Dutch police arrest a 24-year-old Amsterdam man in the ShinyHunters investigation
By Sethu Satheesh · 29 Sept 2026 · 9 min read
Threat Actor: ShinyHunters (the arrested suspect is not publicly named by authorities) · Target: Companies breached by ShinyHunters (SaaS/cloud data-theft extortion victims, 2025-2026)
Source: thehackernews.com
Executive Summary
On September 15, 2026, Dutch police arrested a 24-year-old man from Amsterdam in their investigation into the cyber-extortion group ShinyHunters.12 The national investigations unit (Landelijke Opsporing en Interventies) confirmed the arrest, and the suspect was brought before the Rotterdam District Court and remanded into custody for at least 90 days.12 The FBI's cyber division lead, Brett Leathermann, characterised the person as one of the "alleged leaders of ShinyHunters" — a significant claim about a group behind some of the largest data-theft extortion campaigns of 2025 and 2026.2
Two things about this arrest need to be held apart, because the coverage tends to fuse them. First, the ShinyHunters allegation: Dutch police described the suspect as "participating in a criminal organization," referring to the group.2 Second, a separate and more alarming line of inquiry: police said "a lot of information was found on his laptop, including about two murders that should be committed abroad."2 Crucially, the authorities stated that this murder-solicitation investigation is "separate from the investigation into ShinyHunters."2 The two surfaced together only because material about both was found on the same device; the police have not connected the alleged murder plot to the hacking group. A headline that ties "ShinyHunters" and "planning two murders" into a single accusation reads a link the investigators explicitly declined to draw.
This paper does not name the suspect. Dutch authorities did not release his name, and he has been arrested and remanded on suspicion — not charged in open court, not convicted. Third-party reporting, including KrebsOnSecurity and wire services, has identified him and described a prior hacking conviction and a career in the security industry; those are journalists' identifications, not the state's, and ThreatPaper's standard is to name an individual only when they are charged, convicted, or have named themselves. None of those apply here, so the person is described by what the authorities said: a 24-year-old man from Amsterdam.
ShinyHunters, for its part, denied any connection. A representative told TechCrunch the arrested individual "has no association with us," and the group has publicly mocked the operation.2 That denial is exactly the kind of self-serving statement to weigh skeptically — a criminal collective distancing itself from an arrest is not evidence either way — but it does underline that the "alleged leader" framing is, at this stage, an allegation contested by the group and untested in court.
Verification of Claims
-
Claim: Dutch police arrested a 24-year-old Amsterdam man in the ShinyHunters investigation and he was remanded for at least 90 days. → Verified → The national investigations unit confirmed the September 15, 2026 arrest; the suspect appeared before the Rotterdam District Court and was remanded into custody for at least 90 days.12
-
Claim: The arrested man is one of ShinyHunters' leaders. → Weak evidence → The "alleged leader" characterisation comes from the FBI's Brett Leathermann; Dutch police describe the suspect as "participating in a criminal organization." ShinyHunters denies any association. The person has not been charged in open court or convicted in connection with the group, so the leadership claim is a law-enforcement allegation, contested and unproven.2
-
Claim: The alleged murder-for-hire plot is part of the ShinyHunters case. → False (per Dutch police) → Police stated the murder-solicitation investigation is "separate from the investigation into ShinyHunters." The two lines of inquiry are connected only by having surfaced on the same laptop; the authorities did not link the alleged plot to the hacking group.2
-
Claim: Authorities publicly identified the suspect by name. → False → Dutch authorities did not name the arrested man. The names in circulation come from third-party reporting (KrebsOnSecurity, wire services), not from an official charging document or police statement.12
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| 2025–2026 | ShinyHunters | Data-theft extortion campaigns against SaaS/cloud customers; group named in multiple incidents | 3 |
| September 15, 2026 | Dutch police (LOI) | Arrest a 24-year-old man from Amsterdam in the ShinyHunters investigation | 12 |
| September 2026 | FBI (Brett Leathermann) | Describes the arrested person as one of the "alleged leaders of ShinyHunters" | 2 |
| September 29, 2026 | Rotterdam District Court | Suspect appears; remanded into custody for at least 90 days | 12 |
| September 2026 | ShinyHunters | Denies the arrested individual "has any association with us" | 2 |
Operation Anatomy
The arrest
Dutch police arrested a 24-year-old Amsterdam man on September 15, 2026, in an investigation into ShinyHunters, describing him as "participating in a criminal organization." He was brought before the Rotterdam District Court and remanded for at least 90 days.12
The separate murder-solicitation line
Police said material found on the suspect's laptop included information "about two murders that should be committed abroad," and stated that this investigation is "separate from the investigation into ShinyHunters." The two are not connected by the authorities beyond having been found on the same device.2
The group's method (context, not this arrest)
ShinyHunters is a data-theft-and-extortion collective; its 2025–2026 activity is documented around social-engineering-led theft of data from SaaS and cloud environments, followed by extortion threatening to leak the stolen data (T1566.004, T1078, T1530, T1657). These techniques describe the group's campaigns, not any conduct proven against this individual.3
Loading diagram...
