The FBI Calls Him a ShinyHunters Leader. ShinyHunters Says He's a Stranger, and Also Promised to Support Him. We Scored Their 2026 Claims: 13 of 14 Break-Ins Held Up. Almost Nothing Else Did.
Dutch police arrested a 24-year-old in Amsterdam on September 15 and announced it today, two weeks later, in the ShinyHunters investigation. FBI Director Kash Patel called him "one of the alleged leaders" of the group. ShinyHunters told TechCrunch that he "has no association with us." According to KrebsOnSecurity, the same group also said it would give its member "emotional, mentally, and financial" support.
Those can't both be true. That's not unusual for this crew, and it's why we went back through every dated ShinyHunters claim we've written about this year and scored each one against what actually happened.
Who they arrested
The Dutch National Police haven't named him. They say he's suspected of taking part in a criminal organization, ShinyHunters, and that his laptop held information about two murders that were to be committed abroad, with indications he gave the order. That murder allegation is a separate investigation, and it is an allegation. He appeared in Rotterdam District Court today and is being held for at least 90 days.
KrebsOnSecurity, TechCrunch, SecurityWeek and others identify him as the Dutch hacker who was convicted in 2023 under the handle "Umbreon." In that case, prosecutors said a string of data thefts and extortions earned him between 1.5 and 2.7 million euros. He got four years, one of them suspended. At trial he described a double life: by day a software engineer at a security startup and a volunteer at the Dutch vulnerability-disclosure institute, by night selling victims' data on RaidForums and Breached. When he was arrested this month he was working in offensive security at a Dutch firm, and had recently described himself in an interview as reformed.
Here is what connects him to ShinyHunters in public reporting. KrebsOnSecurity's sources point to voice identification from the February 2026 Odido breach, the Dutch mobile carrier where 6.2 million customers were affected. They also point to Umbreon Pokémon imagery left in the defacement of the FBI's jobs portal last week. But Dutch police say they don't believe he was involved in the Odido breach, and Krebs's sources say a rival inside the group, a teenager known as "Rey," may have planted the Umbreon imagery to pin the FBI hack on him. No public reporting places him at the keyboard for the FBI intrusion.
Put that together and the "leader" label comes from the FBI. The best evidence tying him to specific attacks is disputed by the arresting police on one count and by the reporter's own sources on the other. And the group's statements contradict each other. We'll let a Dutch court sort out the rest.
The FBI part is real
On September 22, ShinyHunters claimed it had breached the FBI through a new bypass of the Oracle PeopleSoft bug it exploited against more than 100 organizations in June. It said it took two to three terabytes. The FBI has since confirmed the breach of apply.fbijobs.gov and said Social Security numbers and personal data on more than 5,000 officials were exposed, including psychiatric and medical files. The job portals are still offline. Nobody has confirmed the terabytes.
FBI Cyber Division Assistant Director Brett Leatherman says the group has breached more than 140 organizations and taken at least 70 million dollars since last year.
Arrests have never stopped the name
This is the sixth time in four years that law enforcement has arrested someone described as ShinyHunters or close to it.
2022: Sébastien Raoult, arrested in Morocco, extradited, and sentenced in the US in January 2024 to three years for his part in ShinyHunters breaches of more than 60 companies.
October 2024: Connor Moucka ("Judische," "Waifu"), arrested in Canada over the Snowflake-customer extortions.
December 2024: Cameron Wagenius ("kiberphant0m"), a US soldier who later pleaded guilty over the AT&T and Verizon extortions tied to that same campaign.
February 2025: Kai West ("IntelBroker"), the former BreachForums administrator, arrested in France.
June 2025: French police arrest four people they identified as the BreachForums personas ShinyHunters, Hollow, Noct and Depressed.
September 2026: Umbreon, per the reporting above.
France announced it had arrested "ShinyHunters" in June 2025. The twelve months that followed were the busiest in the brand's history. In January 2026, the leaked BreachForums database we analyzed still carried a "ShinyHunters" admin account and a "Hollow" super-moderator. A user table is a roster, not a timesheet, so that doesn't prove who was active. It does show the handles outlived the people France said were behind them.
The claims ledger
We scored every dated 2026 claim we could source, from the Odido breach in February to the FBI breach last week. We split them into three kinds, because they don't behave the same way. Almost all of the underlying facts come from victims, vendors and reporters. Our part was assembling and dating them, and one first-party finding: the pre-registered vercel-sso.com domain we surfaced on April 19.
"We got in": 13 of 14 held up. Odido, Telus Digital, McGraw-Hill, ADT, Instructure's Canvas, DentaQuest, Madison Square Garden, the PeopleSoft zero-day campaign, Ernst & Young, Brinks Home, RingCentral, Cl0p's own leak site, and the FBI. In each case the victim confirmed a breach, the vendor patched the bug, or the data or defacement was out in public where anyone could see it. The one miss was OnlyFans in May: 340 million records, flatly denied by the company, and assessed by researchers as a compilation of older leaks. Even the sellers admitted they hadn't breached OnlyFans directly.
