Dutch authorities have detained a suspected associate of the ShinyHunters cybercrime collective, which asserted it had exfiltrated personal data belonging to every FBI employee—approximately 38,000 individuals.
Following the alleged breach last week, the group proclaimed it possessed every agent’s name, role, badge number, and personal details, including home addresses and phone numbers.
In a statement, Dutch police said they had apprehended a 24‑year‑old man from Amsterdam on suspicion of membership in the group, which has also claimed responsibility for other intrusions.
The suspect was taken into custody on 15 September, prior to the purported FBI attack. Police also allege he attempted to incite two murders.
Authorities reported seizing his devices and discovering a “large amount of information” on his laptop, including “details about two murders that were to be committed abroad,” which they believe he may have orchestrated.
He remains in custody, and Dutch officials have not excluded the possibility of additional arrests.
Stan Duijf, who heads the Dutch cybercrime investigations, stated in a release: “The ShinyHunters group is responsible for a substantial number of national and international victims.”
“It is reassuring that we have managed to apprehend a suspect in the investigation of this group.”
Posting on X, FBI Director Kash Patel thanked Dutch partners and said: “As we speak, FBI teams are actively collaborating with partners to gather and act on further leads in the ongoing investigation stemming from this arrest.”
Following the arrest, Brett Leatherman, Assistant Director of FBI Cyber, urged members of the group to surrender “while the choice is still yours”.
He added: “Other groups may believe anonymity or the protection of friends will shield them, but arrests often alter who is willing to cooperate.”
“The longer they remain active, the more intelligence we gather about them—we know how to locate them, and they know how to find us.”
ShinyHunters claimed to have infiltrated the FBI’s servers on 21 September and began contacting journalists the next day, sharing samples and screenshots of the alleged data.
The BBC reviewed a small portion of the leaked material, which appears authentic.
ShinyHunters is an international hacking collective believed to have originated in France. The group has been linked to several high‑profile breaches, including the Rockstar Games incident in April and a disruptive attack on the Canvas education platform in May.
The group asserts it exploited a vulnerability in the Oracle cloud storage system used by the FBI to compromise multiple systems, such as FBIJOBS, FBI BEAST (which conducts background checks on employees and applicants), FBI MedLink (which stores agents’ medical records), and FBI BICS (which holds investigative information).
In a dark‑web message, the group said it did not target the FBI for financial gain.
Instead, the cybercriminals demanded that the FBI withdraw a May advisory concerning the gang, claiming they were “offended” by its characterization.
The public service announcement, external, still posted on the FBI’s website, labels ShinyHunters as “threat actors” who frequently “use real or exaggerated claims of access to sensitive or personal information to extort payment from victims”.
“They primarily target large firms in technology, finance, and retail, often exfiltrating millions of customer records at once,” the advisory noted.

