World

Dutch police arrest suspected member of group that claimed FBI hack

The suspect, 24, was arrested before the alleged cyber attack took place.

Dutch police have detained a suspected member of the ShinyHunters cyber-crime group, which claimed it had stolen sensitive information on all FBI bureau staff — about 38,000 people.

Following the alleged attack last week, the group said it had obtained every agent’s name, job title, badge number and personal details, including home addresses and phone numbers.

In a statement, Dutch police said they had arrested a 24-year-old man from Amsterdam on suspicion of belonging to the group, which has also claimed responsibility for other hacks.

Police said the suspect was arrested on 15 September, before the alleged FBI attack. He is also suspected of attempted incitement to commit two murders, they said.

Authorities said they seized his devices and discovered a “large amount of information” on his laptop, including “details about two murders that were to be committed abroad” that they suspect he may have ordered.

The suspect has remained in custody since his arrest. Dutch officials have not ruled out additional arrests.

Stan Duijf, who heads Dutch cybercrime investigations, said in a statement: “The ShinyHunters group is responsible for a large number of national and international victims.

“It is good that we have been able to arrest a suspect in the investigation into this group.”

Posting on X, FBI director Kash Patel thanked Dutch partners and said: “As we speak, FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest.”

ShinyHunters said it breached the FBI’s servers on 21 September and began contacting reporters the following day, sharing samples and screenshots of the stolen data.

The BBC has seen a small part of the data, which appears to be authentic.

ShinyHunters is an international hacker collective believed to have originated in France. It has been linked to several major breaches, including one at Rockstar Games in April and a highly disruptive attack on the education platform Canvas in May.

The group says it found a vulnerability in the Oracle cloud storage system used by the FBI to access multiple systems, including FBIJOBS, FBI BEAST, which carries out background checks on employees and applicants, FBI MedLink, which stores agents’ medical records, and FBI BICS, which contains investigation information.

In its dark web message, the group said it did not hack the FBI system for money.

Instead, the cyber-criminals asked the agency to withdraw an advisory it issued in May about the gang, saying it was “offended” by its description.

The advisory, which is still on the FBI’s website, described ShinyHunters as “threat actors” who often “use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims”.

“They target major companies across tech, finance, and retail, often stealing millions of customer records at once,” the advisory said.

Cookies on xabarchi

We use cookies to remember your language and theme, and to count how many people are reading right now — that count is anonymous, lasts only while your browser is open, and cannot be tied to you or to another visit. With your permission we also measure how the site is read: Microsoft Clarity, which records page views and on-page interactions, and our own count of returning readers. Nothing that recognises you across visits is measured until you accept.