Dutch law enforcement officers have arrested a 24-year-old suspect believed to be affiliated with the ShinyHunters cybercrime collective, an international group that recently asserted it had exfiltrated sensitive records belonging to approximately 38,000 FBI personnel.
The suspect was taken into custody on September 15, preceding the group’s alleged intrusion into the bureau’s systems. According to a police statement, he is also implicated in attempted incitement for two murders, with officers discovering information on his laptop detailing planned killings abroad.
Stan Duijf, who heads cybercrime investigations in the Netherlands, highlighted the severity of the group’s activities. “The ShinyHunters group is responsible for a large number of national and international victims,” Duijf said. “It is good that we have been able to arrest a suspect in the investigation into this group.” Officials noted that the suspect remains in detention and that further arrests are possible.
The ShinyHunters group, thought to have originated in France, has been linked to several high-profile breaches, including attacks on Rockstar Games and the Canvas education platform. On September 21, the group claimed to have exploited a vulnerability in the Oracle cloud storage infrastructure used by the FBI. They alleged access to multiple databases, including FBIJOBS, FBI BEAST, which conducts background checks, FBI MedLink, containing medical records, and FBI BICS, which holds investigative data.
The hackers stated they did not seek financial gain but rather demanded the retraction of a May public service advisory that characterized them as threat actors who extort payments from victims. The advisory, which remains online, described the group as targeting major corporations in tech, finance, and retail.
FBI Director Kash Patel thanked Dutch partners for their assistance, confirming that FBI teams are actively pursuing new leads derived from the arrest. Brett Leatherman, assistant director of the FBI Cyber division, urged remaining group members to surrender, warning that anonymity is increasingly difficult to maintain.
“The longer you stay in this, the more we learn about you,” Leatherman said. “You know how to find us, we know how to find you.”
The BBC has verified a small sample of the purported stolen data, which appears authentic. The group began contacting journalists on September 22, sharing screenshots and data samples to substantiate their claims.
A laptop revealing planned murders abroad? That’s dark even for hackers. Glad he’s off the streets.
Netherlands really stepped up. It’s impressive to see international cooperation work this smoothly on such a high-profile case.
Does anyone know if the FBIJOBS data was actually sold or if it stayed within the group? The stakes for employees are huge.
Crazy how they demanded political retraction instead of money. Classic ego-driven cybercrime move that probably sealed their fate.