Dutch National Police arrest member of group that claimed to have hacked FBI

The FBI and Dutch National Police said Tuesday they had arrested a suspected member of the notorious cybercrime group ShinyHunters, which claimed responsibility for defacing the FBI’s jobs website last week and boasted that it had stolen information on FBI employees and job applicants.

Dutch police said the suspect is a 24-year-old Amsterdam resident who was arrested on September 15 on suspicion of belonging to ShinyHunters. His arrest came days before the group claimed it had hacked the FBI’s jobs website, an incident first reported by 404 Media on Sept. 22.

Dutch authorities also accuse the man of attempting to incite two murders.

Police seized several data-storage devices and said additional arrests could follow. Investigators found a large volume of information on the suspect’s laptop, including details about two murders allegedly intended to take place abroad. The suspect is being held in isolation and is expected to remain in pretrial detention for at least 90 days, authorities said.

Brett Leatherman, assistant director of the FBI’s Cyber Division, said Tuesday that Dutch authorities had the FBI’s “full support.”

“Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments,” Leatherman said. “They often target third-party vendors and cloud-based platforms, stealing sensitive data and extorting victims with threats to publish it.”

In a post on X, FBI Director Kash Patel did not identify the individual who was arrested, but referred to the person as “one of the alleged leaders” of the organization. “As we speak FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest,” Patel wrote.

The FBI said in a statement that it was “working around the clock to investigate the cyber incident involving FBIJobs.gov” and remained in regular contact with anyone who may have been affected, including through multiple bureau-wide communications issued within 24 hours of the incident becoming public. The investigation remains ongoing.

Last week, ShinyHunters claimed in dark-web posts and messages to several media outlets that it had stolen between two and three terabytes of data linked to FBI and Justice Department employees. The group said it exploited a newly discovered vulnerability in Oracle PeopleSoft, a human resources management system.

In one post published last Tuesday, the group addressed FBI Director Kash Patel and Leatherman, declaring: “We have compromised the FBI.”

The hackers claimed to hold sensitive information on nearly all FBI agents, along with people who had applied for jobs at the bureau. They said criminal justice, human resources and Medlink systems were among the services affected.

On Monday, The New York Times reported that FBI employees had received an internal email identifying the incident as a cybersecurity breach and acknowledging that personal information belonging to some employees had been stolen.

According to a source familiar with the internal communication, the security notice confirmed that hackers had obtained employee information. A sample of the data was shared with select members of the media.

The FBI told employees that multiple divisions were investigating the breach and coordinating assistance for those affected.

Employees were urged to take additional security precautions and report any suspicious contacts, harassment or threats they might receive.

The internal message also said the bureau was assessing additional identity-protection and related support services for affected employees and their families.

An FBI spokesperson declined to discuss the notice’s contents but said the bureau had remained in constant communication with employees since the incident. The spokesperson added that the FBI was providing notifications and updates as more information became available.

Leave a Reply

Your email address will not be published. Required fields are marked *