ShinyHunters Under Pressure: Who They Are, Who Has Been Arrested, and What Comes Next


Figure 1. Data theft and an international investigation.
Note. Original AI-generated editorial illustration; this image does not depict an actual arrest.
Updated October 11, 2026. This article covers publicly documented developments; an arrest or allegation is not a conviction.
A stolen database does not stay inside the company that lost it. It can become a sales listing, an extortion demand, or the script for the next convincing phone call. That is what makes ShinyHunters worth understanding: the damage can continue long after an attacker’s original access is shut down.
Recent arrests have put the group back in the headlines. But those headlines combine several different stories: a convicted participant from the early operation, suspects connected to a stolen-data forum, and a new international investigation. Here is what the public record actually supports.
Who Are ShinyHunters?
The FBI describes ShinyHunters as a cybercriminal group specializing in large-scale data theft and extortion. The business model is straightforward: obtain information that matters to a victim, then sell it or threaten to publish it. Its May 2026 advisory also describes pressure tactics such as threats and harassment directed at victims and family members (Federal Bureau of Investigation [FBI], 2026).
Attribution needs care. Google tracks UNC6040 intrusion activity separately from UNC6240 follow-on extortion, which has claimed the ShinyHunters name. A tracking label or an extortion signature is not a verified membership roster (Google Threat Intelligence Group, 2025).
How the Attacks Work
Some of the most instructive cases start with a person being persuaded to authorize access. The FBI’s September 2025 Salesforce advisory describes callers impersonating IT support, obtaining credentials or MFA codes, and persuading employees to approve malicious connected applications. Once approved, an application’s OAuth tokens can let an attacker query and export data through legitimate interfaces (FBI, 2025).
This is why a familiar login page or an apparently legitimate integration can still be dangerous. The security decision is also about what permissions are being granted, by whom, and for what purpose. My takeaway: treat a request to connect an application with the same care as a request to hand over a password.
Who Has Been Arrested—and Why?
The entries below distinguish confirmed official statements from attributed reporting. They are not a complete membership roster, and the related forum arrests should not be added together as a verified count of ShinyHunters members.
Sébastien Raoult: A Confirmed Conviction
Raoult, known as “Sezyo Kaizen,” was arrested in Morocco in 2022 and extradited to the United States in January 2023. He pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft. On January 9, 2024, a federal court sentenced him to three years in prison and more than $5 million in restitution. The Justice Department linked his role to phishing sites, stolen credentials, data theft, and sales of stolen information under the ShinyHunters identity (U.S. Attorney’s Office, Western District of Washington, 2024).
Four French Forum Suspects: A Related 2025 Case
In June 2025, reporting identified four people detained in France under the aliases ShinyHunters, Hollow, Noct, and Depressed. They were suspected of administering BreachForums, a marketplace for stolen data, and were linked in reporting to investigations of major French data breaches. Their legal names were not supplied in that report. This is relevant to the ecosystem around ShinyHunters, but it does not establish that every forum administrator belonged to the same hacking crew (Antoniuk, 2025).
The Netherlands: September 15, 2026
Dutch police officially confirmed the arrest of a 24-year-old Amsterdam man on suspicion of participation in a criminal organization associated with ShinyHunters. Police seized devices, and on September 29 a Rotterdam court extended his pretrial detention by 90 days. The police statement says he was not arrested as part of the Odido breach investigation (Politie, 2026).
Reuters reported that his former employer identified him as Pepijn van der Stap; Dutch authorities had not publicly named him in that report. ShinyHunters denied an association with him. Police also described a separate suspicion of attempted solicitation of two murders arising from information found on his laptop. That allegation is separate from the ShinyHunters investigation and remains an allegation (Politie, 2026; Van Campenhout & Deutsch, 2026).
Jordan: A Reported Detention
Reporting in early October identified Saif al-Din Khader, associated with the alias “Rey,” as a suspected participant detained in Jordan and reportedly cooperating with investigators. The Record attributed those details to Reuters. The FBI declined to confirm his individual case to The Record, while acknowledging that it had worked with partners to arrest multiple subjects. Public reporting did not establish an extradition or conviction (Greig, 2026).
October 9: Another Arrest, Identity Not Announced
On October 9, FBI Director Kash Patel announced the arrest of another accused co-conspirator in the investigation of the bureau’s jobs-portal breach. The Associated Press reported that the suspect’s identity and possible charges were not immediately clear. Patel described the affected platform as managed by a third-party vendor. That supports a reported arrest, not a publicly established identity or conviction (Associated Press, 2026).
