P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

ShinyHunters: one arrest 'in an investigation', one group 'claiming' a compromise, and 105 official words

The Dutch police say a 24-year-old man was arrested in an investigation into ShinyHunters, and the FBI says a group is claiming a compromise of its jobs portal. Neither text gives a role, a charge or a data volume, so this briefing separates what is stated from what is only reported or claimed.

By Parminder Kumar Sharma · · 19 min read

Editorial illustration for the briefing: ShinyHunters: one arrest 'in an investigation', one group 'claiming' a compromise, and 105 official words

105 words, and what they leave out

The Dutch police and the FBI each put out one short statement about ShinyHunters this week. The police one, posted on X on 28 September, is 40 words. The FBI's, published on fbi.gov on 23 September, is 65. That is 105 official words, counted for this briefing: hyphenated words count once and a long dash counts as a word break.

They are narrower than the coverage around them. The police say a 24-year-old man from Amsterdam was arrested this month "in an investigation into" the hacker group (my translation of the Dutch). The FBI says it is aware of a group "claiming a compromise" of the fbijobs.gov portal, with "alleged impact" on employee personal data. Neither text gives a name, a charge, a quantity of stolen data or a method. The FBI's 65 words contain no figure, no system name, and neither the word "confirmed" nor the word "stolen".

Everything else this week is reporting from unnamed sources, or the group speaking for itself: the suspect's name, the 2 to 3 TB, the 60,000 people, the motive, the internal feud. This briefing keeps the three apart, because a defender who blends them will either panic on a claim or relax on an arrest. It builds on two earlier pieces about the same group, the Grav flaw behind the Clop leak site defacement and the PeopleSoft firewall bypass, and does not repeat them.

The two official statements: the Dutch police post on X of 28 September (translation mine) and the FBI press release of 23 September

StatementOn the recordNot stated
Dutch police, national investigations unit, X, 28 September (40 words)A 24-year-old man from Amsterdam was arrested this month in an investigation into ShinyHunters. He appears before the raadkamer of the Rotterdam court on 29 September. More information promised for that day.His name. The charge. The arrest date. Whether he is a member and what he is suspected of doing. Any link to the Odido breach or to the FBI matter.
FBI, fbi.gov, 23 September (65 words)Aware of a group claiming a compromise of the fbijobs.gov portal and alleged impact on employee personal data. Point of breach undetermined: a third party or the FBI's own enterprise. Investigating with the portal's third-party providers.That data was taken. How much, whose, from which systems. How the intruder got in. Anything about the group's other claims.

Two things follow at once. An official silence is not a denial: the FBI says it is "actively and aggressively investigating", and the Dutch police have promised more information on 29 September. But an official silence is not a confirmation either. Where the record is thin, the honest label is "not stated", and each table in this briefing keeps a column for it.

I checked politie.nl and the Public Prosecution Service's news page on the morning of 29 September and did not find the follow-up the police promised for that day. If it has appeared since, it supersedes what this briefing says about the arrest.

Each development can be written as a ladder of claims, from the cheapest to establish at the top to the most expensive at the bottom. The evidence on both stories reaches about the same height: something happened, the authorities acknowledge it, and then the rungs that would settle the question are empty, pending, or held by a party with an interest.

Two ladders of six rungs each. Dutch arrest: arrest stated by police, custody pending before a court chamber on 29 September, and charge, role in ShinyHunters, link to the FBI or Odido matter and conviction not stated. FBI portal claim: claim made by the group, investigation acknowledged by the FBI, sample data reported genuine by journalists, data taken not stated, point of breach undetermined, scale only the group's figures.
Drawn from the Dutch police post of 28 September, the FBI statement of 23 September and the press reports cited in this briefing.

An arrest is a step in a procedure, not a finding

The Dutch judiciary describes what happens next in plain terms. Pre-trial detention (voorlopige hechtenis) means the suspect is held while waiting for the judge's decision in the criminal case. It has two phases: bewaring, ordered by an investigating judge for up to 14 days, and then gevangenhouding, which the prosecutor asks the court to order. On 29 September the man is due before the court's raadkamer, which AT5 reports will decide whether he stays in custody. Among the tests the judiciary lists is that the suspicion against him must be solid ("stevig"). Solid suspicion is a threshold for holding someone. It is not a finding of guilt, and if a court later acquits, the detention ends.

The police did not name him and have not said what he is suspected of. Dutch and international outlets, citing unnamed sources, have named a man. This briefing does not repeat the name: no court has ruled, and the one official text does not carry it.

