FBI Warns ShinyHunters Members to Surrender After Dutch Police Arrest Alleged Leader
The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man believed to be one of the group’s leaders.
Dutch police arrest alleged ShinyHunters leader
“Today, our partners at the Dutch National Police announced the arrest of one of the alleged leaders of the ShinyHunters, a group associated with cyber attacks in the United States, the Netherlands, and around the world,” FBI Cyber Division Deputy Director Brett Leatherman said in a video released Tuesday.
According to Dutch police, the suspect is a 24-year-old man from Amsterdam who was arrested on September 15. He is suspected of playing a role in ShinyHunters and participating in a criminal organization.
“Following his arrest on September 15, a large amount of information was found on his laptop, including details of two murders that were scheduled to be carried out abroad,” Dutch police announced.
“There is evidence that the suspect directed this.”
The Rotterdam District Court ruled on Tuesday that the suspect would remain in pre-trial detention for at least another 90 days. Police said that further arrests had not been ruled out.
ShinyHunters linked to attacks on more than 140 organizations
The FBI says ShinyHunters and its alleged co-conspirators have infiltrated more than 140 organizations since last year and collected at least $70 million in extortion proceeds.
ShinyHunters frequently targets corporate single sign-on (SSO) accounts, third-party vendors, and cloud-based software-as-a-service platforms such as Salesforce and Snowflake. The group steals sensitive data before extorting victims by threatening to release it.
The FBI’s warning comes shortly after ShinyHunters claimed responsibility for a massive data breach at the agency itself. The attackers told BleepingComputer that the breach involved the exploitation of an Oracle PeopleSoft zero-day vulnerability.
ShinyHunters claimed to have stolen between two and three terabytes of data from FBI systems, including information connected to multiple internal services.
The group later provided news outlets, including BleepingComputer, with samples of approximately 5,000 FBI personnel records to support its claims.
BleepingComputer declined the offer, but 404 Media reported that the stolen information exposed the names and personal data of members of the FBI’s Remote Operations Unit, a secret team involved in hacking operations.
Reuters also reported that some of the exposed employees were assigned to investigations involving China and Russia, raising concerns about the confidentiality of the information.
ShinyHunters says FBI attack was not financially motivated
Despite the sensitive nature of the stolen information, ShinyHunters told BleepingComputer that the FBI attack was never financially motivated, an attempt at extortion, or intended to result in the release of data.
Instead, the threat actors claimed that the attack was carried out to contest the conflict. In an FBI advisory, the agency said ShinyHunters attackers may exaggerate their access to sensitive information, harass victims and their relatives, conduct swatting attacks, and falsely claim to possess dangerous material.
FBI directly warns remaining ShinyHunters members
The FBI is taking a more public approach to the group, with Leatherman directly addressing ShinyHunters members in a video released Tuesday.
“You’ve heard about the arrests of our colleagues. We’re confident the public has seen and heard things in recent days that they don’t know about,” Leatherman said.
“Other groups believed that anonymity and their friends would protect them, but they were wrong. Arrests have a way of changing who is willing to talk, and seizing infrastructure has a way of showing who’s left.”
https://www.youtube.com/watch?v=bxLNRd7WvzU" title="FBI warning to ShinyHunters members
Leatherman warned that law enforcement continues to gather information on people associated with the group and that they are being actively targeted.
“The longer you stay in here, the more we will know about you. You know how to find us, and we know how to find you. We recommend that you contact us first while the choice is still yours.”
Dutch police also clarified on Tuesday that the arrested suspects were not detained as part of an investigation into ShinyHunters’ breach of Dutch telecommunications provider Odid.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



