ShinyHunters member arrested in Amsterdam for cybercrimes and attempted incitement to murder
Quick Look
- A 24-year-old Amsterdam man, suspected of being an alleged leader of the cybercriminal group ShinyHunters, was arrested on September 15, 2026 in Amsterdam.
- Investigators found elements in his computer suggesting an attempt to incite two murders abroad.
- The group, active since 2019, is known for stealing data and demanding bitcoin payments, having targeted companies like Ticketmaster and AT&T.
AI-generated summary
Why It Matters
ShinyHunters is a cybercriminal group active since at least 2019, known for stealing databases and demanding payments in cryptocurrencies like bitcoin or monero. The group has targeted companies such as Ticketmaster, AT&T and Tokopedia, and is linked to other groups like Scattered Spider and Lapsus$.
Catch them all! On September 23, ShinyHunters posted a false notice of seizure on the FBI recruitment portal. The response came six days later. FBI Director Kash Patel announces with Dutch police the arrest of “one of the alleged leaders” of the group. He is a 24-year-old Amsterdammer. Your data may have already passed into the hands of this gang if you are a Ticketmaster or AT&T customer. And this group gets paid in bitcoin, a flaw that we explored in our analysis on the link between data leaks and crypto crime in France.
Arrest of a member of ShinyHunters in Amsterdam, and a much heavier case
The suspect was arrested on September 15, 2026. The information was only made public on September 29, the day the Rotterdam council chamber extended his pre-trial detention by 90 days. According to the Dutch police press release, he is suspected of participation in a criminal organization for his role within ShinyHunters.
What follows is more chilling. Investigators say they found elements in his laptop that support a second suspicion, that of attempted incitement to two murders abroad. Several storage media were seized from his home. The Dutch national prosecutor's office is leading the investigation and does not rule out other arrests.
The tone is martial on the American side. Kash Patel described on X ShinyHunters as a global cybercriminal group linked to attacks in the United States, the Netherlands and elsewhere. He adds that FBI teams are working “right now” with their partners to exploit new leads.
“This morning, the FBI and its partners at the Netherlands National Police announce the arrest of one of the suspected leaders of ShinyHunters, an international group of cybercriminals and malicious actors linked to cyberattacks in the United States, the Netherlands and around the world.
In coordination with FBI investigators, the Dutch Cybercrime Unit arrested the suspect under Dutch law. Currently, FBI teams are actively working with partners to obtain and exploit new leads in the ongoing investigation. We thank our partners at the Dutch National Police for their continued collaboration in this matter, as well as the industry partners who provided us with information. The investigation continues. -DKP🇺🇸»
ShinyHunters, from Pokémon to bitcoin racket
The name makes you smile. It refers to “chromatic” Pokémon, these extremely rare variants that players hunt for hours. The group has been hunting for databases since at least 2019. In 2020, it claimed 91 million accounts on the Indonesian platform Tokopedia. Four years later, the wave of intrusions via the poorly protected customer accounts of the data host Snowflake affected Ticketmaster, Santander and AT&T, which allegedly paid $370,000 to have stolen data erased.
The method hardly changes. The group steals, contacts the victim then demands payment in bitcoin within 72 hours. The file dedicated to it by the MITER ATT&CK reference base documents it in black and white. Threat profiles published by cybersecurity companies also list a Monero address, the so-called “privacy” crypto that blurs the lines much better than bitcoin. Due to lack of payment, the files end up on a leak site. The Dutch operator Odido experienced this in February 2026, threatened with having 21 million records published after refusing to pay.
After the FBIJobs affront, the hunt for ShinyHunters accelerates
One detail deserves your attention. The suspect was arrested eight days before the defacement of the FBIJobs site, and not in retaliation. ShinyHunters nevertheless claimed on September 23 to have data on “almost all FBI agents” and recruitment candidates. The claimed loot weighs 2 to 3 terabytes, sucked up thanks to an unknown flaw in Oracle PeopleSoft software. A sample consulted by the American press covered around 5,000 employees. Oddly enough, the group wasn't asking for money this time. He demanded that the FBI withdraw the warning issued about him in May 2026.
The Amsterdam dragnet is added to an already long list. Frenchman Sébastien Raoult, linked to the group, was sentenced to three years in prison in the United States in January 2024. Four alleged members were arrested in France in June 2025. The brand, however, survives each dragnet. ShinyHunters functions as a sign shared by several cells, similar to Scattered Spider and Lapsus$.
What to Watch
AI outlook — possibilities, not facts
New arrests linked to ShinyHunters will take place in the coming weeks.
Likely · Within weeks
The investigation into ShinyHunters will extend to other European and American countries.
Possible · Within months
Open Questions
- What is the real name of the suspect arrested in Amsterdam?
- What specific evidence supports the charge of attempted incitement to murder?
- Will the ShinyHunters group continue its activities despite this arrest?







