Skip to content
TECH CEO Daily

FBI warns ShinyHunters 'we know how to find you' as Dutch police cite murder plans

After Dutch police announced the arrest of an alleged ShinyHunters leader, the FBI said the group has breached over 140 organizations and collected at least $70 million.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1The FBI told remaining ShinyHunters members to reach out first after Dutch police announced the arrest of an alleged leader.
  • 2The FBI says the group and alleged co-conspirators breached over 140 organizations and collected at least $70 million in extortion.
  • 3A soldier's 70-month sentence and a $16 million crypto fraud charge show enforcement speeding up; extortion attempts have not stopped.

Video summary · 0:52

Watch: FBI warns ShinyHunters 'we know how to find you' as Dutch police cite murder plans

The story in under a minute, with captions. Tap to play with sound.

Video summary · Voiced with a synthetic voice.

The news

The FBI publicly warned remaining ShinyHunters members to come forward in a video released September 29, 2026, after Dutch police announced the arrest of a man the FBI called one of the group's alleged leaders, BleepingComputer and The Register reported.

"You know how to find us, and we know how to find you," said Brett Leatherman, assistant director of the FBI's Cyber Division, according to BleepingComputer. He urged members to reach out while the choice was still theirs. The Register reported that Leatherman also said arrests tend to change who is willing to talk, and that seized infrastructure reveals who is left. FBI Director Kash Patel said on X that the bureau assisted Dutch investigators, The Register reported.

Dutch police said the suspect is a 24-year-old man from Amsterdam who was arrested on September 15, according to BleepingComputer. Police said on September 29 that information found on his laptop included details about two murders that were to be committed abroad, and that there are indications he gave the order, both outlets reported. The Rotterdam District Court ruled the same day that he will stay in pre-trial detention for at least another 90 days, BleepingComputer reported.

The FBI says ShinyHunters and its alleged co-conspirators have breached more than 140 organizations since last year and collected at least $70 million in extortion payments, according to BleepingComputer. The group has claimed a breach of the FBI itself through what it calls an Oracle PeopleSoft zero-day, and says that attack was not financially motivated, BleepingComputer and The Register reported. Google researchers said the hackers may be referring to a modified exploit for CVE-2026-35273, an already-patched PeopleSoft flaw, rather than a new zero-day, SecurityWeek reported.

The warning capped days of enforcement actions. On September 25, former U.S. Army soldier Cameron Wagenius was sentenced to 70 months in prison and ordered to pay $294,978 in restitution for a hacking and extortion scheme that targeted at least 10 organizations, the Justice Department said. On September 24, U.S. authorities arrested Vietnamese national Trung Nguyen Van, 37, at Los Angeles International Airport before he could board a flight to Taiwan, BleepingComputer reported. He is charged with money laundering tied to a pig butchering scam, which lures victims into fake crypto investments, in which one victim lost about $16 million. The charge is an allegation, and he has not been convicted.

The numbers

Organizations breached by ShinyHunters and alleged co-conspirators since last year, per FBI
More than 140
Extortion payments collected, per FBI
At least $70 million
Further pre-trial detention ordered for Dutch suspect
At least 90 days
Cameron Wagenius prison sentence / restitution
70 months / $294,978
Crypto lost by one pig butchering victim
About $16 million
Crypto received by Van's wallets from U.S. fraud schemes, per court documents
About $53,275,939

Why CEOs should care

An arrest does not end the threat to victims. ShinyHunters claimed the FBI breach on September 22, TechCrunch reported, a week after the Amsterdam suspect's arrest, and the FBI's own figures show at least $70 million paid to the group and its alleged partners. General counsels and CISOs should keep a data-extortion playbook ready: who decides whether to engage, which outside counsel and forensic firm are on retainer, how stolen data will be verified, and when regulators and customers must be told.

Leatherman's message is also a signal to victims. Seized infrastructure and cooperating suspects give investigators leads, and reports from victims add to them. Boards should ask whether the company knows its local FBI field office contact before an incident, and whether the incident plan commits to reporting extortion attempts rather than handling them quietly.

For CFOs, the pig butchering case is a reminder that crypto moves fast but leaves a trail. BleepingComputer reported that the $16 million victim's funds were traced to Van's wallet. Any organization that holds or pays in cryptocurrency should have a process to report theft to law enforcement and exchanges within hours.

Companies running Oracle PeopleSoft have a more immediate step: Google advises applying Oracle's patches for CVE-2026-35273, since the group has bypassed web application firewall rules that some organizations used instead of patching, SecurityWeek reported.

The bigger picture

Prosecutors and police are adding visible costs for cybercriminals, including people who committed crimes while serving in the U.S. military. Wagenius was an active-duty Army soldier when he hacked and extorted telecom companies, The Record reported. On September 25, two former Air Force members received a combined 189 months for business email scams run while they were stationed at Dover Air Force Base, The Record reported. Court documents in Van's case say his wallets received about $53,275,939 in crypto from wire fraud schemes targeting U.S. citizens between February 2018 and December 2024, BleepingComputer reported.

What’s next

The Dutch suspect will stay in pre-trial detention for at least 90 more days, and the FBI's warning suggests it expects more ShinyHunters members to be identified. Companies should not wait for that: extortion crews have kept operating through past arrests, so leak-response plans, tested backups of sensitive data and clear payment decision rules belong in place now.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

ShinyHuntersFBIDutch National PoliceData extortion

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.