Back to Feed
Nation-stateSep 29, 2026

FBI tells ShinyHunters members to turn themselves in after recent arrest

FBI warns ShinyHunters members to surrender after alleged leader's arrest.

Summary

Following the arrest of an alleged leader of the ShinyHunters extortion group by Dutch police, the FBI is publicly urging remaining members to turn themselves in. The group is linked to over 140 breaches and $70 million in extortion, recently claiming a significant data theft from the FBI itself, which they stated was not financially motivated but to dispute an FBI advisory.

Full text

FBI tells ShinyHunters members to turn themselves in after recent arrest By Lawrence Abrams September 29, 2026 04:09 PM 0 The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. "Today, our partners at the Dutch National Police announced the arrest of one of the alleged leaders of ShinyHunters, a group linked to cyberattacks in the United States, the Netherlands, and around the world," FBI Cyber Division Assistant Director Brett Leatherman said in a video released Tuesday. Dutch police said the suspect is a 24-year-old man from Amsterdam who was arrested on September 15 and is suspected of playing a role within ShinyHunters and participating in a criminal organization. "Following his arrest on September 15, a large amount of information was found on his laptop, including details about two murders that were to be committed abroad," the Dutch police announced today. "There are indications that the suspect gave the order for this." The Rotterdam District Court ruled Tuesday that the suspect will remain in pre-trial detention for at least another 90 days, while police said further arrests have not been ruled out. The FBI says ShinyHunters and its alleged co-conspirators have breached more than 140 organizations since last year and collected at least $70 million in extortion payments. ShinyHunters frequently targets corporate SSO accounts, third-party vendors, and cloud-based SaaS platforms, such as Salesforce and Snowflake, to steal sensitive data before extorting victims with threats to publish it. The FBI's warning comes shortly after ShinyHunters claimed responsibility for a massive data breach at the bureau itself, which the threat actors told BleepingComputer that the breach involved exploitation of an Oracle PeopleSoft zero-day. ShinyHunters claimed to have stolen between two and three terabytes of data from FBI systems, including information connected to multiple internal services. The group later provided a sample of about 5,000 FBI personnel records to media organizations, including BleepingComputer, to support its claims. While BleepingComputer declined the offer, 404 Media reported that the stolen information exposed names and personal data belonging to members of the FBI's Remote Operations Unit, a secretive team involved in hacking operations. Reuters also reported that some of the exposed personnel were assigned to investigations involving China and Russia, raising concerns about the sensitivity of the information. Despite the sensitivity of the stolen information, ShinyHunters told BleepingComputer that the FBI attack was never financially motivated, an extortion attempt, or intended to publish the data. Instead, the threat actors claim it was done to dispute an FBI advisory that states ShinyHunters actors may exaggerate access to sensitive information, harass victims and their relatives, conduct swatting attacks, and falsely claim to possess compromising material. The FBI is now taking a more public approach against the group, with Leatherman directly addressing the remaining ShinyHunters members in Tuesday's video. "You've heard about the arrest of your colleague. We're confident you've seen or heard things in recent days that the public has not," Leatherman said. "Other groups believed anonymity, or their friends, would protect them, and they were wrong. Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left. " Leatherman warned that investigators are continuing to gather information about those involved in the group and that they are actively being targeted. "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours." Dutch police also clarified Tuesday that the arrested suspect was not detained as part of the investigation into the ShinyHunters breach of Dutch telecom provider Odido. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Dutch police confirm arrest in ShinyHunters hacking investigationShinyHunters hacks Clop leak site, threatens to extort ransomware gangPasskey-themed phishing attacks lead to Microsoft 365 data theftShinyHunters hackers claim breach of Florida "DAVID" DMV databaseNovocure data breach affects more than 1,400 cancer patients

Entities

ShinyHunters (threat_actor)PeopleSoft (product)SSO (technology)Salesforce (product)Snowflake (product)