The U.S. Federal Bureau of Investigation (FBI) called on members of the ShinyHunters cyberextortion group to turn themselves in after Dutch police announced the arrest of a 24-year-old man from Amsterdam suspected of playing a role in the group and being involved in a criminal organization.
The suspect was arrested on September 15, and the Rotterdam District Court decided Tuesday to keep him in pretrial detention for at least another 90 days. Dutch police said they found a large amount of information on his laptop, including details related to two murders that were being planned abroad, with indications, according to the police, that the suspect had ordered them. Police did not rule out further arrests.
A Wide-Ranging Extortion Network
FBI Assistant Director of the Cyber Division Brett Leatherman said ShinyHunters is linked to attacks targeting the United States, the Netherlands, and other countries. The bureau estimates that the group and its associates have breached more than 140 organizations since last year and obtained at least $70 million in extortion payments.
The group often focuses on corporate single sign-on accounts, external vendors, and software-as-a-service cloud platforms, including Salesforce and Snowflake. After stealing sensitive data, it threatens victims with publication of the data in exchange for money.
A Direct Message to Remaining Members
Leatherman said investigators continue to gather information about participants in the group, and that seized infrastructure is helping them identify who remains in it. In a message addressed to the alleged members, he added that their continued activity would lead to more information being learned about them, and urged them to contact the authorities before their options narrow.
The public escalation comes shortly after ShinyHunters claimed responsibility for a wide-ranging breach of FBI systems. The group said the attack exploited an undisclosed zero-day vulnerability in Oracle PeopleSoft and that it stole between two and three terabytes of data. It also provided media outlets with a sample of nearly 5,000 FBI employee records, while reports said the data included names and personal information of individuals from the Remote Operations Unit, a secret team associated with hacking operations.
BleepingComputer declined the offer to obtain the data, while 404 Media reported that some records concerned individuals working on investigations related to China and Russia. The group said its attack on the FBI was not financially or extortion motivated, but was intended to challenge a previous warning by the bureau accusing entities linked to it of exaggerating the extent of their access to sensitive information, harassing victims and their relatives, and carrying out swatting attacks.
What Does This Mean in Practice?
The development shows that targeting corporate identity accounts, vendors, and cloud platforms affects more than data theft; it can enable attackers to establish influence within multiple environments and then use it for extortion. The arrest also does not mean the group’s activity has ended; FBI statements indicate that the investigation is focused on exposing the network, infrastructure, and remaining members. At the same time, Dutch police clarified that the current arrest is not part of the investigation into the breach of Dutch telecommunications company Odido, which places important limits on what can be attributed to the case so far.