Dutch police have arrested a suspected member of the ShinyHunters cyber‑crime group that claimed to have stolen sensitive information on all FBI bureau staff – around 38,000 people.

The suspect, a 24‑year‑old from Amsterdam, was taken into custody on 15 September, a day before the group publicly announced a breach of the FBI’s Oracle‑cloud infrastructure.

Police say the laptop seized from the suspect contained a “large amount of information”, including details of two planned murders abroad that the man may have ordered. He is also charged with attempted incitement to commit those killings.

ShinyHunters first surfaced in France, but have since carried out high‑profile hacks, notably on Rockstar Games and the education platform Canvas. The group claimed to have exploited a vulnerability in the Oracle cloud system used by the FBI to access multiple internal services – FBIJOBS, BEAST, MedLink and BICS.

In a statement, Stan Duijf, chief of Dutch cyber‑crime investigations, said the arrest provides a “critical breakthrough” in the transnational investigation. FBI director Kash Patel, speaking on X, thanked Dutch partners and noted that FBI teams are actively working with international leads.

Brett Leatherman, assistant director of FBI Cyber, urged other members of the group to surrender, warning that continued secrecy could make their activity easier to track. He added, “The longer you stay in this, the more we learn about you, you know how to find us, we know how to find you.”

The FBI’s public service announcement, still live on its website, describes ShinyHunters as a threat actor that claims access to personal data to coerce victims into payments. The agency highlighted that the group “often steals millions of customer records at once.”

Police have released no further arrests, but Dutch officials say no additional suspects were ruled out.