Yaamlabs

Threat intel

A ShinyHunters arrest: what it changes for defenders

Dutch police arrested a convicted hacker in the ShinyHunters case. The group's vishing and SSO playbook is still running. What to check in your tenants.

Dutch police have arrested a 24 year old man from Amsterdam in their investigation into ShinyHunters, the extortion group behind a long run of data thefts from cloud and SaaS (software as a service) platforms. Police say he was arrested on suspicion of participating in a criminal organization, and that he is separately suspected of attempting to arrange two murders abroad. KrebsOnSecurity, SecurityWeek and Security Affairs identify him as Pepijn van der Stap, who used the handle "Umbreon" and was convicted in 2023 of hacking and extortion. He was on supervised release at the time, has not been convicted of anything in this case and is presumed innocent.

The FBI says ShinyHunters has breached more than 140 organizations and collected at least $70 million in extortion payments since 2025. The group says it is still operating, and its main way in, a phone call from someone posing as IT, needs no particular person and no software flaw. If your staff sign in to Microsoft 365, Okta, Google Workspace or Salesforce through single sign-on (SSO), the checks below apply to you this week.

What police have said, and what they have not

The arrest date differs between sources. SecurityWeek, NL Times and Security Affairs, which reports that police searched his Amsterdam home that day, give September 15. KrebsOnSecurity and Hackread put it on or around September 16. Dutch police confirmed the arrest publicly on September 29, the day he was due before the Rotterdam District Court.

Police were specific about the scope. The suspect was not arrested in connection with the February 2026 breach of Odido, the Dutch mobile operator, even though ShinyHunters claimed that attack and police had earlier published a recording of the caller asking the public to identify the voice. The murder suspicion came from material on his laptop after the arrest, and police treat it as a case separate from the ShinyHunters investigation. ShinyHunters, for its part, told Hackread that "that individual has no association with us."

He was first arrested in January 2023 for hacking and extorting more than a dozen companies, and prosecutors said the scheme earned between 1.5 and 2.7 million euros. The court gave him four years with one suspended, and he was released in December 2025.

Reuters reported in early October, citing sources, that Jordanian authorities detained a man identified as Saif al-Din Khader, the ShinyHunters figure known as "Rey", and that he is helping the FBI identify other members. Brian Krebs had identified Rey in November 2025 as a teenager from Amman. The FBI declined to comment on any arrest abroad. Some coverage describes a dispute between the two men over the ShinyHunters name; police have not commented on it.

How the ShinyHunters playbook works

The group's best documented entry point is voice phishing, or vishing. Mandiant described the current version in January 2026 under the cluster names UNC6661 and UNC6671, alongside UNC6240, its name for ShinyHunters' extortion activity.

  1. The caller rings an employee posing as internal IT, often about an MFA (multi-factor authentication) change.
  2. The employee is sent to a custom domain made to look like the company's own SSO portal.
  3. While still on the phone, the attacker relays the password to the real SSO page as it is typed, triggers the genuine MFA challenge, and tells the employee to approve the push or read out the code.
  4. Once in, the attacker registers their own device as an MFA factor so the access survives a password reset.
  5. They delete Okta's "Security method enrolled" notification from the mailbox, so the employee never sees that a new device was added.
  6. They pull data from the SaaS apps behind SSO. Mandiant saw PowerShell used to bulk download files from SharePoint and OneDrive.

An earlier variant, which Google's threat intelligence group tracks as UNC6040, went straight at Salesforce. The caller talked the victim through Salesforce's OAuth consent screen and got them to authorize a connected app dressed up as Salesforce Data Loader. OAuth is the protocol that lets one app act on your behalf in another; once approved, the attacker's app could query and export records through the API with no further login. The attackers then used credentials found in that data to move into Okta and Microsoft 365.

The group also exploits software flaws, such as the Oracle PeopleSoft bug covered below, but the social engineering path is the one that works against a fully patched company.

What the arrest does and does not change

An arrest removes one person and gives investigators devices to read. If Reuters' sources are right that Rey is walking the FBI through his communications, more arrests may follow, and FBI Cyber Division Assistant Director Brett Leatherman has urged remaining members to come forward. Data already stolen does not come back, and no promise to delete it can be verified.

The techniques also have no owner. Mandiant tracks the vishing activity as several clusters because other groups may be copying it, and analysts quoted by SecurityWeek describe ShinyHunters as a brand rather than a fixed crew. After the arrest the group published a statement saying its operations continue and that victims should keep negotiating.

What to check this week

Start with the hunts, because they tell you whether you already have a problem.

New MFA factors. List every factor registered in the last 90 days and confirm each with its owner. In Okta, filter the System Log for eventType eq "user.mfa.factor.activate". In Microsoft Entra ID, filter the audit log for the activity "User registered security info". A factor added from an unfamiliar IP address, or shortly after a call to the user, is the pattern Mandiant describes.

Deleted notifications. Search mailbox audit logs for deletions of messages with the subject "Security method enrolled", or your identity provider's equivalent. A user does not usually delete that email within minutes of it arriving.

Bulk downloads by script. In the Microsoft 365 unified audit log, look for FileDownloaded events from SharePoint and OneDrive where the user agent contains PowerShell, from accounts that are not service accounts.

Salesforce connected apps. In Setup, under Connected Apps OAuth Usage, review every app and remove what you do not recognise, especially anything named like Data Loader that your admins did not install. Google's guidance is to switch API access to deny by default ("For admin-approved users, limit API access to only allowed connected apps"), remove the "API Enabled" permission from ordinary profiles, and watch LoginHistory for LoginType "Remote Access 2.0" followed by BulkApiResultEvent downloads. Revoke the tokens of any app you remove.

Then close the path. Give the help desk a rule that no MFA reset or new factor is approved on an inbound call; Google recommends a video check against photo ID, or a call back to the number on file with manager approval. Move administrators and anyone with export rights to phishing-resistant MFA (FIDO2 security keys or passkeys), which a relayed phone conversation cannot pass, and require a compliant device for SaaS access. Tell staff that IT will never ask them to approve a prompt or read out a code over the phone.

If a hunt turns something up, remove the attacker's factor before resetting the password, revoke all sessions and OAuth tokens for the account, and work out from the audit logs which files and records it reached.

The wider ShinyHunters story

We have covered the group's claimed FBI breach, its hijack of Clop's leak site and its second PeopleSoft exploitation run. The arrest changes none of the fixes in those posts. Our safeguarding and hardening work includes the SSO, MFA and help desk checks above, and security operations can run the factor and download hunts across your tenants. To have an engineer look at yours, open the chat and Yaali, our AI agent, will pass the question on.


Sources: SecurityWeek, Security Affairs, Hackread, KrebsOnSecurity, NL Times, TechCrunch, SecurityWeek on the FBI statement, eSecurity Planet, Security Affairs on the Jordan detention, BleepingComputer on the Jordan detention, BleepingComputer on Mandiant's findings, Help Net Security, CyberScoop, Google Threat Intelligence on UNC6040 hardening, Dark Reading.

Back to the blog, or read this post on the full site.