Watch: The FBI’s Own Arrest Announcement
In the official video below, FBI Cyber Division Assistant Director Brett Leatherman discusses the Dutch arrest of an alleged leader. He explains that Dutch authorities acted under Dutch law with FBI support, while industry partners shared information. He says the suspect and co-conspirators allegedly breached more than 140 organizations and collected at least $70 million in extortion payments since the previous year (FBI, n.d.).
The video explains the partnership behind the arrest. It does not disclose the full sequence of evidence used to identify the suspect or show the arrest itself. I would not turn that limited public account into a claim about a secret tracking technique. The FBI also supplies a written transcript on its official video page (FBI, n.d.).
What This Means for Defenders
An arrest interrupts people and infrastructure; it does not erase copies of stolen information or remove permissions already granted inside a victim’s systems. A useful response has to address both the original access and what can happen to the exposed data afterward.
For organizations, the FBI recommends phishing-resistant MFA, least privilege, monitoring unusual API activity, and reviewing third-party integrations. In a suspected connected-app compromise, investigate the application and its tokens as well as the user account; a password reset alone may leave authorized application access intact (FBI, 2025).
For people contacted by extortionists, verify unusual requests through a separate, known communication channel. Preserve messages and relevant incident details, follow the affected organization’s official guidance, and report suspected criminal activity to IC3 or a local FBI field office. The FBI advises against responding to demands or sending payment (FBI, 2026).
A Clarification About the Google Story
Google’s 2025 disclosure concerned its corporate Salesforce instance and largely public business contact information. It did not establish that two billion Gmail accounts were breached. That distinction is relevant to my earlier phone-call article: the lesson about social engineering remains, but the account type, scope, and attribution must be stated accurately (Google Threat Intelligence Group, 2025).
What stands out to me is how much of this story sits between technical access and human pressure. A persuasive call can open a door. A stolen record can make the next call more convincing. The practical defense is to create places where someone can stop, verify, and say no—and to support that decision with limited permissions and useful monitoring.
References
Antoniuk, D. (2025, June 25). French police reportedly arrest suspected BreachForums administrators. The Record. https://therecord.media/france-breachforums-suspects-arrests
Associated Press. (2026, October 9). FBI arrests suspect in ShinyHunters hack of the bureau’s jobs portal. https://apnews.com/article/b27bad3059c9ab93d1d7006d3af13c0a
Federal Bureau of Investigation. (n.d.). FBI announces ShinyHunters arrest [Video]. https://www.fbi.gov/video-repository/shinyhunters-arrested-092926.mp4/view
Federal Bureau of Investigation. (2025, September 12). Cyber criminal groups UNC6040 and UNC6395 compromising Salesforce instances for data theft and extortion [FLASH alert]. https://www.fbi.gov/file-repository/cyber-alerts/cybercriminal-groups-unc6040-and-unc6395-compromising-salesforce-instances-for-data-theft-and-extortion-091225.pdf
Federal Bureau of Investigation. (2026, May 15). ShinyHunters: Cyber criminal group attacks learning management system. Internet Crime Complaint Center. https://www.ic3.gov/PSA/2026/PSA260515
Google Threat Intelligence Group. (2025, June 4). The cost of a call: From voice phishing to data extortion. Google Cloud. https://cloud.google.com/blog/topics/threat-intelligence/voice-phishing-data-extortion
Greig, J. (2026, October 5). Alleged ShinyHunters member reportedly detained in Jordan, assisting law enforcement. The Record. https://therecord.media/alleged-shinyhunters-member-detained-jordan-fbi
Politie. (2026, September 29). Verdachte aangehouden in onderzoek naar hackersgroep ShinyHunters [Suspect arrested in investigation into hacker group ShinyHunters]. https://www.politie.nl/nieuws/2026/september/29/11-verdachte-aangehouden-in-onderzoek-naar-hackersgroep-shinyhunters.html
U.S. Attorney’s Office, Western District of Washington. (2024, January 9). Member of notorious international hacking crew sentenced to prison. U.S. Department of Justice. https://www.justice.gov/usao-wdwa/pr/member-notorious-international-hacking-crew-sentenced-prison
Van Campenhout, C., & Deutsch, A. (2026, September 29). ShinyHunters suspect also investigated for alleged murder orders, Dutch media report. Reuters. MarketScreener. https://ca.marketscreener.com/news/shinyhunters-suspect-also-investigated-for-alleged-murder-orders-dutch-media-report-ce785addde8ef52c



Comments