Back to Feed
Threat IntelligenceSep 30, 2026

ShinyHunters Defiant After FBI Calls on Members to Come Forward

ShinyHunters claims FBI data theft was a marketing stunt after alleged leader's arrest.

Summary

Following the arrest of a suspected leader, the FBI urged other ShinyHunters members to surrender. The group, however, claims the recent hack of FBIJobs.gov was a marketing campaign, not extortion, intended to protect their brand and combat disinformation. They assert that no data will be published and that the operation has led to a business influx.

Full text

The FBI on Tuesday called on ShinyHunters group members to come forward in the wake of the alleged leader’s arrest. The suspected leader, Pepijn van der Stap, of Amsterdam, was arrested on September 15 in the Netherlands while on probation after serving three of the four-year prison term he was sentenced to in 2023 over hacking and extortion activities. The Dutch police on Tuesday said the 24-year-old man is suspected of “playing a role within the hacking group ShinyHunters” and of planning two murders. “After his arrest on September 15, a lot of information was found on his laptop, including about two murders that should be committed abroad. There are indications that the defendant has ordered this,” reads an automated translation of the Dutch police’s announcement. According to the FBI, the suspect is one of the alleged leaders of the extortion group. Since 2025, the authorities say, he has been involved in the hacking of over 140 organizations and in collecting at least $70 million in extortion payments. “They often target third-party vendors in cloud-based platforms, stealing sensitive data and extorting victims with threats to publish it,” said FBI Cyber Division Assistant Director Brett Leatherman.Advertisement. Scroll to continue reading. According to Leatherman, other ShinyHunters group members should take notice of the arrest and come forward before the authorities find them. “To the remaining members of ShinyHunters: You’ve heard about the arrest of your colleague. We’re confident you’ve seen or heard things in recent days that the public has not,” Leatherman said. “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours,” he added. Not extortion, ShinyHunters says Before the FBI’s statement, the hacking group appeared confident that making headlines over the past week has helped it gain more attention, rather than hurting its business. Referring to the hack of FBIJobs.gov and the one-week ultimatum it gave to the Bureau to retract a previous report stating the group tends to exaggerate its claims, ShinyHunters now says all was a marketing campaign meant to protect its brand. The group previously claimed it stole from the FBI’s jobs site the personally identifiable information (PII) and protected health information (PHI) of all current and former FBI employees. It sent a sample list of 5,000 FBI employees to multiple media outlets, stating that it stole 2-3 terabytes of data. This week, ShinyHunters provided the following statement to the media: “Since the very beginning of this event we have unequivocally and assiduously emphasised this is NOT extortion, this is NOT ransom, this is NOT financially motivated. This was all a marketing campaign to protect our business and actively combat disinformation. If we made this statement normally then this much attention to our words and intentions would’ve never been this widespread. We’d have been ignored and disregarded. However, now everyone knows what the issue is and what we are doing. Everyone is reading about it. We proved our points on several occasions. We do not care what the public says and we are not affected by it nor do we cloud our judgement by external opinions and thoughts. We understand why many misinterpreted this as extortion and are convinced we would publish this data and/or misuse it such as selling to third parties due to our history in past operations which has never involved a government entity of prominence. We again want to emphasise that this is not extortion. It never was one to begin with, not a threat, not a ransom, and not financially motivated. Nothing will happen. We are way past this situation in our businesses operations and we confidently believe we have been successful due to seeing a recent influx of success in our operations. We stand corrected.” In a fresh statement on its Tor-based leak site, the extortion group says its operations and infrastructure have not been affected by the recent events, warning victim organizations that they should continue negotiations to prevent the leak of stolen data. “We are eagerly waiting to make examples of those organizations who think they may have gotten a free pass into not paying us few tens of millions of dollars,” the group wrote. Will ShinyHunters survive? Some suggest that the group has decided against extorting the FBI due to the implications: the agency would be even more motivated to identify and hunt down ShinyHunters members. Others, however, suggest that foreign intelligence agencies might have promised ShinyHunters protection in exchange for the data. None of these have been confirmed. According to GuidePoint Security threat intelligence expert Jason Baker, however, it is unlikely that van der Stap’s arrest by the Dutch police would lead to the extortion group’s demise. Even subsequent arrests may not result in ShinyHunters’ demise as a whole. Due to the decentralized nature of the operation, the remaining members may change the group’s name or spin off to other hacking gangs. iCOUNTER director of customer advisory counter fraud lead Jason Brown believes the same. “An arrest is a disruption, not an ending. ShinyHunters operates like a brand, not a fixed crew. Handles change and members rotate, which is why its current leader is reportedly pinning the FBI hack on someone the group was previously associated with. Arrests like this matter. They create fear and distrust inside the group and give investigators leverage. But the people still operating won’t stop. They’ll adjust,” Brown said. “Groups like this don’t win with new exploits alone. Their most damaging campaigns have come from going after the people inside vendors, help desks, and SaaS providers who hold privileged access, then using that trust to reach dozens of downstream victims at once. That’s the real exposure for most organizations,” he added. Related: Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign Related: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon Related: Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court Related: NightmareStresser DDoS Service Disrupted in International Operation Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Reco Raises $55 Million for Agentic SecurityHackers Use ChatGPT Custom GPTs in ClickFix AttacksDutch Police Arrest Convicted Hacker in ShinyHunters InvestigationDaemon Tools Hackers’ NeedyMantis Malware Dissected by MicrosoftPrison Sentence for Former US Soldier Who Hacked AT&T and VerizonDC Health Agency Exposes 400,000 Beneficiary RecordsGoogle Warns of ShinyHunters’ Fresh Oracle PeopleSoft CampaignKiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability Latest News Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking LawsuitRussian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent AttacksHigh-Severity Vulnerabilities Patched in OpenSSL, WolfSSLTrump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI DevelopmentOpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer ConferenceDARPA Selects Xint to Use AI in Securing Military Messaging AppsNew Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data LeaksRemoteThreat Launches With $7 Million for Offensive Operations Platform Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risk

Entities

ShinyHunters (threat_actor)FBIJobs.gov (product)