The FBI has issued a direct warning to members of the ShinyHunters cybercrime group after Dutch authorities arrested an alleged leader and seized parts of the group’s digital infrastructure.
The warning follows a recent breach targeting FBI systems and portals. According to the supplied report, ShinyHunters allegedly exploited an unpatched zero day vulnerability in Oracle PeopleSoft software to gain access to recruitment portals, human resources systems, and criminal justice databases.
The group is also accused of defacing an FBI recruitment website and leaking a sample dataset containing sensitive personal information linked to roughly 5,000 personnel.
| Detail | Information |
|---|---|
| Cybercrime group | ShinyHunters |
| Recent development | Alleged leader arrested in the Netherlands |
| Infrastructure | Digital systems reportedly seized |
| FBI breach method | Alleged Oracle PeopleSoft zero day |
| Data sample | Information linked to about 5,000 personnel |
| Claimed stolen data | Up to 3TB |
| Organizations breached | More than 140 |
| Reported extortion total | About $70 million |
FBI breach reportedly targeted multiple systems
The supplied material says ShinyHunters recently carried out an intrusion against FBI infrastructure.
The group allegedly used an unpatched vulnerability in Oracle PeopleSoft software to gain access to several internal and public facing systems.
Those systems reportedly included recruitment portals, human resources infrastructure, and criminal justice databases.
The report says the attackers then defaced the FBI’s main recruitment portal by replacing its normal content with a message claiming the site had been seized.
ShinyHunters also allegedly released a verified sample dataset containing personally identifiable information connected to around 5,000 personnel.
The group claimed that it had stolen as much as three terabytes of information covering thousands of current and former agents.
The supplied material presents those figures as claims from the group and does not independently verify the full amount of data allegedly taken.
ShinyHunters described the attack as retaliation
According to the report, ShinyHunters said the intrusion was not financially motivated.
The group claimed it was retaliating against an earlier federal law enforcement advisory that it considered misleading and damaging to its reputation.
It reportedly demanded a formal retraction.
Rather than responding to that demand, law enforcement authorities moved against the group.
Dutch police later arrested an alleged leader, while digital infrastructure connected to ShinyHunters was reportedly seized.
FBI says seized systems could expose remaining members
Following the arrest, FBI Cyber Division Assistant Director Brett Leatherman issued a warning aimed at members who remain active.
He said investigators are gaining more information as arrests are made and infrastructure is taken offline.
The message focused on the idea that seized servers, internal records, and cooperation from arrested suspects can reveal identities and connections inside cybercrime networks.
Leatherman encouraged remaining members to surrender voluntarily before investigators identify and locate them.
His warning made clear that the FBI believes the recent arrest and infrastructure seizure could provide useful intelligence about other people involved in the group.
Dutch police arrest becomes a major development
The Dutch National Police announced the arrest of an alleged ShinyHunters leader under Dutch law.
The arrest is significant because ShinyHunters has been linked to attacks affecting organizations in multiple countries, including the United States and the Netherlands.

The supplied report does not provide the suspect’s name or explain exactly which infrastructure was seized.
It also does not say how many other suspected members have been identified.
Still, the FBI’s public statement suggests investigators believe the operation has created new opportunities to trace the wider network.
ShinyHunters linked to more than 140 breaches
The report says ShinyHunters has been connected to attacks against more than 140 organizations.
The group is also alleged to have extorted approximately $70 million while stealing hundreds of millions of customer and employee records worldwide.
Those figures show why law enforcement agencies have treated the group as a significant cybercrime threat.
ShinyHunters has become associated with large scale data theft and extortion operations targeting organizations with valuable customer, employee, and corporate information.
Investigation appears to be entering a new phase
The latest developments suggest that law enforcement pressure on ShinyHunters is increasing.
An alleged leader has been arrested, infrastructure has reportedly been seized, and the FBI is now openly warning remaining members that investigators are collecting more information about the group.
The supplied material does not say whether the FBI has recovered all of the data allegedly stolen during the recent breach or whether other arrests are expected soon.
It also does not confirm whether the Oracle PeopleSoft vulnerability used in the reported intrusion has been patched across every affected system.
For now, the main development is the shift from investigation to direct pressure, with U.S. and Dutch authorities signaling that the group’s remaining members may face further arrests as investigators examine seized systems and intelligence.



Discussion (0)
Be the first to comment.