Summary
The Dutch National Police have confirmed the arrest of an individual in connection with an ongoing investigation into ShinyHunters, the prolific data theft and extortion collective responsible for breaches of Ticketmaster, AT&T, Bitget, and numerous other high-profile organizations. Dutch police have not disclosed the identity of the arrested individual, their role within ShinyHunters, or the specific charges filed. The arrest is the first publicly confirmed law enforcement action directly naming ShinyHunters as the subject of an active criminal investigation in Europe.
Timeline
| Date | Event |
|---|---|
| Ongoing 2025-2026 | ShinyHunters conducts breaches of Ticketmaster, AT&T, Clop leak site, Bitget, and alleged FBI/PeopleSoft intrusion among others |
| Sep 27-28, 2026 | Dutch National Police confirm arrest of individual in ShinyHunters investigation; identity and charges not disclosed; BleepingComputer reports |
What Happened
ShinyHunters has been one of the most active and consequential data theft and extortion operations of 2025-2026. The group’s operations have ranged from the Ticketmaster breach to the Clop ransomware leak site intrusion (TTO-2026-0925-164), the alleged FBI/PeopleSoft intrusion (TTO-2026-0922-151, updated TTO-2026-0926-170), and the Bitget hack (TTO-2026-0925-166).
The Dutch arrest is significant because the Netherlands has been a historically effective jurisdiction for cybercrime enforcement, previously involved in the takedowns of BreachForums, RaidForums, and multiple ransomware operations. A Dutch arrest in a ShinyHunters investigation suggests investigators have identified at least one member operating from or through Dutch infrastructure. However, ShinyHunters operates as a distributed group with members in multiple jurisdictions — a single arrest does not indicate the group’s operational capability has been disrupted. The group’s remaining members are presumed to continue operations while the investigation proceeds.
Note on Domain Intelligence
ShinyHunters does not operate a legitimate clearnet domain. Domain intelligence scores are not applicable to this bulletin.
The Trust Observatory · thetrustobservatory.com · September 28, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026