
The Dutch police have arrested an alleged ShinyHunters leader, while the group’s spokesperson has adopted a defensive tone over its claimed FBI breach.
The threat actor now insists they never intended to publish the data, and the FBI entry has also been removed from the group’s extortion site.
In a September 29 announcement, the Dutch police said they arrested a 24-year-old Amsterdam man on September 15 on suspicion of participating in a criminal organization.
Police link ShinyHunters, a hacking and extortion group, to breaches involving Odido, Pornhub, and Ticketmaster.
Investigators seized several data storage devices. Information found on the suspect’s laptop also led to a separate suspicion of attempting to solicit two murders abroad, with police saying there were indications he had commissioned them.
A Rotterdam court ordered another 90 days of pretrial detention on September 29. The suspect remains subject to strict communication restrictions, and police have not ruled out further arrests.
FBI’s Brett Leatherman described the suspect as one of ShinyHunters’ leaders. He said the suspect and his co-conspirators had breached more than 140 organizations and collected at least $70 million in extortion payments since last year.
The FBI supported the Dutch-led operation, which Leatherman said reflected its strategy of letting the partner with the strongest authority and access lead.
Leatherman warned remaining members that arrests can encourage cooperation and seized infrastructure can reveal identities, urging them to contact the FBI.
“I suggest you reach out first while the choice is still yours,” he said.
The arrest occurred a week before ShinyHunters publicly claimed the FBI breach.
ShinyHunters spokesperson backpedals
On September 22, ShinyHunters told CyberInsider it had discovered an Oracle PeopleSoft zero-day the previous night and immediately exploited it against the FBI. It claimed remote code execution, lateral movement into FBI-managed AWS GovCloud systems, and theft of 2–3TB of data from services including Criminal Justice, Human Resources, and Medlink.
Screenshots the group provided showed an apparent recruitment-portal defacement and system information on apply.fbijobs.gov. The group claimed it compromised employee, former employee, and applicant information, including personal and health data. CyberInsider has not independently verified the claimed exploit or full dataset.
The FBI acknowledged the claims by September 24 but did not confirm the alleged theft. Reporter Ken Dilanian subsequently reported an internal FBI notification declaring a cybersecurity incident and saying employee Social Security numbers, addresses, and job titles had been exposed.
The group’s original listing demanded the removal of an FBI advisory within one week. CyberInsider’s initial report described this as a threat to leak the data.
However, in a September 29 statement to CyberInsider, its spokesperson disputed that interpretation, saying the group had deliberately left unspecified what would happen after a week and had declined to answer reporters’ questions about consequences.
“This was not a threat. It may have been worded like a threat,” the spokesperson said.
They insisted the operation was never financially motivated and that the group had never planned to publish or sell the data, calling it a marketing campaign to counter alleged misinformation about its activities.
“Nothing will happen,” the spokesperson said, while claiming the campaign had benefited the group’s business.
The defensive explanation and removal of the FBI listing suggest a retreat from the public confrontation. It remains unclear why the group changed its stance, and whether it still holds the data it stole from FBI systems or has deleted copies.






Leave a Reply