Dutch police have arrested a 24-year-old man suspected of being linked to the international cybercrime group ShinyHunters. The arrest comes as the group has claimed to have stolen sensitive information relating to around 38,000 employees of the FBI. The group claims it obtained employees’ names, roles and badge numbers, along with personal information such as home addresses and phone numbers.
Why Was the Suspect Arrested?
According to Dutch police, the Amsterdam resident was arrested on September 15. The arrest took place before the cyberattack that ShinyHunters later claimed to have carried out on September 21. Police said the suspect is accused not only of being part of the cybercrime group but also of attempting to incite the commission of two murders abroad.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
Following his arrest, the suspect’s electronic devices were seized. Police said they found a large amount of information on his laptop, including details related to two alleged murders that were planned abroad. Investigators suspect he may have played a role in ordering the killings. The suspect has remained in custody since his arrest, while Dutch authorities have not ruled out further arrests.
The official leading cybercrime investigations in the Netherlands said ShinyHunters has been responsible for a large number of national and international victims. He said the arrest of a suspect in the investigation was an important step.
FBI Director Kash Patel also thanked Dutch authorities for their cooperation. He said FBI teams were working with international partners to obtain and act on additional leads emerging from the arrest.
Brett Leatherman, assistant director of FBI Cyber, urged other members of ShinyHunters to surrender. He said that the longer people remain involved in cybercrime activities, the more information investigators are able to gather about them and their identities.
What Did ShinyHunters Claim About the FBI?
ShinyHunters claimed that it breached FBI servers on September 21. The following day, the group reportedly began sharing samples and screenshots of the allegedly stolen data. A small portion of the data reviewed so far appeared to be genuine, although the full extent of the alleged breach and the total amount of data stolen have not been independently confirmed.
The group claims it exploited a vulnerability in the Oracle cloud storage system used by the FBI to gain access to multiple systems. These allegedly include FBIJOBS, FBI BEAST, which is used for background checks on employees and applicants, FBI MedLink, which stores medical information relating to agents, and FBI BICS, which contains investigation-related information.
Why Does ShinyHunters Say It Targeted the FBI?
ShinyHunters has also claimed that its objective was not financial. Instead, the group demanded that the FBI withdraw a security advisory issued in May that described it as a cybercrime group.
The advisory said ShinyHunters often uses real or exaggerated claims of access to sensitive or personal information to pressure victims into making payments.
What Happens Next?
The group has been linked to several major cyberattacks. In recent months, it has also claimed attacks involving systems in the gaming and education sectors. Following the latest arrest in the Netherlands, investigators are examining the group’s wider network, the involvement of other suspected members and the nature and extent of the alleged FBI data breach.
The claim involving data of around 38,000 FBI employees is significant, but the full scale of the alleged breach has not yet been independently established. The Dutch arrest gives investigators another potential lead as authorities examine ShinyHunters’ wider network and determine what information, if any, was actually compromised.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics