The news
The FBI publicly warned remaining ShinyHunters members to come forward in a video released September 29, 2026, after Dutch police announced the arrest of a man the FBI called one of the group's alleged leaders, BleepingComputer and The Register reported.
"You know how to find us, and we know how to find you," said Brett Leatherman, assistant director of the FBI's Cyber Division, according to BleepingComputer. He urged members to reach out while the choice was still theirs. The Register reported that Leatherman also said arrests tend to change who is willing to talk, and that seized infrastructure reveals who is left. FBI Director Kash Patel said on X that the bureau assisted Dutch investigators, The Register reported.
Dutch police said the suspect is a 24-year-old man from Amsterdam who was arrested on September 15, according to BleepingComputer. Police said on September 29 that information found on his laptop included details about two murders that were to be committed abroad, and that there are indications he gave the order, both outlets reported. The Rotterdam District Court ruled the same day that he will stay in pre-trial detention for at least another 90 days, BleepingComputer reported.
The FBI says ShinyHunters and its alleged co-conspirators have breached more than 140 organizations since last year and collected at least $70 million in extortion payments, according to BleepingComputer. The group has claimed a breach of the FBI itself through what it calls an Oracle PeopleSoft zero-day, and says that attack was not financially motivated, BleepingComputer and The Register reported. Google researchers said the hackers may be referring to a modified exploit for CVE-2026-35273, an already-patched PeopleSoft flaw, rather than a new zero-day, SecurityWeek reported.
The warning capped days of enforcement actions. On September 25, former U.S. Army soldier Cameron Wagenius was sentenced to 70 months in prison and ordered to pay $294,978 in restitution for a hacking and extortion scheme that targeted at least 10 organizations, the Justice Department said. On September 24, U.S. authorities arrested Vietnamese national Trung Nguyen Van, 37, at Los Angeles International Airport before he could board a flight to Taiwan, BleepingComputer reported. He is charged with money laundering tied to a pig butchering scam, which lures victims into fake crypto investments, in which one victim lost about $16 million. The charge is an allegation, and he has not been convicted.
The numbers
- Organizations breached by ShinyHunters and alleged co-conspirators since last year, per FBI
- More than 140
- Extortion payments collected, per FBI
- At least $70 million
- Further pre-trial detention ordered for Dutch suspect
- At least 90 days
- Cameron Wagenius prison sentence / restitution
- 70 months / $294,978
- Crypto lost by one pig butchering victim
- About $16 million
- Crypto received by Van's wallets from U.S. fraud schemes, per court documents
- About $53,275,939
Why CEOs should care
An arrest does not end the threat to victims. ShinyHunters claimed the FBI breach on September 22, TechCrunch reported, a week after the Amsterdam suspect's arrest, and the FBI's own figures show at least $70 million paid to the group and its alleged partners. General counsels and CISOs should keep a data-extortion playbook ready: who decides whether to engage, which outside counsel and forensic firm are on retainer, how stolen data will be verified, and when regulators and customers must be told.
Leatherman's message is also a signal to victims. Seized infrastructure and cooperating suspects give investigators leads, and reports from victims add to them. Boards should ask whether the company knows its local FBI field office contact before an incident, and whether the incident plan commits to reporting extortion attempts rather than handling them quietly.
For CFOs, the pig butchering case is a reminder that crypto moves fast but leaves a trail. BleepingComputer reported that the $16 million victim's funds were traced to Van's wallet. Any organization that holds or pays in cryptocurrency should have a process to report theft to law enforcement and exchanges within hours.
Companies running Oracle PeopleSoft have a more immediate step: Google advises applying Oracle's patches for CVE-2026-35273, since the group has bypassed web application firewall rules that some organizations used instead of patching, SecurityWeek reported.
The bigger picture
Prosecutors and police are adding visible costs for cybercriminals, including people who committed crimes while serving in the U.S. military. Wagenius was an active-duty Army soldier when he hacked and extorted telecom companies, The Record reported. On September 25, two former Air Force members received a combined 189 months for business email scams run while they were stationed at Dover Air Force Base, The Record reported. Court documents in Van's case say his wallets received about $53,275,939 in crypto from wire fraud schemes targeting U.S. citizens between February 2018 and December 2024, BleepingComputer reported.
What’s next
The Dutch suspect will stay in pre-trial detention for at least 90 more days, and the FBI's warning suggests it expects more ShinyHunters members to be identified. Companies should not wait for that: extortion crews have kept operating through past arrests, so leak-response plans, tested backups of sensitive data and clear payment decision rules belong in place now.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







