Quick Answer
- Dutch police arrested a 24-year-old man from Amsterdam on September 15, 2026, suspected of playing a role in the ShinyHunters hacking group. The arrest was announced on September 29.
- FBI Director Kash Patel called him “one of the alleged leaders” of the group. A Rotterdam court ordered him held for 90 days while investigators examine seized devices.
- The FBI says ShinyHunters has breached more than 140 organizations and collected at least $70 million in extortion payments since last year.
- The announcement follows the group’s claim, made about a week earlier, that it breached the FBI’s jobs website.
- The FBI has urged the remaining members to “reach out first while the choice is still yours.”
What Happened
Dutch authorities arrested the suspect on September 15, 2026, in Amsterdam, as a suspected member of ShinyHunters. The arrest became public on September 29, when FBI Director Kash Patel described the man as one of the group’s alleged leaders. The operation was carried out with FBI investigators and the Dutch National Police’s High-Tech Crime Unit.
Police seized data storage devices. A Rotterdam court ordered the suspect to be held for an additional 90 days while investigators go through the evidence and consider further arrests. He has not been convicted, and the charges described so far relate to taking part in a criminal organization.
What the FBI Said
Brett Leatherman, Assistant Director of the FBI’s Cyber Division, sent a direct message to the rest of the group: “You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
He added that arrests can encourage cooperation and that seized infrastructure can reveal the identities of remaining members. In other words, the FBI is signaling that more arrests could follow, and that members who come forward early may be treated differently.
How Big Is ShinyHunters
According to the FBI, the group has:
- Breached more than 140 organizations
- Collected at least $70 million in extortion payments since the previous year
Reports on the group’s past targets include Ticketmaster, Pornhub, and the Dutch telecom company Odido. ShinyHunters is known for stealing data from companies, often through third-party vendors and cloud platforms, and then demanding payment to keep it private. Reuters-based reporting says the group exploited Oracle PeopleSoft systems used in education, healthcare, government, and technology.
The FBI Jobs Website Claim
The arrest came shortly after ShinyHunters claimed it had breached the FBI itself. On around September 22, the group said it had exploited an unpatched Oracle PeopleSoft vulnerability to get into FBI systems, and it posted a screenshot of apply.fbijobs.gov defaced with the message “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.”
The group claimed to have stolen 2 to 3 terabytes of data, including information on current and former FBI employees and job applicants. It also shared a sample of around 5,000 records. The FBI confirmed it was investigating claims of unauthorized activity affecting FBIjobs.gov and reportedly took affected systems offline. BleepingComputer noted that it could not independently verify the zero-day, the movement through the network, or the amount of data, while 404 Media verified some of the employee record information.
Reports on what the sample contained include names, home addresses, and details about employees in sensitive roles, which raised fears for agents and their families. The full scope has not been confirmed.
ShinyHunters’ Response
By September 29, a ShinyHunters spokesperson said the FBI operation was never financially motivated and denied plans to release the stolen data, calling it a “marketing campaign.” That statement comes from the group itself and has not been verified.
Why This Arrest Matters
Arrests of alleged leaders are rare in cases like this, because groups often operate across countries and use aliases. Three things make this one notable:
- It targets the group’s leadership structure. The FBI is openly encouraging members to cooperate.
- It follows a very public attack on the FBI. Whether the data is ever released is now an open question.
- It shows international cooperation. The Dutch National Police and the FBI worked together on the operation.
It does not necessarily mean ShinyHunters is finished. The group has had members arrested before, and others can keep operating. Cyber threats are also evolving beyond traditional data theft, such as AI-powered phishing services like EvilTokens and malware that lets AI models vote on their next move.
What You Should Do
You do not need to do anything special because of this arrest, but these are sensible habits, especially if you have ever applied for a government job or used services from companies that were breached:
- Use unique passwords and a password manager. Stolen data is often reused across accounts.
- Turn on multi-factor authentication for email, banking, and any account that supports it.
- Watch for phishing messages that use details from leaked data to sound convincing.
- Keep your devices updated. Recent examples include the iOS 26.7.1 emergency security update that fixed an actively exploited flaw.
- Consider a credit freeze if you were notified that your personal information was exposed.
Frequently Asked Questions
Who was arrested in the ShinyHunters case?
A 24-year-old man from Amsterdam, arrested on September 15, 2026, and described by the FBI as one of the group’s alleged leaders. Dutch authorities have described him as a suspect, and he has not been convicted.
When was the arrest announced?
On September 29, 2026, by FBI Director Kash Patel. A Rotterdam court ordered a further 90 days of detention the same week.
What is ShinyHunters?
A cybercriminal group known for stealing data from organizations and demanding extortion payments. The FBI says it has breached more than 140 organizations and collected at least $70 million since last year.
Did ShinyHunters really hack the FBI?
The group claimed it did, targeting the FBI jobs website, and the FBI confirmed it was investigating. The amount and type of data stolen has not been independently verified.
What did the FBI tell other ShinyHunters members?
Brett Leatherman said: “I suggest you reach out first while the choice is still yours.” He said arrests can encourage cooperation and that seized infrastructure can reveal members’ identities.
Will the stolen data be released?
A ShinyHunters spokesperson denied plans to release it, calling the operation a “marketing campaign.” That claim is unverified.