Threat Actor Profile
- Group: ShinyHunters, a data-theft and extortion collective responsible for numerous breach-and-leak campaigns across 2025–2026, frequently operating through social engineering and the theft of data from cloud/SaaS platforms, then extorting victims with the threat of publication.3
- The arrested individual: Not named here. A 24-year-old man from Amsterdam, arrested and remanded on suspicion; the FBI calls him an "alleged leader," Dutch police allege participation in a criminal organization, and ShinyHunters denies any association. He is a suspect, not a convicted or charged-in-open-court defendant, in this matter.12
- Attribution confidence for the leadership claim: Low and contested. It rests on a law-enforcement characterisation, is denied by the group, and has not been tested in court.2
- A separate, unproven allegation: Police are separately investigating material on the suspect's laptop concerning two murders to be committed abroad — expressly stated to be unrelated to the ShinyHunters investigation.2
MITRE ATT&CK techniques (documented ShinyHunters campaign TTPs, for context; verified on attack.mitre.org — not proven against this individual):
| ID | Technique |
|---|---|
| T1566.004 | Phishing: Spearphishing Voice |
| T1078 | Valid Accounts |
| T1530 | Data from Cloud Storage |
| T1657 | Financial Theft |
Technical Indicators
event: "Arrest in a law-enforcement investigation, not a fresh intrusion"
suspect: "24-year-old man from Amsterdam (not named by authorities; not named here)"
arrest_date: "2026-09-15"
court: "Rotterdam District Court"
detention: "remanded at least 90 days"
allegation: "participating in a criminal organization (ShinyHunters)"
separate_investigation: "laptop material about two murders abroad — police state this is separate from the ShinyHunters case"
group_context: "ShinyHunters: social-engineering-led data theft from SaaS/cloud + extortion (2025-2026)"
network_iocs: "None — this paper concerns an arrest. IOCs for specific ShinyHunters campaigns live in the incident reporting for those breaches, not in this arrest."Legal and Regulatory Response
This is itself a law-enforcement action: a Dutch arrest and 90-day pre-trial remand ordered by the Rotterdam District Court, in an investigation the FBI has publicly associated with ShinyHunters' alleged leadership.12 The next legally meaningful step is whether Dutch prosecutors bring formal charges and, if so, on what — the ShinyHunters allegation, the separate murder-solicitation matter, or both. Until then the person remains a suspect in custody, and the "alleged leader" label remains an allegation. The international dimension — an FBI official commenting on a Dutch arrest — reflects the cross-border nature of ShinyHunters investigations, but no extradition or U.S. charging action was reported as of this writing.2
Impact Assessment
- Confirmed: Dutch police arrested a 24-year-old Amsterdam man on September 15, 2026, in the ShinyHunters investigation; he was remanded for at least 90 days by the Rotterdam District Court, and the FBI publicly called him an "alleged leader" of the group.12
- Confirmed: A separate investigation concerns laptop material about two planned murders abroad, which police state is not part of the ShinyHunters case.2
- Contested / unproven: The leadership claim (denied by ShinyHunters, untested in court); the suspect's identity as a matter of official record (named only by journalists, not authorities).2
- Unknown: Whether formal charges follow and on what basis; what specific ShinyHunters conduct, if any, is alleged against this individual; and the outcome of the separate murder-solicitation inquiry.2
Lessons and Defensive Recommendations
For defenders tracking ShinyHunters:
- An arrest of an "alleged leader" is not the end of a decentralised extortion collective. Groups like ShinyHunters operate as loose, overlapping crews; the operational lesson is to keep defending against the group's methods — social-engineering-led theft of data from SaaS and cloud platforms, then extortion — regardless of any single arrest. Treat the arrest as a data point, not a reason to relax controls on OAuth grants, help-desk verification, or SaaS data-export monitoring.
For readers and reporters:
- Keep the two allegations separate. The Dutch police were explicit that the murder-solicitation inquiry is not part of the ShinyHunters case; a framing that merges them asserts a connection the investigators declined to make.
- Weigh the sources by what they are. "Alleged leader" is a law-enforcement characterisation of a suspect who has not been convicted; the group's denial is self-serving; the suspect's name is journalist-sourced, not official. Each belongs in its own category, and a careful account keeps them there rather than flattening them into "ShinyHunters leader arrested for planning murders."
On naming:
- There is a reason to resist naming an arrested-but-unconvicted person even when other outlets have done so: arrest is suspicion, not proof, and a name attached to an unproven allegation is difficult to retract. The disciplined default is to report what the state has established — here, a 24-year-old man from Amsterdam, arrested and remanded — and to let charges or a conviction, if they come, license more.
Sources
Footnotes
-
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation — The Hacker News, September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10
-
Dutch police arrest ShinyHunters hacker accused of planning two murders — TechCrunch, September 29, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26
-
24-Year-Old Arrested in Dutch Investigation Into ShinyHunters — Security Affairs, September 2026 ↩ ↩2 ↩3
Related Research
ShinyHunters claims it breached the FBI, defaced FBIjobs.gov, and stole ~2TB on almost all agents via a PeopleSoft zero-day. The defacement is observed and 404 Media matched a data sample to public records — but the FBI says the breach point is undetermined and most is unverified.
Three men who worked in incident response ran BlackCat attacks. One of them was simultaneously negotiating on behalf of ransomware victims — and passing the attackers his own clients' insurance limits.
GTIG tracked UNC6240 (linked to ShinyHunters) mass-exploiting PeopleSoft's CVE-2026-35273 (CVSS 9.8 unauth RCE). Defenders who blocked /PSEMHUB at a WAF instead of patching were bypassed: the actor requested /%50SEMHUB/, one URL-encoded character, then dropped web shells and the SIDEEYE backdoor.