Press "Enter" to skip to content

FBI tells ShinyHunters members to turn themselves in after alleged leader arrested

The FBI has issued a public warning to members of the ShinyHunters extortion group following the arrest of a 24-year-old man in Amsterdam who authorities suspect of playing a role in the group.

According to reporting by BleepingComputer, FBI Cyber Division Assistant Director Brett Leatherman said Dutch authorities had arrested someone the bureau describes as one of ShinyHunters’ alleged leaders. Leatherman also delivered a direct message to other members: turn yourselves in.

The arrest occurred on September 15, although Dutch authorities publicly announced additional details later in the month. Dutch police said investigators seized digital material and that the suspect is believed to have participated in a criminal organization connected with ShinyHunters. The investigation is continuing.

It is important to keep one point straight: authorities allege that the arrested man is connected to ShinyHunters, while the group has reportedly denied that he is a member. At this stage, the allegation should not be treated as a proven fact.

This comes after a remarkable claim involving the FBI itself

The arrest and warning come during an unusually busy period involving ShinyHunters.

The group recently claimed that it compromised the FBIJobs.gov environment through Oracle PeopleSoft and obtained a massive collection of information involving current and former FBI personnel and job applicants. ShinyHunters has claimed that it stole between 2 and 3 terabytes of data and moved into FBI-managed infrastructure in AWS GovCloud.

Those are claims from the attackers, not all independently established facts. The FBI confirmed that it was investigating unauthorized activity affecting FBIJobs.gov and potential exposure of personally identifiable information, but the exact intrusion path, scope of access and amount of data taken have not all been publicly confirmed.

That distinction matters. When criminals describe their own attacks, their statements can provide useful leads, but they should not automatically be treated as a forensic report.

ShinyHunters also claimed the FBI incident was not primarily about collecting a ransom. The group said it wanted the bureau to retract or correct statements in an earlier FBI advisory describing tactics associated with the operation.

Whatever the motivation, deliberately attracting the attention of the FBI is a particularly aggressive move for a cybercrime operation. Now the bureau is publicly telling people associated with the group that investigators are coming for them.

PeopleSoft remains part of the larger story

There is another ShinyHunters development worth watching alongside the arrest.

Google’s Mandiant researchers have reported renewed exploitation of Oracle PeopleSoft vulnerability CVE-2026-35273. The vulnerability had previously been exploited as a zero-day before Oracle released a patch in June.

More recently, researchers observed ShinyHunters using a simple encoding technique that could bypass some web application firewall rules intended to block exploitation attempts. That allowed attackers to continue targeting vulnerable PeopleSoft systems where the underlying security update had not actually been installed.

BleepingComputer has additional technical details on the PeopleSoft campaign.

This is an important reminder about mitigations. A web application firewall rule can reduce exposure, but it is not necessarily a substitute for installing the vendor’s security update. If attackers can alter a request slightly and get around the filtering rule, an unpatched application can still be vulnerable.

Organizations running PeopleSoft should therefore make sure the actual Oracle security update is installed rather than assuming a WAF workaround permanently solves the problem.

The bigger picture

ShinyHunters has been associated with a long series of data-theft and extortion incidents. The latest developments show several parts of the cybercrime ecosystem colliding at once: exploitation of enterprise software, theft of sensitive data, extortion, international law-enforcement cooperation and the arrest of an alleged participant.

One arrest does not necessarily dismantle an operation like this. Cybercrime groups can consist of people in different countries, affiliates and individuals who move between names and operations. It is also possible for a recognizable criminal brand to continue even after important participants are arrested.

But the FBI’s message is unusually direct. After the Dutch arrest, the bureau is effectively telling other alleged members that law enforcement knows who it is looking for and that surrender is preferable to waiting for investigators to arrive.

For defenders, the practical lesson is less dramatic but more useful: patch exposed enterprise applications, do not rely indefinitely on temporary filtering rules, watch authentication and administrative activity, and treat internet-facing business systems as potential paths into much more sensitive infrastructure.

We will continue watching both the investigation into ShinyHunters and the ongoing Oracle PeopleSoft activity as additional verified information becomes available.

Sources: BleepingComputer: FBI tells ShinyHunters members to turn themselves in after recent arrest; BleepingComputer: ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks.


Discover more from Jared's Technology podcast network

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.