FBI tells ShinyHunters members to turn themselves in after recent arrest

The FBI is cracking down on the notorious ShinyHunters extortion group, warning its remaining members to turn themselves in after a key suspect was arrested by Dutch authorities. This development marks a significant milestone in the ongoing battle against cybercrime, and it’s essential for organizations and individuals alike to understand what’s at stake.

ShinyHunters has been linked to numerous high-profile data breaches and extortion attempts worldwide, including a recent incident that compromised sensitive information from the FBI itself. According to the Dutch National Police, a 24-year-old suspect from Amsterdam was arrested on September 15th and is believed to have played a significant role in the group’s operations. During his arrest, investigators seized a laptop containing details about planned murders, as well as evidence pointing to the suspect’s involvement in orchestrating these crimes.

The FBI has been actively tracking ShinyHunters for over a year, documenting more than 140 breaches and collecting at least $70 million in extortion payments from the group. Their tactics typically involve targeting corporate single sign-on (SSO) accounts, third-party vendors, and cloud-based software-as-a-service (SaaS) platforms like Salesforce and Snowflake to steal sensitive data. This stolen information is then used as leverage for extortion, with ShinyHunters threatening to publish it unless their demands are met.

The group’s recent attack on the FBI was particularly brazen, with ShinyHunters claiming they had exploited an unpatched vulnerability in Oracle PeopleSoft to breach internal systems and steal sensitive data. While the group claimed this breach was not financially motivated or intended for extortion, many have raised concerns about the potential consequences of exposing such sensitive information.

In a striking move, the FBI is now taking a more public approach against ShinyHunters, with Assistant Director Brett Leatherman directly addressing remaining members in a video message. He warned that investigators are continuing to gather information and that those involved should be aware that their anonymity will eventually be compromised. “You know how to find us,” Leatherman said, “and we know how to find you.”

As this story unfolds, it’s essential for organizations and individuals to remain vigilant against similar cyber threats. By understanding the tactics used by ShinyHunters and other groups like them, we can better prepare ourselves against these types of attacks. This includes implementing robust security measures, staying informed about emerging threats, and being cautious when interacting with cloud-based services.

Ultimately, this development serves as a powerful reminder that law enforcement agencies are actively working to disrupt and dismantle cybercrime networks. As the stakes continue to rise, it’s crucial for all parties involved – organizations, individuals, and authorities alike – to work together to combat these threats and protect sensitive information.


Source: Bleeping Computer — 2026-09-29