FBI’s Top Cyber Guy Warns ShinyHunters Crew That They Better Watch Their Backs

FBI’s Top Cyber Guy Warns ShinyHunters Crew That They Better Watch Their Backs

The best way to show you’re not owned is, of course, posting. So the FBI has taken it up a notch after hackers stole a huge trove of data from its servers in a breach last week, including personal details on thousands of FBI officials. The assistant director of the FBI’s Cyber Division, Brett Leatherman, starred in a video on the FBI’s X feed on Tuesday that warned ShinyHunters members the longer they operate, the more the FBI learns about them. Leatherman stated the Dutch High-Tech Crime Unit had arrested “one of the alleged leaders of ShinyHunters,” adding that under the FBI’s cyber strategy, the jurisdiction “with the strongest authority and access leads” such raids and takedowns. In this case, that appears to be Dutch authorities, who The Register reported said the man was carrying a laptop with data on “two murders that were to be committed abroad.” Today, our partners at the Dutch National Police announced the arrest of one of the alleged leaders of ShinyHunters, a group linked to cyberattacks in the United States, the Netherlands, and around the world. The Dutch High-Tech Crime Unit arrested the suspect under Dutch law.… pic.twitter.com/EdfWJpVx2n — FBI Cyber Division (@FBICyberDiv) September 29, 2026 After noting the arrest of this person, Leatherman assured ShinyHunters of their imminent demise. “We’re confident you’ve seen or heard things in recent days that the public has not,” Leatherman warned. “Other groups believed anonymity or their friends would protect them, and they were wrong. Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left.” He also suggested the gang just give up and surrender. “The longer you stay in this, the more we learn about you,” Leatherman warned. “You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.” During the initial incident, ShinyHunters not only stole data from FBI servers but defaced its jobs portal with a parody takedown notice. An internal FBI memo obtained by the New York Times stated the FBI is “operating under the premise” that ShinyHunters has the agency’s complete data on employeer—so if ShinyHunters does want to find the FBI first, they certainly know where to look. The FBI hasn’t disclosed much about the attack. 404 Media first reported the incident while it was ongoing on Sept. 22, 2026. Investigating incidents on this scale often takes an extraordinary amount of time and resources, and it’s not clear whether the scale of the compromise is limited to what the FBI has disclosed so far. A close reading of the FBI’s statements so far is that they haven’t ruled out a third-party compromise, such as a hacked vendor. The FBI’s National Press Office told Gizmodo via email, “We have nothing additional to provide beyond the video.” As the nation’s primary counterintelligence agency, a failure of cybersecurity at the FBI of this scale is more than a little embarrassing. According to the BBC, current and former FBI agents worry the hack could blow undercover agents’ cover, and were especially mortified to hear the perpetrator was an unsophisticated criminal group (as opposed to, say, a nation-state adversary with many times the resources). One former cyber agent told the BBC that current FBI staff are outraged about “sloppy and lazy security failures” that allegedly resulted in the breach. ShinyHunters has since walked back threats of further action if the FBI doesn’t comply with demands like retracting a public advisory the bureau targeted them with, according to the New York Times, and has said they won’t publish the data. The Times noted that ShinyHunters had shared a sample of the data, which was enough to identify who works in some of the FBI’s most sensitive roles like counterintelligence, and the group also claims to have medical data. ShinyHunters denied on Tuesday that the Dutch man is one of their own, telling The Register, “Dutch police are unskilled and incompetent. That individual has no association with us.” According to cybersecurity journalist Brian Krebs, sources said the man was arrested on or around Sept. 15, 2026—well before the attack.

Original Source

Read the full article at Gizmodo →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.