FBI Issues Stark Warning to ShinyHunters After Key Arrest, Citing $70 Million in Extortion
The **FBI** has issued a direct ultimatum to members of the **ShinyHunters** extortion group, urging them to surrender following the arrest of an alleged leader by Dutch police. This development comes as the group is linked to over 140 breaches and an estimated $70 million in illicit gains, even claiming a recent hack of the **FBI** itself.

The **FBI** is intensifying its campaign against the notorious **ShinyHunters** extortion group, delivering a public warning for remaining members to turn themselves in. This aggressive stance follows the arrest of a 24-year-old Amsterdam man, described by the bureau as one of the group's alleged leaders, by Dutch National Police.
"Today, our partners at the Dutch National Police announced the arrest of one of the alleged leaders of **ShinyHunters**, a group linked to cyberattacks in the United States, the Netherlands, and around the world," stated **FBI** Cyber Division Assistant Director **Brett Leatherman** in a video released Tuesday.
### The Arrest and Disturbing Revelations
The suspect was apprehended on September 15, with Dutch police confirming his role within **ShinyHunters** and participation in a criminal organization. The investigation uncovered disturbing information on his laptop, including details related to two planned murders abroad, which authorities suspect he ordered.
A Rotterdam District Court ruling on Tuesday extended the suspect's pre-trial detention for an additional 90 days, with police indicating that further arrests are not being ruled out.
### ShinyHunters' Reign of Breaches and Extortion
The **FBI** attributes over 140 organizational breaches to **ShinyHunters** and its alleged co-conspirators since last year, accumulating at least $70 million in extortion payments. The group frequently targets corporate **SSO accounts**, third-party vendors, and cloud-based SaaS platforms such as **Salesforce** and **Snowflake**, exfiltrating sensitive data and threatening its publication unless a ransom is paid.
### The FBI's Own Breach: A Motiveless Attack?
This latest warning from the **FBI** comes shortly after **ShinyHunters** claimed responsibility for a significant data breach at the bureau itself. The threat actors asserted to BleepingComputer that this breach leveraged an **Oracle PeopleSoft** zero-day vulnerability.
**ShinyHunters** claimed to have stolen between two and three terabytes of data from **FBI** systems, impacting multiple internal services. A sample of approximately 5,000 **FBI** personnel records was reportedly provided to media organizations, including BleepingComputer, to substantiate these claims.
While BleepingComputer declined the offer, **404 Media** reported that the stolen information exposed names and personal data of members of the **FBI**'s Remote Operations Unit, a clandestine team involved in hacking operations. **Reuters** further reported that some exposed personnel were assigned to investigations concerning China and Russia, raising significant national security concerns.
Intriguingly, **ShinyHunters** claimed the **FBI** attack was not financially motivated, an extortion attempt, or intended for data publication. Instead, the group asserted it was a direct response to an **FBI advisory** that accused **ShinyHunters** of exaggerating access, harassing victims, conducting swatting attacks, and falsely claiming compromising material.
### A Direct Message to Remaining Members
In a departure from typical law enforcement advisories, **Assistant Director Leatherman** directly addressed remaining **ShinyHunters** members in Tuesday's video.
"You've heard about the arrest of your colleague. We're confident you've seen or heard things in recent days that the public has not," **Leatherman** stated. "Other groups believed anonymity, or their friends, would protect them, and they were wrong. Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left."
**Leatherman** warned that investigators are actively gathering intelligence on all involved and are targeting them directly. "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."
Dutch police also clarified that the recent arrest was not connected to the investigation into the **ShinyHunters** breach of Dutch telecom provider **Odido**.