Security
The FBI Made a Video for ShinyHunters' Remaining Members. The Arrest It Announced Happened Two Weeks Ago
Dutch police arrested an alleged ShinyHunters leader on 15 September; the FBI made it public this week alongside a video telling everyone still in the group to come forward. The Bureau put numbers on the crew for the first time — 140 organizations, $70 million — and the reason it is spending this much attention is the group's own decision to go after FBI personnel records instead of money.
MAI
The FBI's Cyber Division did not announce an arrest this week so much as address a room. In a video published on 28 September, Assistant Director Brett Leatherman speaks past the press and directly to the people still working inside ShinyHunters:
You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.
The arrest that gave him the standing to say it happened two weeks earlier. Dutch National Police detained a 24-year-old Amsterdam man on 15 September, at the offices of the security company where he worked as chief technology officer. The Rotterdam District Court has ordered him held for at least 90 days. Dutch authorities made the case public on Tuesday; the FBI's video landed alongside it.
The numbers the Bureau chose to publish
| Arrest | 15 September 2026, Amsterdam |
| Disclosed | 29 September 2026 |
| Pre-trial detention | At least 90 days (Rotterdam District Court) |
| Organizations breached | More than 140 since last year (FBI) |
| Extortion payments collected | At least $70 million (FBI) |
| Data claimed from FBI systems | 2–3 TB, via the careers and job-application portal |
| Sample published by the group | Roughly 5,000 personnel records |
Those first two figures are the ones the FBI wanted in circulation. ShinyHunters has spent the past two years as a name attached to other companies' incident reports — Ticketmaster, AT&T, the Salesforce and Snowflake tenant compromises — and the Bureau has now put a single balance sheet under all of it. The method has been consistent and unglamorous: corporate single sign-on accounts, third-party vendors, SaaS tenants, data taken and then sold back to the people it was taken from.
Dutch prosecutors allege something considerably darker than that pattern. Police say material recovered from the suspect's laptop concerned two murders planned abroad, with indications he had authorised them. He faces charges of participating in a criminal organisation. None of it has been tested in court, and ShinyHunters told TechCrunch the man "has no association with us" — a denial worth roughly what such denials usually are, in either direction.
The group made itself a priority
The more interesting question is why a diffuse, profit-driven extortion crew became the subject of a video statement from the head of FBI Cyber. The answer is that ShinyHunters stopped behaving like a business.
In September the group used the Oracle PeopleSoft flaw CVE-2026-35273 to reach the FBI's careers and job-application system, and claimed 2–3 terabytes. The sample it released was not financial data. It was personnel: names, home addresses, phone numbers, family details, and duty assignments identifying employees working on China, Russia, Hezbollah and cartel investigations, along with some medical information. The group's demand was not money. It wanted the Bureau to retract a May 2026 public service announcement that disputed the group's claimed affiliations. On Monday it said it would not publish the larger trove, called the whole confrontation a "marketing campaign", and did not say the data had been deleted.
Threat researcher Jon DiMaggio, quoted by CyberScoop, put the strategic error plainly:
This is retaliation, which is crazy because they have just put a massive target on themselves.
Extortion of a corporate victim is a negotiation with a finite end. Publishing the home addresses of counterintelligence personnel is not a negotiation, and it converts a fraud investigation into something the Bureau will fund indefinitely. Cynthia Kaiser, a former FBI official, made the point that matters most for the people in those records: "once data is disseminated, you can't pull it back and delete all copies." Whatever happens to the group, that exposure is permanent.
What an arrest actually changes
Leatherman's video is a pressure instrument, and the mechanics he describes are real ones. Seized infrastructure names the people who used it. Custody changes who is willing to talk. His second line is the operative one:
The longer you stay in this, the more we learn about you.
That is aimed at a structural weakness. ShinyHunters is not a hierarchy that decapitation ends; it is a loose confederation that has operated alongside and under other names, including the Scattered Lapsus$ Hunters banner, has fractured and rebranded repeatedly, and recruits through the same forums it leaks on. Arresting an alleged leader does not close it. Making every remaining member wonder which of the others is already cooperating is a more plausible theory of how it ends.
For the organisations that have been on the receiving end, none of this changes the week's work. The PeopleSoft campaign that reached the FBI is still running against everyone else, and the patch for it has been available since June. An arrest in Amsterdam does not close that hole. It only tells you what the people exploiting it are prepared to do once the money stops being the point.
Sources: FBI: ShinyHunters Arrested · BleepingComputer: FBI tells ShinyHunters members to turn themselves in after recent arrest · Nextgov/FCW: FBI warns ShinyHunters members to come forward after alleged leader's arrest · TechCrunch: Dutch police arrest ShinyHunters hacker accused of planning two murders · CBS News: Dutch National Police arrest member of group that claimed to have hacked FBI · NBC News: FBI warns ShinyHunters crime group that hacked agent data after arrest · CyberScoop: ShinyHunters trades financial extortion for a reckless war of ego with the FBI