and investigated in every case
level: high
KQL — Microsoft Sentinel / Defender
// Hunt 1: Bulk file access/downloads by a single user in M365 (insider pattern —
// mirrors a negotiation-firm insider mass-accessing client case files)
let threshold = 500;
OfficeActivity
| where TimeGenerated > ago(24h)
| where OfficeWorkload in ("SharePoint", "OneDrive")
| where Operation in ("FileDownloaded", "FileSyncDownloadedFull", "FileAccessed")
| summarize FileOps = count(), DistinctFiles = dcount(OfficeObjectId), Sites = dcount(SiteUrl)
    by UserId, bin(TimeGenerated, 1h)
| where FileOps > threshold or DistinctFiles > 200
| project TimeGenerated, UserId, FileOps, DistinctFiles, Sites
| order by FileOps desc;

// Hunt 2: New OAuth consent grants to unverified publishers (vishing payload pattern)
AuditLogs
| where TimeGenerated > ago(14d)
| where OperationName in ("Consent to application", "Add OAuth2PermissionGrant")
| mv-expand TargetResources
| mv-expand TargetResources.modifiedProperties
| where tostring(TargetResources_modifiedProperties.displayName) has "Scope"
| extend Scopes = tostring(TargetResources_modifiedProperties.newValue)
| where Scopes has_any ("Mail.Read", "Files.Read.All", "full_access_as_app", "offline_access")
| project TimeGenerated, OperationName, InitiatedBy = tostring(parse_json(tostring(InitiatedBy.user)).userPrincipalName), AppName = tostring(TargetResources.displayName), Scopes;

// Hunt 3: Exfil tooling execution on endpoints (EDR telemetry)
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where FileName in~ ("rclone.exe", "megacmd.exe", "winscp.com", "winscp.exe", "filezilla.exe", "7z.exe", "rar.exe")
| where ProcessCommandLine has_any ("copy", "sync", "move", "/script=", " a ", "-m", "--transfers")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, FolderPath
| order by TimeGenerated desc
VQL — Velociraptor
// Hunt for exfiltration tooling artifacts: rclone configs, recent archives, and dual-use transfer binaries
SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)rclone|megacmd|winscp|filezilla'
   OR Exe =~ '(?i)rclone\.exe|megacmd|winscp\.(exe|com)'

// Enumerate rclone configuration files (attacker staging leaves these behind)
SELECT FullPath, Size, Mtime
FROM glob(globs='C:/Users/*/AppData/Roaming/rclone/rclone.conf')

// Find large recently-created archives in user-writable directories (staging for exfil)
SELECT FullPath, Size, Mtime
FROM glob(globs='C:/Users/*/**/*.{zip,7z,rar,tar.gz}')
WHERE Size > 100000000
  AND Mtime > now() - 86400*7
PowerShell
# Audit script: OAuth consent grants + unauthorized transfer tools + risky app consents
# Run as Global Reader / Cloud App Security admin; requires Microsoft.Graph module

# --- 1. Enumerate all delegated permission grants (catch malicious OAuth consent) ---
Connect-MgGraph -Scopes "Directory.Read.All" -NoWelcome
$grants = Get-MgOauth2PermissionGrant -All
$report = foreach ($g in $grants) {
    $sp = Get-MgServicePrincipal -ServicePrincipalId $g.ClientId
    [PSCustomObject]@{
        AppName     = $sp.DisplayName
        Publisher   = $sp.PublisherName
        Verified    = $sp.VerifiedPublisher.Status
        Scope       = $g.Scope
        ConsentType = $g.ConsentType
    }
}
# Flag unverified publishers with high-value scopes
$report | Where-Object { $_.Scope -match 'Mail.Read|Files.Read|full_access|offline_access' -and $_.Verified -ne 'Verified' } |
    Format-Table -AutoSize
$report | Export-Csv -Path ".\OAuthConsentAudit_$(Get-Date -Format 'yyyyMMdd').csv" -NoTypeInformation