Three things the statement does not carry, and which the surrounding coverage tends to fill in:

  • The Odido link. The police statement does not mention Odido. On 7 September the police published the voice of a man suspected in the Odido hack, a caller who posed as an IT colleague and got an employee to enter credentials and a verification code on a fake login page. The group then told Dutch media the man in that recording is one of its members. No official source says the arrested man is that caller, and the report, relayed by BleepingComputer, that people who know him doubt the voice matches is third-hand and untested.
  • The FBI link. The arrest was in September and the FBI claim followed within days. That is a sequence, and nothing the police have said ties the two. KrebsOnSecurity, citing unnamed sources, offers a story about a feud over control of the group's brand. The group offers a story about retaliation. Neither is on any official record.
  • The denial. The group told BleepingComputer the arrested man has "no association with us", and told Dutch media much the same. That denial comes from the same voice that claims the FBI breach. Either both statements are evidence or neither is, and I treat both as claims.

Does one arrest touch the group? Nothing official gives the group's size. BleepingComputer wrote in 2025 that ShinyHunters was believed to be several actors operating under one name, and reported, citing Le Parisien, that French police had arrested four people in June of that year, one of them using the ShinyHunters handle. That was more than a year before this arrest, and the group's 2026 activity since is what this week's stories are about. The group itself told The Register that it has seen the "majority" of GnosticPlayers members arrested, the name it says it used before 2020. That is a self-description, unverified, and no more than that.

The reported arrest date is 15 September, from BleepingComputer citing DataBreaches and from a Reuters interview relayed by the Dutch news agency ANP. The police say only "this month", and KrebsOnSecurity's sources say on or around 16 September. Counting from the reported date: the Clop leak site was defaced on 18 September (day 3, attributed to ShinyHunters in the earlier Grav briefing). The group says it entered the FBI portal on the Monday night, 21 September (day 6), and went to the press on 22 September (day 7). Mandiant published its report of renewed mass exploitation on 25 September (day 10). Every day count here is derived from a date the police have not confirmed.

Those counts show that the group's public activity did not pause. They do not show that the arrest made no difference, or that the same people did all of it.

What the Dutch police statement (X, 28 September) and the judiciary's description of pre-trial detention support

The arrest establishesIt does not establish
Dutch police arrested a 24-year-old man from Amsterdam in September, in an investigation into ShinyHunters.That he is a member, or what he is suspected of doing.
A court chamber in Rotterdam hears his custody on 29 September.That he has been charged, or convicted of anything in this case.
The investigation has reached the stage of custody, and the police intend to say more.That the group is smaller, slower or disrupted.
Nothing more than that.That the arrest relates to the Odido breach or to the FBI portal.
Nothing more than that.That the FBI claim is true, or false.

Fifteen days, and who vouches for each step

The diagram puts the fifteen days on one axis and colours each event by who is vouching for it. The colours matter more than the dates. An event vouched for by an authority is a different kind of fact from one vouched for by the group that benefits from being believed.

The group's own deadline for the FBI is drawn hollow because it is derived. BleepingComputer and the BBC report that the group gave the bureau one week to correct or remove its May advisory. The BBC adds that the group would otherwise publish the data; BleepingComputer reports that when asked, the group declined to say whether it would. One week from 22 September is 29 September, and a later BBC report of "five days" points to 30 September. I did not read the group's statement, so the deadline rests on those reports. If data appears after this briefing is published, it will not be linked from here.

A dot plot of events from 15 to 30 September 2026, coloured by evidence tier. Dutch case: arrest 15 September as reported, police statement 28 September, court chamber hearing 29 September. FBI claim: Clop leak site defaced 18 September, claimed entry 21 September, claim to press and FBI acknowledgement 22 September, FBI statement 23 September, Mandiant report 25 September with no FBI mention, group's bypass claim 26 September, group's derived deadline 29 to 30 September.
Drawn from the police post, the FBI statement, Mandiant and GTIG, and the press reports cited in this briefing. The arrest date and the deadline are not official.

Claimed, acknowledged, sampled: three different things

On 22 September the group told BleepingComputer and The Register that it had entered the FBI's jobs site the previous night through a PeopleSoft flaw, moved onto FBI-managed servers in AWS GovCloud, and taken 2 to 3 TB. It told 404 Media it held data on "all FBI employees and applicants". That is a claim. The same day the FBI told BleepingComputer it was "aware of claims regarding unauthorized activity" affecting the portal and "currently investigating". That is an acknowledgement of an investigation. On 23 September it published the longer statement quoted above.

Outlets then read those words in several different ways.

