For most of the past year, ShinyHunters has acted like a group that believed nobody could touch it. It posted stolen data, taunted victims and, just last week, replaced images on the FBI’s own recruiting website with a cartoon Pokémon. Then, on Monday, the Dutch national police said something the group’s members did not want to hear: an arrest had already been made.
“It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters,” the Dutch police said, according to BleepingComputer. The statement came from the national investigations unit and was posted on X. The man was scheduled to go before a judge in Rotterdam on Tuesday, September 29.
That is the confirmed part. Almost everything else about this case is still being sorted out, and some of the early reporting points in different directions. Here is what we actually know, what we do not, and why it matters to Americans who have never heard of the group.

What Dutch Police Have Confirmed
The official record is thin, which is normal in the Netherlands at this stage of a case. Police have confirmed the suspect’s age, his city and the investigation he was arrested in. They have not released his name or said what specific offenses he is suspected of committing.
According to BleepingComputer, a Dutch tactical police unit searched the man’s Amsterdam home on September 15 and seized electronic devices. The cybercrime news site DataBreaches.net also reported the arrest took place on September 15, and KrebsOnSecurity reported he had been held since around September 16.
Several security outlets, including KrebsOnSecurity and BleepingComputer, have reported the man’s identity and say he was previously convicted in a 2023 Dutch hacking and extortion case, and later worked in the cybersecurity industry. Dutch police have not confirmed his name, and Stucci Media is not publishing it. Under Dutch law, as under American law, he is presumed innocent.
Who ShinyHunters Is
ShinyHunters is a loosely organized group that steals data from companies and then demands payment to keep it from being published. The name and mascot come from Pokémon, and the group has leaned into the cartoon imagery even as its attacks have grown more serious.
Over roughly the past year, the group has targeted or claimed attacks on major companies including Ticketmaster, AT&T, Instructure, McGraw Hill, Carnival Cruise Line and 7-Eleven, according to The Record from Recorded Future News. BleepingComputer reports the group has also claimed a breach of Florida’s DAVID driver database and defaced the leak site of the rival Clop ransomware gang.
The money is serious. Austin Larsen, a researcher with Google’s Mandiant threat intelligence team, estimated the group was on track to collect nearly $100 million in extortion payments in 2026, according to KrebsOnSecurity.
The playbook often relies less on exotic code than on people. Social engineering, such as calling a help desk while pretending to be an employee, is a common tactic in these attacks, and KrebsOnSecurity described the February breach of Dutch telecom Odido as a social engineering attack. That is one reason these attacks are so hard to stop: the weakest link is often a tired worker taking a convincing phone call. It is a theme we have seen in other major intrusions, including the Chinese espionage campaign that hit at least nine U.S. telecom companies.

The FBI Breach Claim
The Amsterdam arrest became public days after ShinyHunters made its boldest claim yet. On Tuesday, September 22, the group defaced FBIjobs.gov, the bureau’s recruiting and job application site, swapping in a Pokémon image and claiming it had stolen data on current and former FBI employees and job applicants.
The group said it was angry about an FBI public service announcement from May that disputed some of its earlier claims. ShinyHunters threatened to leak information on “every FBI agent and anyone who has applied for a job at the FBI” unless the notice came down, The Record reported.
The FBI’s public response has been brief. “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” a spokesperson said. The bureau declined to answer more specific questions.
The group handed a sample of 5,000 records it said belonged to FBI agents to 404 Media and other outlets, which reported they appeared authentic, according to The Record. The Hacker News reported that researchers believe the attackers used a URL-encoding trick to slip past web application firewall protections related to a PeopleSoft vulnerability tracked as CVE-2026-35273. KrebsOnSecurity reported that the group has been exploiting PeopleSoft systems at dozens of organizations since June.
Is the Arrest Connected to the FBI Hack?
This is the question everyone wants answered, and the honest answer right now is: not as far as the public record shows.
The Amsterdam man was taken into custody around September 15, a week before the FBI site was defaced. Dutch police have not tied him to the FBI intrusion. Dutch media reporting has instead linked the investigation to the February 2026 breach of Odido, a Dutch telecom company, in which attackers stole data on roughly 6.2 million people. KrebsOnSecurity reported that Dutch authorities had earlier released an audio clip asking the public to help identify a voice connected to that attack.
ShinyHunters itself has pushed back. A person claiming to represent the group told BleepingComputer: “That individual has no association with us. Frankly, we are laughing.” Taunts like that are part of the group’s brand, so they should be taken with a large grain of salt. Criminal groups have every reason to downplay an arrest, and every reason to try to rattle investigators.
So the fair way to put it is this: the arrest and the FBI breach happened close together in time, but no evidence made public so far connects them.

