Dutch police announced the arrest of a 24‑year‑old man from Amsterdam on 15 September. He is suspected of being a member of the ShinyHunters collective that publicly claimed to have accessed personal data for approximately 38,000 FBI employees.
According to ShinyHunters, the breach exposed agent names, badge numbers, roles, home addresses, phone numbers and other private details. The group released screenshots and sample data to journalists the day after the reported attack.
The arrested suspect is also suspected of planning two murders abroad. Police seized his laptop, which reportedly contained a large amount of information, including details that could be used to order the killings.
Evidence from the investigation has led Dutch authorities to announce that further arrests are possible. The Dutch national cybercrime lead, Stan Duijf, said the group has “damaged a large number of national and international victims” and praised the international cooperation.
FBI officials confirmed collaboration, with Director Kash Patel thanking Dutch partners in a public statement. Assistant Director Brett Leatherman urged other suspected members to consider surrendering while the “choice is still yours”.
ShinyHunters first surfaced in France and have previously hacked prominent organisations such as Rockstar Games and an education platform, Canvas. The group claims to have exploited a vulnerability in the Oracle cloud storage system to infiltrate multiple FBI services, including background‑check, medical‑record and investigative databases.
The FBI’s public service announcement still characterises ShinyHunters as “threat actors” who often use exaggerated claims to elicit payment from victims. The agency warned that the group targets large companies across technology, finance and retail.

















