Dutch Police Nab ShinyHunters Member After Claimed FBI Data Breach

By Henry Moore | 29 September 2026, 16:02 BST | Updated 7 hours ago

Police officers standing near a crowd at a public gathering in Amsterdam

A 24‑year‑old man from Amsterdam has been arrested by Dutch police on suspicion of being part of the ShinyHunters hacking collective, which last week announced it had breached the United States Federal Bureau of Investigation's systems, claiming access to the personal details of about 38,000 FBI staff members.

The suspect was detained on 15 September, before the alleged cyber‑attack was carried out. Investigators say his laptop contained “large amounts of information” about the FBI, including details that correspond to two planned murders abroad, which authorities suspect he may have ordered.

Dutch Cybercrime chief Stan Duijf said: “The ShinyHunters group is responsible for a large number of national and international victims. It is good that we have been able to arrest a suspect in the investigation into this group.”

The FBI has already teamed up with Dutch partners to investigate further arrests, according to a statement from director Kash Patel on X. “As we speak, FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest,” he tweeted.

In a press statement, FBI cyber‑bureaux assistant director Brett Leatherman urged other members of the group to surrender: “While the choice is still yours, the longer you stay in this, the more we learn about you. You know how to find us, we know how to find you.”

ShinyHunters, believed to have originated in France, has previously made headlines over breaches of Rockstar Games in April and the education platform Canvas in May. The collective claims they discovered a vulnerability in the Oracle cloud storage system that the FBI used for multiple internal systems, including FBIJOBS, FBI BEAST, FBI MedLink and FBI BICS.

Despite the data appearing genuine, the group stated it did not hack the FBI for profit. Instead, they demanded the agency retract a May advisory that labelled them “offended” by its portrayal.

The FBI’s public service announcement still listed ShinyHunters as a threat actor that “frequently uses real or exaggerated claims of sensitive information to prompt payment from victims,” noting that the group had targeted major tech, finance and retail firms worldwide.

For now, the suspect remains in custody, with Dutch authorities not ruling out further arrests as the investigation continues.