ProBackend
law enforcement crackdowns
3 hours ago6 min read

ShinyHunters' Dutch Connection: First European Arrest Lands Amid FBI's $700M Manhunt

Dutch police confirmed the arrest of a 24-year-old Amsterdam man tied to the ShinyHunters extortion group — the first European detention in a case that spans Salesforce breaches, UK retail attacks, and AI-powered vishing campaigns.

A Quiet Arrest in Amsterdam

Dutch National Police confirmed on September 28, 2026, that they'd detained a 24-year-old Amsterdam resident on September 10 as part of an ongoing probe into the ShinyHunters cybercrime gang. The Unit for High-Tech Crime (NHTC) — the specialized division that handles complex digital offenses in the Netherlands — made the bust. Police say the suspect is suspected of involvement in "the theft and sale of large amounts of data via hacking."

The arrest itself was quiet. No helicopter shots. No perp walk. Just a brief operational disclosure from NHTC confirming computer equipment and data carriers had been seized. But the timing tells you everything. This happened three days before the FBI publicly warned ShinyHunters members that their identities were about to be "outed" to law enforcement worldwide. And it came roughly four months after the Dutch police first linked Odido breach to Dutch hackers using AI-powered vishing, the telecom attack that put this specific threat group squarely on Dutch law enforcement's radar.

ShinyHunters, characteristically, denied any connection.

The Group Denies the Obvious

Within days of the arrest becoming public knowledge, ShinyHunters posted a statement on their forums calling it "a case of mistaken identity." They doubled down with a claim that reads almost laughable given the evidence catalogued against them: "As far as we are concerned, this Dutch person has nothing to do with us," the statement read. "We have never recruited employees, not Dutch, not from anywhere else."

That last bit is doing a lot of heavy lifting. Bloomberg — which was among the outlets that reported on the arrest, alongside AP News and the New York Times — reported that the alleged hacker worked for a cybersecurity company in the Netherlands. An insider with access to the very tools and techniques that make ShinyHunters effective. The "never recruited employees" line isn't a denial. It's a legal defense being workshopped in public.

Denials from ShinyHunters are standard procedure at this point. The group publicly denied a relationship with Scattered Spider, the younger, flashier hacking collective they've worked alongside, and made a similar "mistaken identity" claim after Dutch police named two of their own nationals as the suspects in the Odido vishing attack. The pattern is consistent: when law enforcement gets specific, ShinyHunters goes vague.

The FBI's Unusual Public Warning

Here's what makes this arrest genuinely different from the dozen-plus ShinyHunters-linked incidents that preceded it. On September 24, 2026, the FBI broke the fourth wall. Anonymous messages appeared on the same underground forums where ShinyHunters operates, the same platforms where the group recruits affiliates and flaunts stolen datasets. The FBI's message was direct: surrender to authorities before you're exposed.

Accompanying that message was a bounty. The FBI offered a reward of 10,000 BTC for information leading to arrests. At 2026 market prices, that's approximately $700 million. It's not subtle. It's not the kind of number you put on a poster hoping no one collects. It's the kind of number you put out there because you know your own people will eventually take the money.

The FBI didn't name individuals. The warning was addressed to ShinyHunters members as a collective, a deliberate choice that signals the bureau expects the information to come from inside the group. Paranoia is a weapon. And the FBI knows that when you put a price tag on everyone's head simultaneously, everyone starts watching each other.

The FBI's pressure campaign against ShinyHunters following international arrests marks a significant escalation from the traditional cybercrime investigation playbook. Usually, law enforcement moves quietly, indictments drop in coordinated fashion across jurisdictions, sometimes years after the initial breach. This is different. This is law enforcement openly courting defectors.

What ShinyHunters Actually Did

The arrest is only newsworthy because of the body of work behind it. ShinyHunters spent 2025 and 2026 building what is arguably the most prolific data-theft operation on the internet, and they did it by being relentlessly opportunistic rather than technically sophisticated.

Their signature move: compromise Salesforces CRM instances through social engineering, then extort the organizations that trusted them. They hit the UK's Co-op and took customer data. They hit the Angling Trust, a small fishing organization nobody has heard of, and made off with personal information. In May 2026, Marks & Spencer was hit with a cyberattack the group claimed responsibility for, a breach that cost the British retail giant an estimated £300 million in lost sales.

They claimed a massive data breach against Dutch telecom provider Odido. That one hit differently because Dutch police confirmed it publicly. They said attackers accessed personal information on Odido's customer database through vishing, social engineering over the phone, and sold it to parties who used it for SIM-swap fraud. Roughly 100,000 customers needed to change their SIM cards. The Dutch police named the attackers: Dutch hackers using AI-powered vishing. That detail matters because it connects the dots between the Dutch-speaking criminal underground and what had previously seemed like an English-language operation.

ShinyHunters also hit Salesforce itself, a breach that rippled through downstream customers. And when a rival extortion gang tried to move in on their territory, ShinyHunters hacked Clop's ransomware leak site and threatened to publish payment details of Clop's victims. That's not just theft. That's territorial violence executed in code.

Why the Netherlands Matters

The Dutch angle on ShinyHunters isn't coincidental. The Netherlands hosts a concentration of Salesforce data centers, European headquarters for major SaaS providers, and a Dutch-speaking criminal community with technical skills and a history of operating below the radar of international cybercrime attention. When Dutch police moved on the Odido breach, they weren't investigating some distant foreign crime with a Dutch victim. They were investigating a local product.

The 24-year-old from Amsterdam fits that profile precisely. Young, technically capable, embedded in the Dutch cyber ecosystem, allegedly moonlighting for an extortion gang while holding a legitimate job at a security firm. If that Bloomberg detail is accurate, it tells you something uncomfortable about the cybersecurity industry's insider risk problem, the same people hired to defend against attacks are occasionally on both sides of them.

What Comes Next

ShinyHunters is under pressure from every direction. The FBI is publicly offering a bounty that dwarfs anything in cybercrime history. Dutch police have made an arrest with seized hardware they believe connects to the operation. The group is denying its own members exist in public while presumably scrambling internally to understand who's talking.

Whether this Amsterdam arrest leads to a prosecution, or to more arrests, depends on what's on those seized data carriers. Dutch police said the investigation is ongoing. No further arrests have been confirmed at the time of this writing.

But the message the FBI sent on those forums isn't aimed at the general public. It's aimed at the next 24-year-old in Amsterdam, or Manchester, or wherever else ShinyHunters has embedded operators, who now knows that $700 million is sitting on a table somewhere, waiting for a name.

a quiet arrest in amsterdam

More blogs