ShinyHunters Hacker Arrested After FBI and Dutch Investigation, Then Police Find Two Murder Orders on His Laptop

File Photo. Image Credit: Dorota Szymczyk / Shutterstock.

A suspected member of one of the world’s better-known cyber-extortion groups was already in Dutch custody when investigators opened his laptop and found material that, police say, widened the case far beyond stolen passwords and corporate databases.

Dutch National Police arrested a 24-year-old Amsterdam man on Sept. 15 on suspicion of participating in ShinyHunters, a hacking and extortion operation tied to attacks in the United States, the Netherlands and elsewhere. After examining his laptop, investigators said they found information concerning two killings that were supposed to take place abroad, along with indications that he had given instructions for them, leading to the additional suspicion that he had attempted to solicit two murders.

Dutch authorities say that allegation is separate from the ShinyHunters investigation.

The FBI highlighted the arrest Tuesday, crediting Dutch police and describing the case as an example of its new cyber strategy, in which the agency or country with the strongest legal authority and access takes the lead.

A Different Kind of Door

Embedded media follows; please allow a moment for it to load.

ShinyHunters has operated under that name for years, stealing corporate and customer data for sale or extortion. Federal prosecutors previously said members broke into company systems for proprietary information, personally identifiable information and financial records, while data attributed to the group from more than 60 companies was advertised for sale on dark-web markets between April 2020 and July 2021, with some victims also threatened with publication or sale of sensitive files if they refused to pay.

French national Sebastien Raoult later pleaded guilty in a U.S. case tied to the group and was sentenced in 2024 to three years in federal prison and more than $5 million in restitution.

Later ShinyHunters-branded campaigns have often depended on persuading employees to surrender or approve access rather than exploiting an obscure software flaw. The FBI has documented attackers posing as company IT workers and calling employees about supposed connectivity problems or automatically generated support tickets, then directing them to login pages, asking for credentials or convincing them to provide multifactor-authentication codes.

Other campaigns went further by persuading employees to authorize connected applications inside Salesforce, allowing attackers to query and export company data through legitimate platform functions. Google’s threat researchers found instances involving altered versions of Salesforce’s Data Loader or custom applications that, once approved, could obtain OAuth tokens issued by Salesforce itself, meaning access could persist even after a password reset because changing an employee’s password does not necessarily revoke permission already granted to a connected application.

Mandiant documented related campaigns in 2026 in which callers impersonated internal IT personnel, directed employees to company-branded credential-harvesting pages and sought single-sign-on credentials and MFA codes, sometimes using that access to enroll their own devices in the victim’s multifactor-authentication system.

Mandiant said those intrusions did not require a vulnerability in Salesforce or the other affected software because employees were persuaded to provide or approve the access themselves.

An unexpected support call should remain untrusted even when the caller knows an employee’s company, department, or software. Employees should not approve authentication codes, new MFA devices, or unfamiliar applications at the direction of an unsolicited caller; instead, they should end the call and contact their company’s IT department through an established internal number, help-desk portal, or other known channel. Mandiant recommends stronger identity protections, including phishing-resistant authentication, which can make stolen passwords and intercepted authentication codes considerably less useful.

Automotive World

Stellantis confirmed in September 2025 that attackers gained unauthorized access to a third-party platform supporting its North American customer-service operations. ShinyHunters claimed responsibility and said it obtained more than 18 million Salesforce records containing names and contact information, although Stellantis confirmed only that customer contact information was exposed and did not independently verify the group’s record count.

The company is the parent of Jeep, Ram, Dodge, and Chrysler, among other brands.

CarGurus disclosed another breach in 2026 involving customer names, email addresses, phone numbers and physical addresses, with Have I Been Pwned attributing the incident to ShinyHunters and reporting that approximately 12.5 million accounts were affected.

The group has also claimed attacks involving used-car retailer CarMax and vehicle-shopping site Edmunds, although those claims remain distinct from incidents the companies themselves have independently confirmed or attributed.

Earlier this month, ShinyHunters claimed it had obtained data from the Florida Department of Highway Safety and Motor Vehicles. Florida subsequently confirmed that an international cybercriminal organization accessed department data after obtaining credentials belonging to a Plant City Police Department user that state officials said had been improperly stored on the employee’s personal electronic device, although the state did not publicly identify ShinyHunters as the attacker.

After the Arrest

The Amsterdam suspect came to the attention of the Dutch National Investigation and Interventions Unit, while the country’s High Tech Crime Team investigates ShinyHunters under the National Public Prosecutor’s Office.

He was arrested on suspicion of participating in a criminal organization, and police seized several data-storage devices. Investigators examining his laptop said they found substantial information concerning two murders that were supposed to be carried out outside the Netherlands and indications that he had ordered the killings, which led to the additional suspicion of attempting to solicit two murders.

Police said the murder allegation is separate from the ShinyHunters investigation and clarified that he was not arrested as part of the investigation into the breach of Dutch telecommunications company Odido, which remains active.

Dutch authorities have not publicly named him.

A Rotterdam court ruled Tuesday that he will remain in pretrial detention for at least another 90 days as investigators continue examining the seized devices, and police said additional arrests remain possible.

The FBI said the Dutch High Tech Crime Unit made the arrest under Dutch law and credited industry partners that supplied information during the broader ShinyHunters investigation.

All parties are presumed innocent unless and until proven guilty in a court of law.

Leave a Comment

Flipboard