Dutch police arrest a suspect in the ShinyHunters investigation as the group's attacks escalate
Police in the Netherlands confirmed a 24-year-old Amsterdam man was arrested in September in an investigation into ShinyHunters, the extortion group behind help-desk vishing and PeopleSoft exploitation this year. The group denies any link.
Dutch police confirmed that a 24-year-old man from Amsterdam, arrested on September 15, was detained in an investigation into the ShinyHunters extortion group. Tactical officers searched his home and seized devices, and a court appearance was set for September 29. BleepingComputer and KrebsOnSecurity report the suspect was convicted in 2023 of hacking and extorting more than a dozen companies. Police have not said which breaches he is suspected of, and a ShinyHunters representative denied any connection. The group's activity has not slowed. It was linked this year to the Odido telecom breach, where a help-desk employee was phoned by someone posing as IT and entered credentials into a fake login page, and it has been exploiting Oracle PeopleSoft flaw CVE-2026-35273 using a URL-encoding trick that slips past web application firewall rules.
Why it matters
One arrest does not retire a brand that operates as a loose collective, and ShinyHunters has repeatedly continued after members were detained. The practical takeaway is its method, which barely changes from campaign to campaign: a phone call to someone who can reset or enter credentials, a convincing login page, and then the data. That is the pattern behind help-desk social engineering, the EY claim in July, and the Scattered Spider playbook it overlaps with.
The PeopleSoft detail carries a second lesson. Organizations that had not applied Oracle's June patch were relying on a WAF rule matching the literal path, and the attackers simply percent-encoded one character. A WAF rule is a stopgap for an unpatched system, not a control, and it fails the moment the attacker encodes around it. If PeopleSoft is in your estate, Mandiant's advice is to patch, then search WebLogic logs for /PSEMHUB/ requests and their encoded variants.
Source: BleepingComputer
Related on Start with Identity
- Blog1.6 million RingCentral records leaked, and the entry point was one phone call
ShinyHunters voice-phished a RingCentral employee out of their password in July, took 623GB, and dumped 280GB after the company refused to pay. Have I Been Pwne
- BlogAttackers are phoning employees about their passkeys, then enrolling their own MFA method
Microsoft detailed a campaign running since May 2026 in which callers posing as IT tell US enterprise users to update their passkey or MFA settings, route them
- BlogA Zimbra XSS zero-day let a Russian espionage group read mailboxes and steal 2FA codes for months
NSA, CISA, and partner agencies detailed a year-long campaign against Zimbra Classic UI, tracked under several names including Void Blizzard and LAUNDRY BEAR, t
- ExpertCo-chair, OpenID Shared Signals working group
Annabelle Backman is a principal security engineer on AWS Identity and co-chairs the OpenID Shared Signals and Events working group. She edited RFC 8935 and RFC
- ExpertIETF working group chair and RFC author
Hannes Tschofenig has co-chaired the IETF OAuth working group and the ACE working group on authentication and authorization for constrained environments, alongs
- ExpertInventor of CAEP, co-chair of the Shared Signals working group
Atul Tulshibagwale invented the Continuous Access Evaluation Protocol at Google and co-chairs the OpenID Foundation's Shared Signals working group, which publis