How outlets described the same FBI wording (The Register and the BBC, 25 September; BleepingComputer, 26 September; KrebsOnSecurity, 28 September)

OutletWhat it wrote about the FBI
The RegisterThe FBI "confirmed the breach" to the outlet.
The BBC, body textThe FBI "acknowledged the breach" on the Wednesday.
The BBC, headlineTest results "stolen in FBI hack". The body text says the criminals "say they have" the data.
KrebsOnSecurityThe FBI issued a brief statement "confirming the hack".
BleepingComputerThe FBI did not confirm its systems were breached or that data was stolen.

The FBI's text says it is aware of a group "claiming a compromise", of "alleged impact", and that "the point of breach is still undetermined". The strongest phrase in it is "point of breach", which treats a breach of something as the working assumption while leaving open whether it was "a third-party or the FBI's enterprise". That is more than a bare "we are aware of claims". It is still not a statement that data was taken, how much, or whose. Reasonable readers differ. BleepingComputer's reading is the most literal and the Register's the most generous. For anything you would put in a board paper, quote the literal one. (The FBI's original text uses dashes, so the phrases are quoted separately here.)

The same table exercise works on the group's own claims, one row at a time.

What the group claims, what the FBI has stated about each item, and what others have checked, as of 29 September

The group claimsThe FBI has statedChecked by others
Entry through a PeopleSoft flaw on the jobs site.A compromise is claimed. Point of breach undetermined: third party or FBI enterprise.Mandiant's 25 September report does not mention the FBI. The group told BleepingComputer on 26 September that it used the firewall bypass Mandiant describes, and still claims a second, new bug in the same component.
2 to 3 TB taken from FBI-managed servers on AWS GovCloud.Nothing.Nothing found.
Data on all employees and applicants, later about 60,000 current and former staff.Nothing on scope.The BBC gives the bureau's staff as about 38,000. 404 Media's sample held about 5,000 records, per BleepingComputer.
Sample records with home addresses, phone numbers and medical examination details.Alleged impact on employee personal data.The BBC says samples shared with journalists "appear genuine". 404 Media told BleepingComputer some details were accurate. Reuters examined documents, per KrebsOnSecurity.
Access to HR, medical, criminal justice and investigative systems.Nothing.Nothing found beyond the group's own list.

The samples matter. Several outlets that examined them say they appear genuine, which is real evidence that some authentic personal data is in the group's hands. It is not evidence of where it came from. The FBI itself does not yet say whether the point of breach was a supplier or its own systems, and a jobs portal run by a supplier can hold a great deal of real personal data without touching an investigative system. The BBC describes fitness-for-work medical records among the samples it saw. That fits a claim of HR-side data, and by itself does not show access to investigative systems. That last step is my inference, not a finding.

The scale moved too. On 22 September the claim was 2 to 3 TB and data on all employees and applicants. By 25 September the BBC reported that the group said it had underestimated and now claimed about 60,000 current and former staff. Claimed scope rose. Confirmed scope did not change, because none has been stated.

One thing I could check myself. At about 10:15 UTC on 29 September, a plain request to apply.fbijobs.gov, the address named in the claim, was answered with a redirect to the fbi.gov home page. The Register saw a maintenance message on 22 September and reported the portal still down on 25 September. That says the portal is not serving as normal. It says nothing about why, or about what was taken.

The entry method moved as well. On 22 September the group said a new, unpatched PeopleSoft zero-day. On 25 September it told The Register the flaw still had no patch. On 26 September it told BleepingComputer it had used the encoded-path bypass against FBI Jobs, while still claiming a new flaw in the same component. KrebsOnSecurity on 28 September says the group named CVE-2026-35273, the flaw Oracle patched on 10 June.

If the later account is right, the FBI's jobs portal, or its provider, is the case in the earlier briefing: a path-based mitigation standing in for a patch, 104 days after Oracle's fix (10 June to 22 September, derived). If the earlier account is right, there is an unpatched flaw in a widely used product. Only Oracle, the FBI or the portal's provider can say which. None has, in anything I read, and The Register reported that Oracle had not responded.

What a stated motive tells a defender

The headline motive is the group's: "This is NOT financially motivated", it told The Register on 22 September. Three days later it told the same outlet: "We are just protecting our business as any other business would do." It called the FBI intrusion "fundamentally a public relations and marketing initiative for our business". It said it expects "future corporate partners we engage with for payment" to read the documentation and take the group for "serious, results-driven professionals".

The Register's own gloss is that most people call those partners victims. The BBC reports that the group is not asking the FBI for money but for a retraction, and says the group would otherwise publish. BleepingComputer reports that the group declined to say. The group says the demand is not extortion. Whether it is, is a matter for prosecutors and makes no difference to a defender.