# --- 2. Sweep endpoints for unauthorized exfiltration/archiving tools ---
$tools = 'rclone.exe','megacmd.exe','winscp.exe','winscp.com','filezilla.exe','megasync.exe'
$paths = @("$env:ProgramFiles","${env:ProgramFiles(x86)}","$env:LOCALAPPDATA","$env:APPDATA","C:\Users\Public")
foreach ($p in $paths) {
    Get-ChildItem -Path $p -Recurse -Include $tools -ErrorAction SilentlyContinue |
        Select-Object FullName, Length, LastWriteTime
}

# --- 3. Check for Tor Browser presence (insider/anonymized comms indicator) ---
Get-ChildItem -Path 'C:\Users' -Recurse -Filter 'tor.exe' -ErrorAction SilentlyContinue |
    Select-Object FullName, LastWriteTime

# --- 4. Restrict user consent so attackers can't ride social-engineered approvals ---
# Set the default user consent policy to disallow self-service consent to unverified apps
$body = @{ permissionGrantPolicyIdsAssignedToDefaultUserRole = @() }
Update-MgPolicyAuthorizationPolicy -BodyParameter $body
Write-Output "User self-service OAuth consent disabled. Route app requests through admin approval workflow."

Remediation and Hardening Recommendations

1. Treat IR and negotiation vendors as privileged third parties — because they are.

  • Enforce least-privilege, time-bound access to case data. No vendor should retain your forensic images, scoping documents, or insurance details after engagement closure without a documented business need.
  • Contractually require background checks on personnel with access to your engagement data, named-personnel clauses (no substitution without approval), breach notification within 24 hours, and right-to-audit provisions.
  • Segment what each vendor can see. Your breach coach doesn't need the forensic images; your negotiator doesn't need your identity architecture diagrams.

2. Harden identity against vishing-driven initial access.

  • Require phishing-resistant MFA (FIDO2/passkeys) for all users; eliminate SMS and voice-based factors, which ShinyHunters-style vishing defeats reliably.
  • Lock down help desk identity verification: require manager callback or hardware-token verification for password resets and MFA changes. Microsoft and CISA both published updated help-desk social engineering guidance in 2025 — adopt it.
  • Disable end-user OAuth consent entirely and route all application consent through an administrator approval workflow (script above). Malicious connected apps die at this control.

3. Detect the theft, not just the intrusion.

  • Deploy DLP and UEBA analytics tuned to volume and velocity of access per user — the single most reliable signal for both external extortion actors and malicious insiders.
  • Alert on any execution of unsanctioned transfer tooling (rclone, MEGA, WinSCP) and any Tor usage on corporate assets. Both should be near-zero in a standard enterprise.
  • Monitor egress to consumer cloud storage domains and flag sessions moving more than a defined baseline (start at 5 GB/hour, tune down).

4. Prepare for extortion that never touches your endpoints.

  • Inventory where your crown-jewel data actually lives — CRM, SaaS file shares, code repos, data warehouses — and confirm audit logging is enabled and centralized for each. SaaS-native intrusions won't show up in your EDR console.
  • Update your IR playbooks: extortion-only incidents require different decisions than encryption events (no restore path saves you — only legal, comms, and negotiation strategy). Pre-vet any negotiation or IR firm you might call before you need them, and have legal counsel validate their regulatory standing.
  • If you've engaged a negotiation firm in the past 24 months, consider a retrospective review of what data they held and whether any engagement details could have leaked — particularly if any prior incident had an unusually well-informed adversary.

5. If you suspect a compromised vendor or insider:

  • Preserve all vendor access logs, email, and engagement artifacts before confronting or terminating access — you may be preserving federal evidence.
  • Rotate every credential the vendor touched, revoke their OAuth grants and service accounts, and audit all actions taken under their identities during the engagement window.
  • Report to the FBI (ic3.gov) and CISA immediately. Given this week's arrest, federal investigators are actively building the ShinyHunters case — your report may matter more than usual right now.

The uncomfortable takeaway from this arrest is that trust itself is now an attack surface being deliberately targeted. Vet your defenders as hard as you vet your defenses.

Related Resources

Security Arsenal Alert Triage Automation AlertMonitor Platform Book a SOC Assessment platform Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.