FBI vows to pursue ShinyHunters hackers after personnel data theft
In a video posted online, Brett Leatherman, the head of the FBI’s cyber division, made clear the bureau has stepped up its pursuit of the notorious hacking collective.

WASHINGTON — The FBI on Tuesday warned the criminal hacking gang that stole vast amounts of its sensitive personnel data that it would aggressively pursue its members as it promoted the recent arrest of one of its suspected associates.
In a video posted online, Brett Leatherman, the head of the FBI’s cyber division, said the bureau had worked with authorities in the Netherlands. The authorities recently arrested a 24-year-old convicted of cyberattacks on suspicion of aiding in data thefts and extortions tied to the group, known as ShinyHunters.
News of the arrest and its possible links to the group surfaced earlier this week, but Leatherman’s remarks are the first significant public statement from the FBI about the hackers since the agency’s breach of its online jobs portal was revealed last week.
Leatherman did not specifically mention the FBI hack in the video, but made clear the bureau has stepped up its pursuit of the notorious hacking collective.
“We’re confident you have seen or heard things in recent days that the public has not,” Leatherman said. “Other groups believed anonymity or their friends would protect them, and they were wrong. Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left.”
Looking directly into the camera, Leatherman said, “We know how to find you.”
An email account ShinyHunters uses to correspond with reporters did not immediately respond to a request for comment on the video. On Monday, it denied that the Dutch person who was arrested had ties to the group.
“That individual has no association with us,” ShinyHunters said in an email. “Frankly, we are laughing.”
Leatherman’s promise to pursue ShinyHunters, as well as a social media post Tuesday by FBI Director Kash Patel, came as the bureau was scrambling to assess the damage from the breach. A large tranche of data — including names, home addresses, details about spouses and other family members, secretive job titles, and much more — on potentially all FBI employees was stolen in the hack.
In announcing its theft, ShinyHunters had given the FBI a deadline of the end of Tuesday to comply with its demand to revise or remove a public advisory the bureau issued in May stating the hackers engaged in a variety of harassment and intimidation tactics to coerce hacked victims into payment. The group said it was angry about the characterization, which it denied, and suggested it would leak the stolen data online.
On Monday, the group issued a statement saying that it would not leak the private material and contending that it never planned to do so.
Leatherman did not say when the arrest occurred in the Netherlands, but a Dutch news release stated it took place two weeks ago, before ShinyHunters disclosed its hack of the FBI. It is not clear when that breach first occurred, but in an email, the group told the New York Times that the attack happened last week.
ShinyHunters is considered one of the most notorious and capable cybercriminal enterprises in the world. The group is believed to have breached more than 140 organizations and extorted $70 million since last year, Leatherman said, and has often targeted third-party vendors and cloud-based platforms.
This article originally appeared in the New York Times.
