A comforting label is not a control. "Not financially motivated" sounds like lower risk. By the group's own account it describes what was asked of the FBI, not the business the intrusion advertises. The group's picture of itself as "professional and predictable" is also marketing, and nobody should price a risk on a self-description. I take these words as a record of what the group says, not of what is so.

What the group's stated motive tells a defender, and what it does not

It does tell youIt does not tell you
The group needs its claims believed. It says so: bringing a corporate to the table takes "a lot of convincing" if the company thinks it is being bluffed.Whether any given claim, including this one, is exaggerated. The FBI's May advisory warns of "real or exaggerated claims of access".
By the group's account, a public statement about it can draw a response. The FBI's May advisory is the stated cause.That this is a pattern. It is one incident, and the account is the group's.
The FBI intrusion was, in the group's words, advertising aimed at future victims.Which victims are next. "Protect our business" is not a filter on targets.
That the group is willing to talk to journalists at length, which gives you claims to test.How it got in. Technique evidence is Mandiant's, and covers dozens of systems in seven sectors, government among them.

Method belongs apart from accusation. The FBI's May advisory is an assertion about the group's tactics: harassment of victims and their families, swatting, and false claims of compromising material. The group denies it. Neither side has published evidence for or against in anything I read, and this briefing takes no position on that dispute. It matters here for one reason. It is the group's stated reason for the FBI intrusion, and a defender should note that the reason is a dispute about credibility.

Two interests to state without sneering. Mandiant sells incident response, so its post is a primary source on technique and is silent on the FBI. And every outlet quoted here gained an exclusive by carrying the group's words, which also serves the group's stated purpose. That is a reason to read the quotes as statements, not findings.

The defender's conclusion is narrower and more useful. A claim about your data is a hypothesis with a cost to test, made by a party who gains if you believe it. Both errors are expensive: acting on a bluff and ignoring a real theft. What separates them is your own evidence, not the claimant's confidence and not a stranger's assessment of its motive.

What to do about it

Nothing in the Dutch statement changes a technical control, and the FBI text does not say how anyone got in. So this list does not wait for either. The legal point in the fourth item is general guidance, not legal advice, and it draws on the ICO's breach guide and the Article 29 Working Party guidelines it points to.

Take this with you

In the order worth doing

  • Find every PeopleSoft instance you run or that a supplier runs for you, including recruitment, careers and HR portals. Confirm each has Oracle's 10 June Security Alert for CVE-2026-35273 applied. A firewall rule is not a substitute, as the earlier briefing sets out.
  • Ask each supplier in writing who hosts and patches the portal, at what version, and how quickly they would tell you of a suspected intrusion. The FBI's own statement shows the ownership question can stay open for days.
  • Hunt your PeopleSoft web logs for the Environment Management Hub path in every encoded spelling, and on every node, using the detail in the earlier briefing.
  • Write down who may declare that you are aware of a breach, and on what evidence. The UK GDPR gives 72 hours from becoming aware, with information allowed in phases. The Working Party guidelines say a controller told of a potential breach by a media organisation or another source may run a short investigation first, and may not be regarded as aware during it. That investigation is expected to begin as soon as possible and to reach a reasonable degree of certainty. A message from a group starts that investigation, not the notification, and not investigating is how a claim could become a failure to notify.
  • Decide in advance how you will test a claim about your data without touching a leak site or downloading stolen personal data. Use your logs, your suppliers' logs and counsel. Follow the FBI's May advice to people contacted by the group: verify unusual requests through another channel, and do not send payment or respond to demands.
  • Inventory the applicant and employee data your portals hold, and cut retention. The reporting describes medical examination records among the samples, and the general point is that HR data ends up wherever the workflow puts it, which is not a finding about the FBI's systems. Data you no longer hold cannot be claimed.
  • Brief staff and executives that extortion pressure can reach individuals. The FBI's advisory says the group harasses victims and their families. The group denies it. Prepare for it either way.
  • Do not relax because of the arrest, and do not escalate because of the motive. Neither is evidence about your exposure. Your exposure is what your own logs, patch records and supplier answers say.

The question this leaves

On 23 September the FBI said it did not yet know whether the point of breach was a third-party provider or its own enterprise. That statement is the latest official word I could find. An agency with a full investigative arm began by saying it could not yet say whose systems were the entry point.

So the question is for your own estate. If your careers portal were named on a leak site this afternoon, could you say by tonight whether the point of breach was yours or a supplier's, and who would have to answer for the answer?

