
Dutch authorities and the FBI said Tuesday that Dutch law enforcement had arrested a leader of ShinyHunters, the international cybercrime group that last week claimed to have hacked an FBI website and stolen sensitive personal information on agents.
The bureau is not explicitly tying the Dutch man’s arrest to the FBI hack, which seemingly occurred after the man was detained, but is using it to warn other members of the ShinyHunters criminal ring.
In a video statement published to the FBI website, Cyber Division Assistant Director Brett Leatherman addressed the hackers directly and urged them to confess to law enforcement.
“To the remaining members of ShinyHunters: You’ve heard about the arrest of your colleague,” Leatherman said.
“Other groups believed anonymity or their friends would protect them and they were wrong. Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left,” he said. “I suggest you reach out first while the choice is still yours.”
Leatherman did not directly address the FBI hack in his message to ShinyHunters.
Earlier on Tuesday, Dutch National Police announced that on Sept. 15 it had arrested a 24-year-old Amsterdam man suspected of being a ShinyHunters hacker. They said he is separately being investigated for allegedly ordering two murders abroad.
ShinyHunters is a prolific cyber-extortion group with members from across the globe. It routinely hacks companies to steal sensitive data and then threatens to leak it onto the dark web unless they’re paid a fee.
Last week, ShinyHunters announced on its website it had hacked the FBI’s jobs portal site and stolen significant personal information on agents. The group demanded that the FBI retract a public service announcement about the group issued in May. It gave a deadline of Sept. 29 to do so, though it did not explicitly say it would publish the data it had stolen.
ShinyHunters breached the FBI on Sept.21, placing the hack after the Dutch man’s arrest. The group did not respond when asked about the arrest and Leatherman’s message.
While the full extent of what ShinyHunters stole from the FBI is unclear, a ShinyHunters spokesperson sent NBC News a sample document that included sensitive personal information about a former agent, who confirmed it was authentic.
According to a Justice Department notification to lawmakers obtained by NBC News, the FBI designated the matter a cybersecurity incident on Sept. 22. It said the affected system holds sensitive personal information, including Social Security numbers, dates of birth, phone numbers, addresses and emergency contact information, and that investigators are still working to determine how many people may have been affected.
ShinyHunters also claimed to have used its access to the FBI jobs portal to pivot and steal a cache of other information from multiple other agency programs, but did not provide evidence of those claims.
The FBI sent a message to employees on Friday saying they were working on the premise that personally identifiable information of employees may have been obtained, according to a person familiar with the communication, and to be vigilant and report any unsolicited contacts. The person said that some FBI employees were frustrated that they heard about the data breach from the media as well as what they saw as a slow response from the bureau.
“The FBI is working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted — including multiple Bureau wide communications within 24 hours of public reporting. The FBI treats the security of its information and the safety of its workforce as top priorities, and our investigation is ongoing,” an agency spokesperson said in a statement.
On Monday afternoon, before the FBI’s announcement, the ShinyHunters spokesperson told NBC News that it now was committed not to publish any data it had stolen from the agency. The spokesperson added a lengthy statement that indicated it was backing down from its demand the PSA be retracted.
“This was all a marketing campaign to protect our business and actively combat disinformation,” the statement said.
“This was not a threat. It may have been worded like a threat but ultimately the public has drove this story out of context and made their own wild assumptions and speculations,” it said. “We stand corrected.”












Leave a Reply