Key facts
- Dutch police arrested a 24-year-old man on September 15 in connection with the ShinyHunters hacking group.
- ShinyHunters claimed to have breached FBI servers on September 21, allegedly obtaining personal data of agents.
- The suspect is also accused of attempted incitement to commit two murders abroad.
- Dutch police seized the suspect's devices and found information related to alleged murder plots.
- FBI Director Kash Patel thanked Dutch partners for their assistance in the ongoing investigation.
- ShinyHunters has previously claimed responsibility for hacks on Rockstar Games and Canvas.
Dutch police have arrested a 24-year-old man from Amsterdam on suspicion of being part of the ShinyHunters hacking group, which claimed responsibility for a breach of FBI servers last week. The group alleged it obtained sensitive personal details of FBI agents, including names, roles, badge numbers, home addresses, and phone numbers.
The suspect was arrested on September 15, prior to the alleged FBI attack, and is also suspected of attempted incitement to commit two murders abroad. Dutch police seized his devices and reportedly found a significant amount of information on his laptop related to these alleged murder plots. He has been in custody since his arrest, and Dutch officials have not ruled out further arrests.
Stan Duijf, who leads Dutch cybercrime investigations, stated that ShinyHunters has been responsible for numerous national and international victims, and expressed satisfaction with the arrest. FBI Director Kash Patel acknowledged the arrest and stated that FBI teams are actively working with partners to pursue additional leads.
ShinyHunters claimed to have exploited a vulnerability in Oracle's cloud storage system used by the FBI to access multiple systems, including those for job applications and employee medical records. The group stated their motive was not financial, but rather to pressure the FBI to retract a May advisory that characterized them as "threat actors" who use exaggerated claims of data access to extort victims. The advisory noted that ShinyHunters often targets major companies in the tech, finance, and retail sectors, stealing millions of customer records.