Why an Arrest Overseas Matters Here
It might seem like a Dutch story. It is not. Many of ShinyHunters’ alleged victims are American companies, which means the stolen records often belong to American customers: names, phone numbers, account details and sometimes more sensitive information. The FBI claim, if the stolen data is what the group says it is, would put federal agents and their families at risk.
International cooperation has also become the main way these groups get caught. Members are often young, spread across several countries and communicate only online. An arrest in one country can produce devices, chat logs and payment records that lead investigators to others. That is why security researchers watch these early arrests so closely, even when the official details are sparse.
There is also a fair debate about how much public attention helps. Some researchers argue that naming and shaming hacking crews pushes them to escalate, as ShinyHunters appeared to do after the FBI’s May advisory. Others argue that sunlight is the only thing that makes victims, companies and lawmakers take the threat seriously. Both points have merit, and the FBI episode is likely to feed that argument for months.
What Happens Next
In the Dutch system, a suspect’s first appearances before an investigating judge usually decide whether he stays in custody while the case is built. Formal charges and a public trial can take many months. Prosecutors may say little in the meantime.
In the United States, the FBI’s investigation into its jobs site continues. If American prosecutors believe the suspect or anyone else connected to ShinyHunters committed crimes against U.S. targets, they could seek charges here and pursue extradition, a process that has been used in past cybercrime cases involving European suspects. As of now, no such U.S. case has been announced.
How to Protect Yourself if Your Data Is Exposed
You cannot control whether a company you do business with gets breached. You can limit the damage.
- Freeze your credit with Equifax, Experian and TransUnion. It is free and stops most new-account fraud.
- Turn on multi-factor authentication for email, banking and phone accounts, preferably using an authenticator app rather than text messages.
- Stop reusing passwords. Our breakdown of the most popular and worst passwords shows how many people still make it easy.
- Treat unexpected calls and texts with suspicion, especially ones that reference real account details. Stolen data is often used to make scams sound legitimate.
- Keep devices updated. Attackers love old software, as seen in campaigns like the North Korean hackers who disguised malware as apps.
The Bottom Line
For a group that has made a sport of mocking law enforcement, the confirmation of an arrest is a meaningful moment. But one arrest is not the end of ShinyHunters, and the most important questions, including who breached the FBI and what was taken, remain open. We will follow the Rotterdam case and the FBI investigation and update readers as officials release more.
Frequently Asked Questions
Who was arrested in the ShinyHunters investigation?
Dutch police confirmed they arrested a 24-year-old man from Amsterdam in September 2026 as part of an investigation into ShinyHunters. Police have not released his name or specific charges, and he is presumed innocent.
What is ShinyHunters?
ShinyHunters is a data theft and extortion group that steals information from organizations and demands payment to keep it private. It has claimed or been linked to attacks on companies including Ticketmaster, AT&T and 7-Eleven.
Did ShinyHunters hack the FBI?
The group claimed it breached the FBI’s job site, FBIjobs.gov, and defaced it on September 22, 2026. The FBI said it is aware of the claims and is investigating. Sample records shared with reporters appeared authentic, according to The Record.
Is the Amsterdam arrest connected to the FBI breach?
No public evidence connects them. The arrest happened about a week before the FBI site was defaced, and Dutch media have linked the investigation to the February 2026 Odido telecom breach.
What should I do if my data was in a breach?
Freeze your credit, turn on multi-factor authentication, change reused passwords and be cautious of unexpected calls or messages that cite your personal details.
Rocci J. Stucci is the founder and CEO of Stucci Media and host of The Rocci Stucci Show.








