HomeSecurityFBI calls on ShinyHunters members to surrender, after arrest...

FBI calls on ShinyHunters members to surrender, after alleged leader arrested

The FBI has a very simple message for the ShinyHunters: turn yourself in. On Tuesday, the FBI’s assistant director of cybercrime, Brett Leatherman, released a video thanking Dutch police for the arrest of a 24-year-old man believed to be a member of the group, who is separately suspected of trying to orchestrate two murders. The FBI describes the man arrested in Amsterdam as “one of the alleged leaders of the ShinyHunters,” although Dutch police only say he played a role.

See also: Dutch police arrest hackers in ShinyHunters investigation

Article image: FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader

This arrest is a significant development in the fight against cybercriminals, as ShinyHunters has become known for its attacks on large companies and organizations. This group has been linked to several data breaches, stealing sensitive information and extorting ransom from their victims. Their activities have raised concerns among law enforcement authorities, as their attacks often involve exploiting vulnerabilities in widely used software.

Leatherman’s warning to the rest of the ShinyHunters gang is clear: the man’s arrest is a game-changer and could encourage others to share information with authorities. The arrest comes at a critical time, as the FBI recently confirmed that its job application portal was hacked by the gang. The data stolen in the breach included Social Security numbers and personal details of about 5,000 FBI employees, including some who had worked on sensitive investigations involving China and Russia. Additionally, some of the hacked data included files containing sensitive medical and psychiatric records.

According to ShinyHunters, they gained access to FBI data by exploiting a recently patched vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools. This vulnerability had already been patched, but the attack highlights how important it is for organizations to apply security updates promptly. Delaying the application of these updates can leave systems vulnerable to attacks like the one exploited by ShinyHunters.

It would be a mistake to believe that Dutch police, with the help of the FBI, arrested a suspected leader of the ShinyHunters in response to the embarrassing FBI data breach. The truth is that the arrest came about a week before the FBI breach made headlines. Underworld observers say the group's activities escalated sharply after the arrest, which they attribute to a change in leadership.

See also: ShinyHunters: New wave of attacks – see if your data was leaked and what to do

FBI calls on ShinyHunters members to surrender, after alleged leader arrested

The following days saw not only the FBI hack but also an attempted extortion attempt by the Russian ransomware gang Cl0p. In mid-September, ShinyHunters claimed to have stolen source code, CMS plugins, and Tor private keys from the Cl0p leak site, as well as log files that they claimed could reveal members’ IP addresses. ShinyHunters went on to threaten that if a ransom was not paid, they would publish details of which companies had paid ransom to Cl0p and how much.

This situation highlights the ongoing threat posed by cybercriminals to businesses and government agencies. Organizations must be prepared to face such attacks by investing in strong security measures and training their staff to recognize and respond to threats. In addition, cooperation between international law enforcement agencies is critical to combating cybercrime globally.

Apparently, there's no love lost between cybercriminals, with rival gangs and hackers often falling into feuds and fighting each other. If, like me, you like a ray of sunshine, focus on the thought that this is something that will help encourage information sharing with the FBI and other law enforcement agencies around the world, if not the hackers themselves to turn themselves in outright.

See also: ShinyHunters hacked the dark web site of the Cl0p gang

ShinyHunters FBI zero-day Oracle PeopleSoft breach

The arrest of the alleged leader of ShinyHunters may be an important step in this direction, strengthening efforts to combat cybercrime and protect sensitive data.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS