ShinyHunters: FBI urges members to surrender after arrest

ShinyHunters: FBI urges members to surrender after arrest

The FBI has publicly called on members of the ShinyHunters extortion group to turn themselves in. The appeal follows the arrest in the Netherlands of a man the bureau describes as one of the group's alleged leaders.

The message came in a video released on Tuesday by Brett Leatherman, Assistant Director of the FBI's Cyber Division. "Today, our partners at the Dutch National Police announced the arrest of one of the alleged leaders of ShinyHunters, a group linked to cyberattacks in the United States, the Netherlands, and around the world," he said.

A 24-year-old from Amsterdam

According to the Dutch National Police, the suspect is a 24-year-old man from Amsterdam who was arrested on September 15. He is suspected of having a role within ShinyHunters and of taking part in a criminal organization.

The police also revealed a more serious finding. "Following his arrest on September 15, a large amount of information was found on his laptop, including details about two murders that were to be committed abroad," the Dutch police said, adding: "There are indications that the suspect gave the order for this."

On Tuesday, the Rotterdam District Court ruled that the man will stay in pre-trial detention for at least another 90 days. Police said they have not ruled out further arrests. They also clarified that the suspect was not detained as part of the separate investigation into the ShinyHunters breach of Dutch telecom provider Odido.

140 victims and $70 million in payments

The FBI says ShinyHunters and its alleged co-conspirators have breached more than 140 organizations since last year and collected at least $70 million in extortion payments.

The group tends to go after corporate single sign-on (SSO) accounts, third-party vendors and cloud-based SaaS platforms such as Salesforce and Snowflake. Once it has stolen sensitive data, it pressures victims by threatening to publish it.

The breach at the FBI itself

The warning comes shortly after ShinyHunters claimed responsibility for a large data breach at the FBI. The threat actors told BleepingComputer that the attack involved the exploitation of a zero-day vulnerability in Oracle PeopleSoft.

The group claimed it took between two and three terabytes of data from FBI systems, including information tied to several internal services. To back up its claims, it later offered a sample of about 5,000 FBI personnel records to media organizations, BleepingComputer among them.

BleepingComputer declined the offer. However, 404 Media reported that the data exposed names and personal details of members of the FBI's Remote Operations Unit, a secretive team involved in hacking operations. Reuters reported that some of the exposed personnel were assigned to investigations involving China and Russia, which raises concerns about how sensitive the information is.

ShinyHunters told BleepingComputer that the FBI attack was never about money, was not an extortion attempt and was not meant to lead to a data leak. Instead, the group says it wanted to dispute an FBI advisory. That advisory states that ShinyHunters actors may exaggerate their access to sensitive information, harass victims and their relatives, carry out swatting attacks and falsely claim to hold compromising material.

"Reach out first"

With Tuesday's video, the FBI is taking a much more public line against the group. Leatherman spoke directly to the remaining members.

"You've heard about the arrest of your colleague. We're confident you've seen or heard things in recent days that the public has not," he said.

"Other groups believed anonymity, or their friends, would protect them, and they were wrong. Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left."

Leatherman said investigators are still collecting information on people involved with the group and that they are actively being targeted.

"The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."

Our Take

A video message aimed directly at suspects is not a common move for the FBI, and it suggests the bureau wants to use the Dutch arrest as leverage. The logic is familiar from other takedowns: once one person is in custody and devices have been seized, the remaining members cannot be sure what investigators already know. The FBI appears to be betting that this uncertainty will push some of them to cooperate before they are identified. Recent cases such as the guilty plea by the Rydox marketplace operator show that US prosecutors keep pursuing cybercriminals through the courts.

There is also a personal element here. The claimed breach of FBI systems, and the reported exposure of Remote Operations Unit staff, makes this case more than a routine extortion investigation. The public tone of the warning may partly reflect that.

For defenders, the arrest does not remove the threat. ShinyHunters has been described as a group with several members, and its methods - going after SSO accounts, vendors and SaaS platforms - can be copied by others. Organizations that rely heavily on cloud services should keep reviewing third-party access and account security regardless of how this case develops.

It is worth watching whether the Dutch investigation leads to further arrests, as police have hinted, and whether the FBI's appeal produces any visible defections. How ShinyHunters responds - through silence, new leaks or more attacks - will also say a lot about whether the pressure is working.