The FBI has publicly urged remaining ShinyHunters members to surrender after Dutch police arrested a 24-year-old man from Amsterdam described as one of the group's alleged leaders. The suspect, detained on September 15, will remain in pre-trial detention for at least another 90 days as investigators link the group to more than 140 breached organizations and at least $70 million in extortion since last year. The appeal follows ShinyHunters' claim it stole between two and three terabytes of FBI data by exploiting an Oracle PeopleSoft zero-day.

Arrest in the Netherlands

FBI Cyber Division Assistant Director Brett Leatherman addressed the detention in a video released Tuesday, crediting partners at the Dutch National Police and describing the detainee as an alleged ShinyHunters leader connected to attacks in the United States, the Netherlands, and elsewhere.

Dutch authorities identified the individual as a 24-year-old man from Amsterdam, arrested on September 15 on suspicion of acting within ShinyHunters and taking part in a criminal organization. Police said examination of his laptop uncovered a large volume of material, including plans for two murders intended to occur outside the country, and added there were indications he had directed those plans.

The Rotterdam District Court ruled Tuesday that pre-trial detention will continue for at least another 90 days. Investigators said additional detentions remain possible. Police also clarified Tuesday that this custody is separate from the inquiry into the ShinyHunters breach of Dutch telecom provider Odido. More background on that detention was reported in Dutch police confirm arrest in ShinyHunters hacking investigation.

Scale and methods of extortion campaign

According to the FBI, ShinyHunters and alleged co-conspirators have compromised more than 140 organizations since last year, obtaining at least $70 million in extortion payments.

The group typically focuses on corporate SSO accounts, third-party vendors, and cloud-hosted SaaS platforms such as Salesforce and Snowflake. The pattern involves extracting sensitive data and then demanding payment under threat of disclosure. Previous SSO-focused theft activity is detailed in SSO account data theft attacks, while large Salesforce-related theft claims are covered in 1.5 billion Salesforce records claim and attacks at Qantas, Allianz Life and LVMH. Snowflake customer impacts after a SaaS integrator compromise are described in Snowflake customers hit after SaaS integrator breach.

Claimed breach of FBI systems

The FBI's public warning followed ShinyHunters' assertion that it had breached the bureau itself. The actors told BleepingComputer the intrusion relied on an Oracle PeopleSoft zero-day, as reported in ShinyHunters claims FBI hack in PeopleSoft zero-day breach.

The group asserted it removed between two and three terabytes of data from FBI systems, spanning information tied to multiple internal services. To support the assertion, it said it distributed a sample of about 5,000 FBI personnel records to news outlets, including BleepingComputer.

BleepingComputer declined that sample. 404 Media reported the material contained names and personal data for members of the FBI's Remote Operations Unit, a secretive unit involved in hacking operations. Reuters separately reported that some listed personnel were assigned to investigations involving China and Russia, heightening concern over the sensitivity.

ShinyHunters told BleepingComputer the FBI intrusion was not financially driven, was not an extortion attempt, and was not meant for public release. The group said the action was intended to challenge an FBI advisory characterizing ShinyHunters actors as potentially overstating access to sensitive information, harassing victims and relatives, conducting swatting attacks, and falsely asserting possession of compromising material.

Direct appeal to remaining members

Leatherman used Tuesday's video to speak directly to other participants. He said they were aware of their colleague's detention and had likely encountered recent non-public developments. He argued that prior groups that relied on anonymity or associates for protection had been proven wrong, noting that arrests can alter cooperation and that recovered infrastructure can identify remaining participants.

He added that investigators continue to collect information on group members, that those individuals are under active focus, and that the amount of knowledge held by authorities grows the longer they remain involved. He advised them to initiate contact while that option remains available.

Technical background

This section describes the general class of activity, not new facts about this case.

SSO- and SaaS-centered extortion typically avoids endpoint encryption. Operators obtain identity material through phishing, session-token theft, or misuse of third-party integrations, then use legitimate application APIs and data-export features to copy large datasets from platforms such as CRM, ticketing, and data-warehouse services.

A generic investigative outline for this pattern is:

  1. Identify unexpected authentication events for SSO and SaaS administrator roles, especially logins from new locations, devices, or autonomous system numbers.
  2. Review OAuth grants, connected applications, and API keys for additions around the time of the alert.
  3. Examine bulk read, export, report, and replication activity for unusual volume or scope.
  4. Correlate identity logs with data-access logs to reconstruct which objects were viewed or exported.
  5. Revoke suspect sessions and tokens, rotate credentials, remove unknown integrations, and preserve logs before rebuilding access.

Illustrative generic checks, not tied to this incident:


# list recent SSO sign-ins with failures, new IPs, and MFA results
# replace with fields from your identity provider export
cat sso_signins.json | grep -i -E "fail|unusual|new_ip|mfa"

# look for mass export or API download activity
cat saas_audit.log | grep -i -E "export|download|bulk|report|sync"