FBI Says ShinyHunters Breached 140 Organizations as Dutch Police Make Arrest

Dutch police arrested a ShinyHunters suspect as the FBI linked the group to more than 140 breaches and at least $70 million in extortion payments globally.

Written By
Liz Ticong
Liz Ticong
Oct 1, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The FBI says a ShinyHunters-linked extortion campaign has compromised more than 140 organizations and generated at least $70 million in payments.

Dutch police arrested a 24-year-old Amsterdam man on Sept. 15 who is suspected of participating in the group. The FBI has described him as one of ShinyHunters’ alleged leaders, while Dutch authorities have stopped short of assigning him that role.

The case highlights a recurring risk for enterprises: attackers can gain access through third-party cloud environments and use stolen data for extortion even when the victim’s own systems were not the initial point of compromise.

Investigators examine seized devices

Dutch police disclosed the arrest on Sept. 29, two weeks after taking the suspect into custody on Sept. 15. They have released few identifying details, saying only that he is 24 and from Amsterdam.

The High Tech Crime Unit carried out the operation under national law with FBI support and seized several data-storage devices that remain under examination.

FBI officials described him as one of ShinyHunters' alleged leaders. Dutch authorities used narrower wording, saying he is suspected of playing a role in the group and participating in a criminal organization. Neither agency has publicly detailed what evidence establishes his position inside ShinyHunters.

A Rotterdam court ordered the suspect to remain in pretrial detention for at least another 90 days. Police have not ruled out additional arrests as the investigation continues.

Stolen data gave attackers leverage without encrypting systems

According to the FBI, attackers stole sensitive information through those third-party environments and then threatened to publish it unless victims paid.

Extortion under this model depends on possession of stolen data. Organizations can therefore face pressure to pay even when services remain online, separating the threat from the disruption commonly associated with ransomware.

FBI Cyber Division Assistant Director Brett Leatherman credited industry partners with quickly sharing information that assisted the investigation. He then addressed remaining members directly. “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left.”

Advertisement

Reducing third-party data exposure

Security teams should treat vendor access as part of their own exposure map instead of something handled only during procurement. Start by identifying which providers can reach sensitive information and checking if every account or integration still needs that level of access.

Strong third-party risk management should continue after onboarding. Remove stale accounts, cut permissions that are no longer needed, and use phishing-resistant MFA wherever a provider supports it.

Monitoring should cover outside identities as closely as internal accounts. Watch for unexpected logins, unusual access patterns, or large data transfers, and make sure security teams can revoke access promptly when activity does not match normal use.

Response plans should also account for breaches that begin with a supplier. A clear incident response plan should identify who can disable outside access and determine what information the provider held. 

The ShinyHunters investigation shows why that matters: an organization does not need to be breached directly to become an extortion target if attackers can reach valuable data through someone else.

More cybersecurity news: A Pentagon breach exposed sensitive data tied to more than 3 million people, including Social Security numbers and military job details.

Liz Ticong

Liz Ticong is a staff writer for eWeek and TechRepublic focused on AI, cybersecurity, enterprise software, and data. She has more than 10 years of editorial experience as a technology industry writer, combining reporting, product research, and hands-on software testing in her coverage. Her work has been published on Datamation, Enterprise Networking Planet, and TechnologyAdvice.com. She writes technology news, software reviews, product comparisons, and buyer’s guides for business and IT readers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.