FBI tells ShinyHunters members to turn themselves in after recent arrest

The FBI has issued a stern warning to members of the notorious ShinyHunters extortion group, urging them to turn themselves in following the recent arrest of one of their alleged leaders. The move comes as part of a widening investigation into the group’s activities, which have seen them breach over 140 organizations worldwide and extort at least $70 million from victims.

ShinyHunters has made headlines for its brazen tactics, targeting corporate Single Sign-On (SSO) accounts, third-party vendors, and cloud-based Software as a Service (SaaS) platforms like Salesforce and Snowflake. The group’s modus operandi involves stealing sensitive data before extorting victims with threats to publish the stolen information. But what’s particularly alarming is that ShinyHunters has also claimed responsibility for a massive data breach at the FBI itself, which saw them allegedly exploit an Oracle PeopleSoft zero-day vulnerability to steal between two and three terabytes of data.

The group provided a sample of 5,000 FBI personnel records to media organizations, exposing personal data belonging to members of the FBI’s Remote Operations Unit, a secretive team involved in hacking operations. The stolen information also included sensitive details about investigations involving China and Russia, raising concerns about the potential consequences of this breach.

In a bizarre twist, ShinyHunters claims that the FBI attack was not financially motivated or intended to publish the data, but rather an attempt to dispute an FBI advisory that criticizes their tactics. This assertion has been met with skepticism by law enforcement officials, who are now taking a more public approach against the group.

FBI Cyber Division Assistant Director Brett Leatherman directly addressed the remaining ShinyHunters members in a video statement, warning them that investigators are actively gathering information about those involved and that arrests have become increasingly common. “Other groups believed anonymity would protect them, and they were wrong,” Leatherman said. “We know how to find you, and I suggest you reach out first while the choice is still yours.”

The Dutch police’s arrest of a 24-year-old man from Amsterdam has sent shockwaves through the group, with further arrests not ruled out. The suspect’s laptop was found to contain details about two murders that were intended to be carried out abroad, raising concerns about the group’s willingness to engage in violent activities.

As the investigation unfolds, one thing is clear: ShinyHunters’ days are numbered. With law enforcement agencies increasingly cracking down on cybercrime groups, it’s only a matter of time before more members are brought to justice. If you’re involved with ShinyHunters or any similar group, take heed of the FBI’s warning: surrender now and avoid facing severe consequences later.

For security-conscious individuals and organizations, this story serves as a stark reminder of the dangers posed by cybercrime groups like ShinyHunters. Protecting your organization from these threats requires a multi-faceted approach, including robust cybersecurity measures, employee education, and a proactive response to potential incidents. Stay vigilant, stay informed, and always be prepared for the worst-case scenario – it’s the only way to stay ahead of cybercrime groups like ShinyHunters.


Source: Bleeping Computer — 2026-09-29