Start with Identity
News

Dutch police arrest a suspect in the ShinyHunters investigation as the group's attacks escalate

Police in the Netherlands confirmed a 24-year-old Amsterdam man was arrested in September in an investigation into ShinyHunters, the extortion group behind help-desk vishing and PeopleSoft exploitation this year. The group denies any link.

By SWI Community TeamSep 28, 2026

Dutch police confirmed that a 24-year-old man from Amsterdam, arrested on September 15, was detained in an investigation into the ShinyHunters extortion group. Tactical officers searched his home and seized devices, and a court appearance was set for September 29. BleepingComputer and KrebsOnSecurity report the suspect was convicted in 2023 of hacking and extorting more than a dozen companies. Police have not said which breaches he is suspected of, and a ShinyHunters representative denied any connection. The group's activity has not slowed. It was linked this year to the Odido telecom breach, where a help-desk employee was phoned by someone posing as IT and entered credentials into a fake login page, and it has been exploiting Oracle PeopleSoft flaw CVE-2026-35273 using a URL-encoding trick that slips past web application firewall rules.

Why it matters

One arrest does not retire a brand that operates as a loose collective, and ShinyHunters has repeatedly continued after members were detained. The practical takeaway is its method, which barely changes from campaign to campaign: a phone call to someone who can reset or enter credentials, a convincing login page, and then the data. That is the pattern behind help-desk social engineering, the EY claim in July, and the Scattered Spider playbook it overlaps with.

The PeopleSoft detail carries a second lesson. Organizations that had not applied Oracle's June patch were relying on a WAF rule matching the literal path, and the attackers simply percent-encoded one character. A WAF rule is a stopgap for an unpatched system, not a control, and it fails the moment the attacker encodes around it. If PeopleSoft is in your estate, Mandiant's advice is to patch, then search WebLogic logs for /PSEMHUB/ requests and their encoded variants.

Source: BleepingComputer

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.