<p>The FBI’s top cyber official on Tuesday warned remaining ShinyHunters members to contact investigators while they still have a choice, suggesting authorities could have made undisclosed progress against the hacking group that recently claimed to have stolen troves of highly sensitive bureau personnel records.</p>
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
<p>“You know how to find us, and we know how to find you,” Brett Leatherman, assistant director of the FBI’s Cyber Division, said in a <a href=“https://m.youtube.com/watch?v=bxLNRd7WvzU”>YouTube video</a> posted by the bureau. “I suggest you reach out first while the choice is still yours.”</p>
<p>Leatherman’s remarks accompanied Dutch authorities’ announcement Tuesday that they had <a href=“https://www.politie.nl/nieuws/2026/september/29/11-verdachte-aangehouden-in-onderzoek-naar-hackersgroep-shinyhunters.html”>arrested</a> an alleged leader of the group. The suspect and his alleged co-conspirators have breached more than 140 organizations and collected at least $70 million in extortion payments since last year, he said.</p>
<p>“We’re confident you’ve seen or heard things in recent days that the public has not,” Leatherman said, addressing the remaining members. “Other groups believed anonymity or their friends would protect them, and they were wrong.”</p>
<p>“Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left,” he added. “The longer you stay in this, the more we learn about you.”</p>
<p>The video marks a significant escalation in the FBI’s public confrontation with ShinyHunters and offers one of its clearest statements to date that investigators may be closing in on the group’s remaining members.</p>
<p>A representative for ShinyHunters did not immediately respond to a request for comment.</p>
<p>Leatherman’s warning comes a day after ShinyHunters<a href=“ShinyHunters says it won’t publish FBI data - Nextgov/FCW”> </a>told <em>Nextgov/FCW</em> it would <a href=“ShinyHunters says it won’t publish FBI data - Nextgov/FCW”>not publish</a> the larger trove of FBI data it claims to possess, cryptically describing its confrontation with the bureau as a “marketing campaign.” Its statement did not say the records had been deleted. The FBI declined to comment on the group’s statement.</p>
<p>It’s possible the group could still sell parts or all of the data to foreign intelligence services or other willing buyers, said retired Lt. Gen. Robert Skinner, who led the Defense Information Systems Agency from 2021 to 2024.</p>
<p>“I would never take a criminal’s word for anything,” said Skinner, who is now board chairman at Axonius Federal Systems. “If they’re saying it now, they probably won’t do it now, but that doesn’t mean that they won’t do it in the future.”</p>
<p>In its initial claim over the intrusion last week, ShinyHunters <a href=“ShinyHunters claims FBI data theft, demands bureau retract cyber warning - Nextgov/FCW”>demanded</a> the FBI retract a public warning about its tactics, addressing its message directly to Leatherman and FBI Director Kash Patel. </p>
<p>The disputed May 15 advisory described harassment, swatting and exaggerated claims about stolen information among the tactics used to pressure victims. ShinyHunters denied those practices and maintained its confrontation with the FBI was not financially motivated.</p>
<p>Last week, the group supplied <em>Nextgov/FCW</em> with an apparent sample containing roughly 5,000 entries, including names, home addresses, phone numbers and information about spouses and siblings. Online searches of multiple names confirmed employment with the FBI.</p>
<p>The exposed records identified personnel <a href=“Stolen FBI data reveals employees’ roles in intelligence and surveillance - Nextgov/FCW”>in sensitive intelligence and surveillance roles</a>, including analysts working on China, Russia, Hezbollah and cartels. The information also identified employees involved in human intelligence and electronic surveillance, as well as the Remote Operations Unit, which develops specialized tools to target computers and networks. Sensitive medical information was also listed.</p>
<p>Congressional staff are in touch with the bureau, according to two people familiar with the matter who spoke on the condition of anonymity to discuss the communications.</p>
<p>The incident follows other cyberattacks involving the bureau and its leadership this year. In March, pro-Iran hacking group Handala<a href=“Pro-Iran hackers claim breach of FBI director’s email - Defense One”> published material</a> from FBI Director Kash Patel’s personal email account, which the bureau said contained historical information unrelated to government business. Separately, a suspected China-linked<a href=“Suspected Chinese breach of FBI system exposed surveillance targets’ phone numbers - Nextgov/FCW”> intrusion into an FBI system</a> earlier this year exposed surveillance targets’ phone numbers.</p>
Article Link: FBI warns ShinyHunters members to come forward after alleged leader’s arrest - Nextgov/FCW