Skip to content
feed: live
>_0dayNews
ransomware

FBI Warns ShinyHunters Members to Surrender After Arrest

Dutch police arrested an alleged ShinyHunters leader, prompting the FBI to warn remaining members of the extortion group to turn themselves in.

FBI Warns ShinyHunters Members to Surrender After Arrest
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
loopNadia "Loop" Park·Published ·2 min read

Dutch police have arrested a man the FBI describes as one of the alleged leaders of the ShinyHunters extortion group. Following the arrest, the FBI issued a warning to other members of the group: turn themselves in, according to BleepingComputer reporting published September 29.

ShinyHunters has been among the most active extortion groups tracked through 2026. The group’s operations have included the Oracle PeopleSoft campaigns documented through September, the Clop Tor site breach in late September, and a string of high-volume data thefts spanning healthcare, financial services, and enterprise SaaS providers. We have covered ShinyHunters’ claims of breaching FBI infrastructure via a PeopleSoft zero-day earlier this month, which the bureau has not confirmed.

What the arrest changes, operationally

Law enforcement arrests of alleged group leaders do not automatically disrupt operations. ShinyHunters has historically operated with distributed membership across multiple jurisdictions, with infrastructure that has proven resilient to individual arrests. The FBI’s decision to publicly warn remaining members, rather than simply pursue them, signals either confidence in additional pending arrests or an attempt to accelerate internal fracture within the group.

The warning’s effectiveness depends on what the Dutch arrest produced. If the arrested individual had access to identities, communications, or operational infrastructure tied to other members, that changes the calculation for those still active. If not, the warning is primarily psychological pressure.

Context: an active group at an inflection point

ShinyHunters has been running multiple simultaneous operations across this month. The group’s active exploitation of Oracle PeopleSoft CVE-2026-35273 is ongoing against enterprise targets, and the group has been extorting Cl0p victims using data from a separate breach of Cl0p’s own infrastructure.

Whether this arrest alters those campaigns will become visible over the next few days. Groups in active extortion cycles typically continue operations through an arrest if the operational infrastructure is intact; they slow if the arrested member held active access or key relationships with victims.

Further details about the identity of the arrested individual, the charges, and the scope of the Dutch investigation have not been publicly released.


Related coverage: ShinyHunters Claims FBI Breach via PeopleSoft Zero-Day | ShinyHunters WAF Bypass and Oracle PeopleSoft CVE-2026-35273 | ShinyHunters Extorts Cl0p, Victim Data at Risk

Found this useful? Share it.