Dutch police arrest suspected member of ShinyHunters, hacker group held responsible for data breaches | #cybercrime | #infosec


The group reportedly stole personal data on thousands of FBI agents, along with that of anybody who has used the jobs site to apply for the bureau.

WASHINGTON — Dutch police said Tuesday that they have arrested a suspected member of the ShinyHunters hacker group that has been held responsible for a string of serious data breaches, and accused the man of trying to arrange two murders.

Police said they arrested a 24-year-old man from Amsterdam on Sept. 15 who is “suspected of playing a role in the hacker group ShinyHunters. The man is also suspected of attempted solicitation of two murders.”

Police said the suspicion of trying to arrange two murders was linked to information found on the suspect’s laptop but “is not related to the investigation into ShinyHunters.”

ShinyHunters last week claimed to have breached the FBI’s jobs website. The hacker group said it had stolen “very sensitive data” belonging to thousands of agents and applicants and that it had compromised the bureau’s jobs website.

FBI Director Kash Patel took to X to highlight the arrest in the Netherlands.

“This morning @FBI and our partners the Dutch National Police are announcing the arrest of one of the alleged leaders of ShinyHunters – a global cybercrime and threat actor group linked to cyberattacks in the United States, the Netherlands, and around the world,” Patel said.

“In coordination with FBI investigators the Dutch High-Tech Crime Unit arrested the suspect under Dutch law,” Patel added. “As we speak FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest.”

The Dutch police statement announcing the arrest did not mention the FBI hack or coordination with American law enforcement.

Dutch detectives seized data storage devices during their probe and were investigating their contents and said they did not rule out more arrests.

“Arresting cybercrime suspects is a key intervention in our broad-based fight against this type of crime,” said Stan Duijf, the Dutch police official responsible for tackling cybercrime. “The ShinyHunters group is responsible for a large number of victims, both in the Netherlands and abroad. It is gratifying that we have been able to arrest a suspect in the investigation into this group.”

A court in Rotterdam on Tuesday, Sept. 29 ordered the suspect held for a further 90 days.

Last Wednesday, Sept. 23, the FBI said it was “actively and aggressively investigating” a claimed hack of the FBIJobs.gov portal. A message that circulated online from ShinyHunters claimed responsibility.

“We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,” said the ShinyHunters message, which was directed to Patel and Brett Leatherman, the assistant director in charge of the bureau’s cyber division. The claims could not immediately be verified.

In its message, ShinyHunters said it would give the bureau one week to correct or remove what it said were false allegations contained in an FBI public advisory from May that described the organization as a “cyber criminal group specializing in large-scale data breaches and extortion.”

The hackers sought retribution over an FBI advisory

Miriam Wugmeister, a lawyer specializing in data, privacy and cybercrime who tracks hacking outfits like ShinyHunters, said that based on the group’s past practices, there was reason to believe the hackers’ claims, “so I think it’s likely that they were able to compromise this website and they got some data.”

Wugmeister said that though the data that appeared to be compromised was the type of personal information that is routinely accessed during a breach, the hack nonetheless had alarming national security implications given that it could expose agents and their families to extortion, swatting and other harassment and because the identities of spouses were also said to have been obtained.

“Even if the agents and the analysts and the employees are sophisticated, you worry about their families, too,” Wugmeister said.

In its message, ShinyHunters said it would give the bureau one week to correct or remove what it said were false allegations contained in an FBI public advisory from May that described the organization as a “cyber criminal group specializing in large-scale data breaches and extortion.”

That advisory characterized ShinyHunters as “threat actors” who often “use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims,” commonly harass or threaten victims and “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”

ShinyHunters said in its message to the FBI that it was “offended” by those characterizations and demanded that the FBI remove those claims. It did not say what would happen if the FBI did not do so within a week.

“This is not a ransom, coercion, or extortion. Your federal policies do not apply here. This PSA is NOT financially motivated,” the hacking group’s message said.

ShinyHunters has a reputation for “causing trouble and being disruptive,” Wugmeister said, as evidenced by the group’s involvement in a hack last spring of Canvas, an online system used by thousands of schools and universities. The breach created chaos as students tried to study for finals and prompted the FBI’s advisory that ShinyHunters is now objecting to.

Copyright 2026 Associated Press. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.     



Click Here For The Original Source.

——————————————————–

..........

.

.