2 min read

FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader

Graham CLULEY

October 01, 2026

FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader

The FBI has a very simple message for the ShinyHunters gang: give yourselves up.

On Tuesday, FBI cyber division assistant director Brett Leatherman released a video, thanking the Dutch police for arresting a 24-year-old man they believe to be a member of the group, and and who is separately suspected of attempting to arrange two murders.

The FBI describes the man arrested in Amsterdam as "one of the alleged leaders of ShinyHunters", although Dutch police say only that he played a role.

Leatherman is warning remaining members of the ShinyHunters gang that the arrest of the man changes things considerably, could encourage others to share information with the authorities, and that they should get in touch "while the choice is still yours."

The warning to remaining members of ShinyHunters follows particularly embarrassing episode for the FBI, which recently confirmed it had had its job application portal compromised by the gang.

Data stolen in the breach included Social Security numbers and personal details of approximately 5,000 FBI staff, including some who had worked on sensitive investigations involving China and Russia. Furthermore some of the hacked data included files that contained sensitive medical and psychiatric records.

According to ShinyHunters, it gained access to the FBI's data by exploiting a recently-patched flaw (CVE-2026-35273) in Oracle PeopleSoft PeopleTools.

It would be incorrect, however, to believe that the Dutch police, with the FBI's help, have arrested a suspected leader of ShinyHunters in reaction to the FBI's embarrassing data breach. The truth is that the arrest came a week or so before the compromise of the FBI became headline news.

Observers of the criminal underground say the group's activities escalated sharply after the arrest, which they link to a change of leadership. The subsequent days saw not just the FBI hack but also the attempted extortion of the Russian ransomware gang Cl0p.

In mid-September, ShinyHunters claimed to have stolen source code, CMS plugins, and Tor private keys from Cl0p's leak site, as well as logs that they claimed could reveal the IP addresses of members.

ShinyHunters went on to threaten that if a ransom was not paid, it would publish details of which companies had paid ransoms to Cl0p, and how much.

Clearly there is no love lost between cybercriminals, with rival gangs and hackers frequently falling out and finding themselves battling each other.

If, like me, you like a ray of sunshine - focus on the thought that this is something that will help encourage information to be shared with the FBI and other law enforcement agencies around the world, if not individual hackers directly handing themselves in.

tags


Author


Graham CLULEY

Graham Cluley is an award-winning security blogger, researcher and public speaker. He has been working in the computer security industry since the early 1990s.

View all posts

You might also like

Bookmarks


loader