Skip to main content
Threat IntelligenceEmerging Threats

FBI Pursues ShinyHunters Members After Key Arrest

Laptop computer sits on a plain surface, surrounded by blurred law enforcement elements.

A 24-year-old man from Amsterdam was arrested on September 15 and, according to Dutch police, investigators found "a large amount of information" on his laptop — including "details about two murders that were to be committed abroad."

The arrest in Amsterdam and Dutch police findings

Dutch National Police announced the arrest on September 15 of a 24‑year‑old Amsterdam man suspected of “playing a role within ShinyHunters and participating in a criminal organization.” The Rotterdam District Court ordered the suspect to remain in pre‑trial detention for at least another 90 days. Police said further arrests have not been ruled out and clarified the detainee was not held as part of the investigation into a ShinyHunters breach of Dutch telecom provider Odido.

On the evidence recovered, Dutch authorities said: "Following his arrest on September 15, a large amount of information was found on his laptop, including details about two murders that were to be committed abroad." The police added, "There are indications that the suspect gave the order for this."

FBI goes public — direct warning from Brett Leatherman

FBI Cyber Division Assistant Director Brett Leatherman recorded a public video statement after the Dutch announcement, framing the arrest as an opportunity for investigators to press their advantage. Leatherman said, "Today, our partners at the Dutch National Police announced the arrest of one of the alleged leaders of ShinyHunters, a group linked to cyberattacks in the United States, the Netherlands, and around the world."

He directly addressed remaining members: "You've heard about the arrest of your colleague. We're confident you've seen or heard things in recent days that the public has not." Leatherman added a pointed warning about operational security crumbling after arrests: "Other groups believed anonymity, or their friends, would protect them, and they were wrong. Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left." He closed with an explicit offer to would‑be cooperators: "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."

ShinyHunters: scope, techniques, and alleged haul

The FBI says ShinyHunters and alleged co‑conspirators have breached more than 140 organizations since last year and collected at least $70 million in extortion payments. According to the reporting, the group frequently targets corporate single‑sign‑on (SSO) accounts, third‑party vendors, and cloud‑based SaaS platforms — naming Salesforce and Snowflake as examples — to steal sensitive data and then extort victims with threats to publish it.

The claimed breach of FBI systems and released samples

The arrest and the FBI's public messaging came shortly after ShinyHunters claimed responsibility for a large data breach at the bureau itself. The threat actors told BleepingComputer they exploited an Oracle PeopleSoft zero‑day and claimed to have stolen between two and three terabytes of data from FBI systems, "including information connected to multiple internal services." To support the claim, the group provided a sample of about 5,000 FBI personnel records to media organizations; BleepingComputer declined the offer, while 404 Media reported the sample exposed names and personal data of members of the FBI's Remote Operations Unit.

Reuters reported that some exposed personnel were assigned to investigations involving China and Russia, a detail the reporting said raised concerns about the sensitivity of the information. ShinyHunters told BleepingComputer the FBI attack "was never financially motivated, an extortion attempt, or intended to publish the data," and that it was carried out to dispute an FBI advisory that warned ShinyHunters actors "may exaggerate access to sensitive information, harass victims and their relatives, conduct swatting attacks, and falsely claim to possess compromising material."

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: Expect renewed scrutiny on SSO, third‑party vendor access controls, and cloud SaaS configurations — the story names Salesforce and Snowflake as common exploitation targets in ShinyHunters activity.
  • Policymakers and regulators: The FBI's public appeal and cross‑border cooperation with the Dutch National Police highlight transnational enforcement dynamics and the scale of alleged extortion payments — the FBI attributes at least $70 million to the group's activity.
  • Affected enterprises and procurement leaders: Organizations that rely on third‑party integrations should watch the intersection of vendor risk and extortion risk, given the group's stated preference for vendor and cloud platform access as a pathway to sensitive data.

The immediate aftermath of the Amsterdam arrest is concrete: one person detained, laptop evidence described by Dutch police, and a Rotterdam court holding the suspect for at least 90 days while investigators continue their work. The FBI has signaled it intends to turn public pressure into more intelligence from seized infrastructure and from individuals who may choose to cooperate. Whether Leatherman's public appeal leads more members to "reach out first" remains the next test in a case that cuts across criminal extortion, alleged violent plots, and a claimed intrusion into the bureau's own systems.

Source: BleepingComputer — FBI tells ShinyHunters members to turn themselves in after recent arrest