The FBI publicly called on remaining members of the extortion group ShinyHunters to surrender, days after Dutch National Police arrested a 24-year-old Amsterdam man identified as one of the group’s alleged leaders. Investigators say they found evidence on the suspect’s laptop describing plans to commit two murders abroad.
Amsterdam Arrest Leads to 90-Day Pre-Trial Detention
Dutch National Police arrested the suspect on September 15. A Rotterdam court subsequently ordered at least 90 days of pre-trial detention. Beyond the extortion-group allegations, Dutch authorities say they found material on the suspect’s laptop describing plans for two murders to be carried out abroad, with indications suggesting the suspect had ordered the killings.
Brett Leatherman Issues Direct Warning to Remaining Members
FBI Cyber Division Assistant Director Brett Leatherman released a video statement addressing ShinyHunters members who remain at large. “The longer you stay in this, the more we learn about you,” Leatherman said in the statement. “I suggest you reach out first while the choice is still yours.” The direct, public framing of the message signals that the FBI intends to keep pressuring the group’s remaining membership following the Amsterdam arrest.
FBI Says the Group Extorted at Least $70 Million From 140 Victims
According to the FBI, ShinyHunters and its co-conspirators have breached more than 140 organizations since last year and collected at least $70 million in extortion payments. The bureau said the group’s targeting has focused on single sign-on accounts, cloud platforms including Salesforce and Snowflake, and third-party vendors that provide access into larger corporate environments. That approach lets the group reach data belonging to a breached vendor’s downstream customers rather than limiting the damage to the vendor itself.
Targeting single sign-on credentials and cloud platform access, rather than exploiting a specific software vulnerability in each victim’s own systems, gives ShinyHunters a repeatable playbook: once the group obtains valid access to a shared platform or a vendor’s administrative tools, it can pivot across every downstream customer connected through that same access point. The FBI’s disclosure of the $70 million and 140-victim figures at this stage of the investigation indicates the bureau has now attributed a substantial share of recent SSO and cloud-platform extortion activity to this single group and its co-conspirators.
Group Has Claimed a Breach of FBI Systems via Oracle PeopleSoft
ShinyHunters has separately claimed to have breached FBI systems using an Oracle PeopleSoft zero-day vulnerability, allegedly stealing 2 to 3 terabytes of data that the group says includes personnel records belonging to the FBI’s Remote Operations Unit. Neither the scope of that claimed intrusion nor the authenticity of the allegedly stolen records has been independently confirmed in the FBI’s public statement, but the claim itself illustrates the group’s stated willingness to target law enforcement infrastructure directly rather than confining its activity to corporate and cloud-platform victims.
Public Ultimatum Marks Escalation in the Law Enforcement Campaign
The combination of a completed arrest, a court-ordered detention period, and a direct public appeal from a senior FBI cyber official represents a shift from investigation toward active pressure on the group’s remaining members. Publicizing the scale of the group’s alleged activity, 140-plus victim organizations and $70 million in extorted payments, alongside the surrender request suggests investigators are betting that remaining members will calculate the risk of continued exposure against the option of coming forward voluntarily.
The murder-plot evidence found on the arrested suspect’s device adds a violent dimension to a group whose public profile has centered on large-scale data theft and extortion against corporate cloud environments. Investigators have not disclosed whether the alleged murder plans were connected to internal group disputes, witness intimidation, or another motive. The FBI’s investigation into the group’s broader membership and infrastructure continues alongside the Dutch prosecution of the arrested suspect, whose detention is set to run at least 90 days from the September 15 arrest.
