ShinyHunters investigation widens after reported detention in Jordan
Reuters reported a suspected member was cooperating with the FBI, days after authorities disclosed a separate arrest in the Netherlands.
The international investigation into ShinyHunters widened on October 3 with a Reuters report that a suspected member of the hacking group had been detained in Jordan and was cooperating with the FBI.
Reuters attributed the account to three sources. It followed public statements about a separate arrest in the Netherlands, giving investigators two distinct developments to pursue. The Jordan detention should not be confused with the Dutch case or treated as a publicly established conviction. The identity, evidence and legal outcome of each suspect require separate scrutiny.
In a September 29 video statement, FBI cyber official Brett Leatherman said Dutch authorities had arrested a suspected ShinyHunters member under Dutch law. He described an investigation involving the FBI and the Netherlands’ High Tech Crime Unit, and said the wider criminal activity had affected more than 140 organizations and generated at least $70 million in extortion payments since the previous year.
Those are the FBI’s figures for the alleged campaign. They are not a finding that the person arrested personally committed every intrusion or received every payment. The distinction matters in investigations involving a group name used across multiple attacks and online claims.
Dutch police supplied a more detailed timeline. Their September 29 statement said a 24-year-old Amsterdam man had been arrested on September 15 on suspicion of membership in a criminal organization. Investigators seized data-storage devices. A Rotterdam court subsequently extended his custody by 90 days while the investigation continued.
The Dutch statement also explicitly distinguished the arrest from the investigation into the Odido hack. Linking every prominent breach associated with a group name to the same suspect would therefore go beyond what police have established. Reuters separately reported that ShinyHunters denied the Amsterdam man was associated with the group.
The FBI’s account describes a business model centered on access to third-party vendors and cloud platforms. Attackers steal information and threaten to publish it unless victims pay. That places organizations at risk even when the point of entry lies in a service they buy rather than a system they directly operate.
Reuters’ October 3 report also referred to a group claim that it had stolen information concerning every FBI employee. That claim was not independently established by the reporting available for this article, and its stated scope should not be presented as a verified description of a breach.
The public evidence therefore consists of different layers: a Dutch arrest and court decision confirmed by police, an FBI account of the broader extortion campaign, and a source-based Reuters report about detention in Jordan. The Dutch investigation remained open, with police saying further arrests were possible and the suspect held under the court’s extended detention order.