# Dutch police arrest a suspect in the ShinyHunters investigation as the group's attacks escalate

Source: https://startwithidentity.com/blog/2026-09-28-dutch-police-arrest-suspect-in-shinyhunters-investigation/
Last updated: 2026-09-28
License: content by Start with Identity. Cite the source URL.

---

Dutch police confirmed that a 24-year-old man from Amsterdam, arrested on September 15, was detained in an investigation into the ShinyHunters extortion group. Tactical officers searched his home and seized devices, and a court appearance was set for September 29. BleepingComputer and KrebsOnSecurity report the suspect was convicted in 2023 of hacking and extorting more than a dozen companies. Police have not said which breaches he is suspected of, and a ShinyHunters representative denied any connection. The group's activity has not slowed. It was linked this year to the Odido telecom breach, where a help-desk employee was phoned by someone posing as IT and entered credentials into a fake login page, and it has been exploiting Oracle PeopleSoft flaw CVE-2026-35273 using a URL-encoding trick that slips past web application firewall rules.

## Why it matters

One arrest does not retire a brand that operates as a loose collective, and ShinyHunters has repeatedly continued after members were detained. The practical takeaway is its method, which barely changes from campaign to campaign: a phone call to someone who can reset or enter credentials, a convincing login page, and then the data. That is the pattern behind [help-desk social engineering](https://startwithidentity.com/techniques/help-desk-social-engineering/), the [EY claim in July](https://startwithidentity.com/blog/2026-07-27-shinyhunters-claims-ey-breach-via-stolen-third-party-credentials/), and the [Scattered Spider playbook](https://startwithidentity.com/breaches/scattered-spider-helpdesk-social-engineering/) it overlaps with.

The PeopleSoft detail carries a second lesson. Organizations that had not applied Oracle's June patch were relying on a WAF rule matching the literal path, and the attackers simply percent-encoded one character. A WAF rule is a stopgap for an unpatched system, not a control, and it fails the moment the attacker encodes around it. If PeopleSoft is in your estate, Mandiant's advice is to patch, then search WebLogic logs for `/PSEMHUB/` requests and their encoded variants.

Source: [BleepingComputer](https://www.bleepingcomputer.com/news/security/dutch-police-confirm-arrest-in-shinyhunters-hacking-investigation/)
