Download Privacy Needle App

Type to search

Cybersecurity

ShinyHunters Claims FBI Data Hack Was Marketing Campaign

Share
ShinyHunters Claims FBI Data Hack Was Marketing Campaign

The hacking group ShinyHunters has dismissed allegations of extortion following the arrest of a suspected leader, claiming its recent targeting of FBI-related data was a “marketing campaign” intended to protect its brand rather than a financial attack.

The group’s response follows increased pressure from law enforcement. The FBI has called on remaining members of the ShinyHunters group to come forward after the arrest of a key individual suspected of playing a significant role in the gang’s operations.

Suspected Leader Arrested in the Netherlands

Pepijn van der Stap, a 24-year-old from Amsterdam, was arrested on 15 September in the Netherlands. The arrest occurred while the suspect was on probation following a previous prison sentence related to hacking and extortion activities.

Dutch police stated that information discovered on van der Stap’s laptop included details regarding two planned murders to be committed abroad. The FBI’s Cyber Division has identified the suspect as one of the alleged leaders of the extortion group.

According to the FBI, the suspect has been involved in the hacking of more than 140 organisations and has facilitated the collection of at least $70 million in extortion payments since 2025. The agency noted that the group frequently targets third-party vendors on cloud-based platforms to steal sensitive data and extort victims.

ShinyHunters Denies Extortion Intent

In a statement released via its Tor-based leak site, ShinyHunters claimed it never intended to publish stolen data from FBIJobs.gov. The group had previously alleged it had exfiltrated two to three terabytes of data, including personally identifiable information (PII) and protected health information (PHI) belonging to current and former FBI employees.

The group characterised the incident as an effort to combat disinformation, stating that the event was not financially motivated. They claimed the high level of attention gained from the incident was a successful attempt to protect their business operations and prove their points to the public.

Despite the law enforcement crackdown, ShinyHunters maintains that its operations and infrastructure remain unaffected. The group issued a warning to victim organisations, suggesting they continue negotiations to prevent the release of stolen information.

Resilience of Decentralised Hacking Groups

Cybersecurity analysts suggest that the arrest of a single leader may not lead to the dissolution of ShinyHunters. Due to the group’s decentralised nature, experts believe remaining members may simply rename the operation or spin off into new criminal entities.

Jason Brown, director of customer advisory at iCOUNTER, noted that such arrests act as a disruption rather than an end. He observed that groups operating like brands often rotate members and handles, allowing them to adjust to law enforcement pressure while continuing their campaigns against vendors, help desks, and software-as-a-service (SaaS) providers.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.