ShinyHunters in October: Two Arrests, a Dark Leak Site, and a 16-Year-Old Reportedly Helping the FBI. We Won't Name the Kid. Here Is What Still Resolves.
Nine days ago we scored ShinyHunters' claims for 2026 and wrote that the brand was being worn by several crews who were fighting each other. Since then, the fight has gone to law enforcement. A second suspect has been detained, the FBI says there have been "multiple" arrests, and the group's leak site has gone dark. One of the people now in custody is reported to be 16.
What happened
On September 28 or 29 (reports differ), a teenager was detained in Amman, Jordan. Reuters, citing FBI sources, reported that he is cooperating with the FBI and other agencies to identify other members of the group. The FBI has not said where he is held or whether he will be extradited, and no charges are public. KrebsOnSecurity tied him last November to the handle "Rey," which Krebs described as one of the administrators of the Scattered LAPSUS$ Hunters channel. Outlets disagree on whether he is 15 or 16.
On September 30 the group's leak site went offline. By October 2 its contact email no longer answered, and its spokesperson stopped responding to reporters. On October 5 the FBI confirmed that it and its partners had arrested "multiple" people in the investigation, without naming them.
That makes seven arrests tied to the ShinyHunters name since 2022, counting the Dutch arrest on September 15 that we covered last week.
The twist our ledger saw coming
In our September 29 post we repeated something Krebs's sources said: that a teenager known as "Rey" may have planted Umbreon imagery in the FBI breach to pin it on a rival. That rival is the 24-year-old the Dutch police arrested. Ten days later, the teenager alleged to have framed him is reported to be helping the FBI identify the rest of the group.
We called ShinyHunters a franchise whose members were fighting over the royalties. This is what that looks like at the end: members framing each other, then turning on each other, with the brand going quiet in the middle. None of this is proven in a courtroom yet. It is the pattern the public record shows.
Why we won't name him
Reuters published his name. We are not going to repeat it. He is a child. The facts that matter for defenders (a minor in Jordan, reported handle "Rey," reportedly cooperating) carry all the analytical weight without adding another search result that follows him into adulthood. Most countries' justice systems protect the identity of minors for exactly this reason, and a threat-intel blog has no reason to be less careful than a juvenile court.
There is also a harder point. The ecosystem this brand grew out of has long been full of teenagers doing the keyboard work, the phone calls and the SIM swaps, while older people collect most of the money. If the reporting holds, a 16-year-old is now in custody in another country, cooperating, with no public word on his legal protections. Whatever he did, that is not a story that ends well for anyone, and it is worth saying so plainly. It is also the most useful thing a parent or a school can take from this: the recruiting is real, and it happens in the same chat apps kids use for everything else.
What our own data shows today
We checked the infrastructure we hold rather than repeat other people's summaries.
All 12 single-sign-on phishing domains are dead. Every one of the lookalike login domains from EclecticIQ's reporting earlier this year (Okta, Workday and Microsoft impersonations) no longer resolves.
One piece of the PeopleSoft campaign is still standing. The domain azurenetfiles.net, the MeshCentral command server the group used in its Oracle PeopleSoft campaign, still resolves today to 142.11.200.187, an address on a US hosting provider. Its DNS zone has not changed since May 28, and Shodan currently sees no open ports on the address. That looks like an abandoned server nobody turned off, not a live one. We added the link between the address and the campaign to our feed today, below our own edge shield's blocking floor, because a dormant address can be reassigned. The address itself was first reported in June by the researcher @rxerium through TweetFeed, so the credit for spotting it is theirs; our part is checking that it still resolves.
Our corpus is cleaner than it was. After the correction we promised on September 29, we hold 25 indicators attributed to ShinyHunters, down from 57. The 27 junk records an automated extractor had mislabeled (news sites, victims, government domains) are gone. The newest real indicator is from June 30. We hold nothing first-party on the FBI breach or on any of the arrests, and we are not going to imply that we do.
What to expect next
Quiet is not gone. France announced it had arrested "ShinyHunters" in June 2025, and the following twelve months were the busiest in the brand's history. The name is worth too much to retire. If a teenager is naming names, the people he names have every reason to reappear under a new handle, and other crews have every reason to use the old one while it still frightens victims.
Our advice from the claims ledger still stands. If someone claiming to be ShinyHunters says they got into your systems, start incident response, because that kind of claim held up 13 times out of 14 this year. If they tell you how much they took, treat the number as a sales pitch. And if they tell you who they are, or who is no longer one of them, assume nothing.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=shinyhunters-october-2026-arrests-dark-leak-site-sixteen-year-old



Comments