ShinyHunters Claims FBI Data Hack Was Marketing Campaign
Share
The hacking group ShinyHunters has dismissed allegations of extortion following the arrest of a suspected leader, claiming its recent targeting of FBI-related data was a “marketing campaign” intended to protect its brand rather than a financial attack.
The group’s response follows increased pressure from law enforcement. The FBI has called on remaining members of the ShinyHunters group to come forward after the arrest of a key individual suspected of playing a significant role in the gang’s operations.
Suspected Leader Arrested in the Netherlands
Pepijn van der Stap, a 24-year-old from Amsterdam, was arrested on 15 September in the Netherlands. The arrest occurred while the suspect was on probation following a previous prison sentence related to hacking and extortion activities.
Dutch police stated that information discovered on van der Stap’s laptop included details regarding two planned murders to be committed abroad. The FBI’s Cyber Division has identified the suspect as one of the alleged leaders of the extortion group.
According to the FBI, the suspect has been involved in the hacking of more than 140 organisations and has facilitated the collection of at least $70 million in extortion payments since 2025. The agency noted that the group frequently targets third-party vendors on cloud-based platforms to steal sensitive data and extort victims.
ShinyHunters Denies Extortion Intent
In a statement released via its Tor-based leak site, ShinyHunters claimed it never intended to publish stolen data from FBIJobs.gov. The group had previously alleged it had exfiltrated two to three terabytes of data, including personally identifiable information (PII) and protected health information (PHI) belonging to current and former FBI employees.
The group characterised the incident as an effort to combat disinformation, stating that the event was not financially motivated. They claimed the high level of attention gained from the incident was a successful attempt to protect their business operations and prove their points to the public.
Despite the law enforcement crackdown, ShinyHunters maintains that its operations and infrastructure remain unaffected. The group issued a warning to victim organisations, suggesting they continue negotiations to prevent the release of stolen information.
Resilience of Decentralised Hacking Groups
Cybersecurity analysts suggest that the arrest of a single leader may not lead to the dissolution of ShinyHunters. Due to the group’s decentralised nature, experts believe remaining members may simply rename the operation or spin off into new criminal entities.
Jason Brown, director of customer advisory at iCOUNTER, noted that such arrests act as a disruption rather than an end. He observed that groups operating like brands often rotate members and handles, allowing them to adjust to law enforcement pressure while continuing their campaigns against vendors, help desks, and software-as-a-service (SaaS) providers.




Leave a Reply