Sources

  1. PrimaryThe police post of 28 September confirming the arrest of a 24-year-old man from Amsterdam in an investigation into ShinyHunters, the raadkamer date of 29 September and the promise of more information. The one official text on the arrest; read in Dutch and translated.Politie Landelijke Opsporing en Interventies (Dutch police)accessed 2026-09-29
  2. PrimaryThe 7 September release publishing the voice of a man suspected in the Odido hack, used for what the police say about that investigation and to show it is separate from the 28 September statement.Politie (Dutch police)accessed 2026-09-29
  3. PrimaryHow pre-trial detention works: bewaring for up to 14 days, then gevangenhouding decided by the court, with the test that the suspicion must be solid. Used to say what a raadkamer hearing is and is not.Rechtspraak (the Dutch judiciary)accessed 2026-09-29
  4. PrimaryThe FBI's 23 September statement on the fbijobs.gov portal, read in full (65 words). Read with a browser because curl met a bot check, which was not bypassed.Federal Bureau of Investigationaccessed 2026-09-29
  5. PrimaryThe 15 May 2026 public service announcement on ShinyHunters that the group says prompted the FBI intrusion. Read through an Internet Archive capture of 27 September; used for the FBI's description of the group's tactics and its advice.FBI Internet Crime Complaint Centeraccessed 2026-09-29
  6. PrimaryShinyHunters renewed mass exploitation targeting Oracle PeopleSoft, 25 September 2026. Used for the technique, the dozens of systems in seven sectors, the 10 June Oracle alert, and to confirm the report does not mention the FBI.Mandiant and Google Threat Intelligence Groupaccessed 2026-09-29
  7. PrimaryPersonal data breaches: a guide. Used for the 72 hours from becoming aware, phased reporting under Article 33(4), and the pointer to the Article 29 Working Party guidance on when a controller is aware.Information Commissioner's Officeaccessed 2026-09-29
  8. PrimaryGuidelines on personal data breach notification (WP250 rev.01, last revised 6 February 2018), section II. Used for when a controller becomes aware and the short period of investigation after a media or other report.Article 29 Data Protection Working Partyaccessed 2026-09-29
  9. Reported by22 September report of the claim, with the group's statements on motive and the May advisory. Secondary: the group's words as relayed to a reporter.The Registeraccessed 2026-09-29
  10. Reported by25 September interview with the group, used for the motive quotes, the GnosticPlayers history claim and the FBI quote as the outlet printed it. Secondary.The Registeraccessed 2026-09-29
  11. Reported by22 September report of the claim, the FBI's first statement to the outlet, the sample records and 404 Media's verification, and the one-week demand. Secondary.BleepingComputeraccessed 2026-09-29
  12. Reported by26 September report that the group told the outlet it used the firewall bypass against FBI Jobs while still claiming a new flaw, and that the FBI had not confirmed a breach or data theft. Secondary.BleepingComputeraccessed 2026-09-29
  13. Reported by28 September report of the police statement, the reported arrest date of 15 September, and the group's denial of any association with the arrested man. Secondary. It names the suspect and this briefing does not.BleepingComputeraccessed 2026-09-29
  14. Reported by23 September report that the FBI is investigating the claim, the bureau's staff numbering about 38,000, and the group's one-week demand. Secondary.BBC Newsaccessed 2026-09-29
  15. Reported by25 September report of medical records in the samples, the group's revised figure of about 60,000 staff, and the wording that the FBI acknowledged the breach. Secondary.BBC Newsaccessed 2026-09-29
  16. Reported by28 September report citing unnamed sources on the arrest timing, an alleged feud over the group's brand, the group's reported use of CVE-2026-35273 against the FBI site, and Reuters and 404 Media findings. Secondary, and it names the suspect; this briefing does not.KrebsOnSecurityaccessed 2026-09-29
  17. Reported by29 September report of the group's statement to BNR that the arrested man has nothing to do with it. Secondary.NL Timesaccessed 2026-09-29
  18. Reported by8 September report that the group told BNR the man in the police audio clip is a member and that a lawyer was arranged. Secondary.NL Timesaccessed 2026-09-29
  19. Reported by28 September Dutch report embedding the police post and stating that the raadkamer decides whether he stays in custody. Secondary.AT5accessed 2026-09-29
  20. Reported by28 September ANP report used for the 15 September raid date given in a Reuters interview and the group's denial to Dutch media. Secondary.Reformatorisch Dagblad (ANP)accessed 2026-09-29
  21. Reported by25 June 2025 report, citing Le Parisien, of French arrests of BreachForums operators including one using the ShinyHunters handle, and the view that the group is several actors under one name. Secondary.BleepingComputeraccessed 2026-09-29

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.