One caveat on that 13. A confirmed breach doesn't prove who did it. Ernst & Young confirmed the intrusion through a third-party IT service-management platform but has never confirmed ShinyHunters. And the Vercel breach was real, but the ShinyHunters name on it probably wasn't, which is the next section.
"We took this much": 2 of 10 held up. Madison Square Garden's 26 million records became a 45-gigabyte public dump, and McGraw-Hill's leak was confirmed at around 13.5 million accounts. Six others were never verified by anyone but the people selling them: Telus at roughly a petabyte, ADT at 10 million, Canvas at 275 million, Brinks at 4.9 million, RingCentral at 623 gigabytes, and the FBI at two to three terabytes. OnlyFans' 340 million was false. The strangest one runs the other way: DentaQuest was listed at 744 users, and the real number turned out to be 2.6 million. The numbers aren't measurements. They're whatever makes the ransom look reasonable that week.
"Here's who we are": 1 of 3 held up. In April, established ShinyHunters figures said the Vercel breach wasn't theirs, and Mandiant separately assessed the claimant as likely an imposter. That's the only self-description we can check against an outside source, and it held. The other two came apart without any help from outsiders. In May, after Instructure paid for the Canvas data to be destroyed, the group announced within 48 hours that the deal only covered the first dataset and set a new deadline. And today, the man the FBI calls their leader has "no association" with them and is also getting their support.
Where we stand on ShinyHunters
ShinyHunters in September 2026 isn't a crew. It's a brand that several crews wear, and the wearers are fighting. The same month produced its biggest trophy (the FBI), its most theatrical stunt (seizing Cl0p's leak site and demanding 2.333 percent of Cl0p's net worth), and an arrest that current insiders are publicly disowning. If Krebs's sources are right about a teenager planting a rival's calling card on a federal breach, the members are framing each other. That's what a franchise looks like when the royalties are big enough to fight over. Arrests take out individuals and the name keeps going, as it has five times before.
So do they tell the truth all the time? No. But they're not simply liars either, and that's the more useful thing to know. Here's what we can agree on, at about 95 percent:
When ShinyHunters says it got into you, believe it and start incident response. Thirteen of fourteen times this year, something real had happened.
When ShinyHunters says how much it took, treat the number as a sales pitch. Only two of ten held up, and one was low by a factor of more than three thousand.
When ShinyHunters talks about itself, who's a member, who isn't, what it deleted, what it promised, assume nothing. That's where the brand lies most, because that's where lying pays: it protects members, sets up the next demand, and keeps the name valuable.
The defender takeaway is the same one we wrote in July, when we argued that anyone can claim to be ShinyHunters. Doubting every claim is just as wrong as believing every claim. The claims that come true are about your systems, so act on them. The ones that don't are about the group itself, so ignore them.
What our own data holds, and one thing we got wrong
We hold 145 posts that mention ShinyHunters (an exact-phrase count we took on September 21), going back to the Salesloft Drift OAuth compromise in September 2025, plus a standing adversary profile and 57 records in our indicator index attributed to the name. We hold nothing on the arrestee: our corpus returns zero hits for Umbreon or for Rey. That's expected, since none of our indicators are about people. But it means this arrest doesn't connect to anything in our feed, and we aren't going to pretend it does.
Checking those 57 records for this post turned up a mistake of our own. Twenty-seven of them came from an automated extractor we ran against the adversary profile in May. It pulled every domain the profile mentioned and labeled them ShinyHunters infrastructure: news sites that covered the group, the journalism site DataBreaches.net, victims such as Odido and Drizly, and justice.gov, europa.eu and okta.com. A 28th, Madison Square Garden's msg.com, is a victim record stored in the same index. None of them are infrastructure. None of them were ever in our downloadable blocklist CSVs, and the 27 were never marked for detection in the MISP feed, so no subscriber's firewall blocked the Department of Justice. They did show up with the wrong label in the MISP event and in single-indicator lookups. We found them while writing this post, and they are being pulled from both. The real infrastructure is the rest: ten operator IPs and twelve single-sign-on phishing domains from EclecticIQ's reporting, the leak-site onion and domain, the PeopleSoft campaign's MeshCentral command-and-control domain, the Salesforce exfiltration user agent, and a few actor records. We didn't discover any of those first. EclecticIQ, Reco and TweetFeed did, and they get the credit. That includes a line in our own adversary profile claiming we had the Canvas operators' infrastructure "40+ days" before disclosure. That date is when we ingested EclecticIQ's report, not when we detected anything, so it isn't a lead and the line is being corrected.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=the-fbi-calls-him-a-shinyhunters-leader-shinyhunters-says-he-s-a-stranger-and-also-promised-to-sup




Comments