Sentrix

Analysis · Identity

ShinyHunters: an arrest, and what does not change

An alleged ShinyHunters leader was arrested in the Netherlands. The group's methods, SSO accounts, third parties and SaaS platforms, stay open to others.

By Sentrix · Published 2026-10-05

On September 29, 2026, the Dutch National Police announced the arrest, on September 15, of a 24-year-old man from Amsterdam suspected of taking part in a criminal organization linked to ShinyHunters. The same day, the FBI described the suspect as one of the group's alleged leaders. An arrest matters. It does not close the doors this group has used.

What the authorities say

The Dutch police. The statement says the Rotterdam district court ordered the suspect held for at least 90 more days, that data carriers were seized and that the investigation continues. Police and prosecutors urge companies to strengthen their digital security with preventive measures.

The FBI. Brett Leatherman, Assistant Director of the Cyber Division, said: "Today, our partners at the Dutch National Police announced the arrest of one of the alleged leaders of ShinyHunters." According to the FBI, quoted by CyberScoop, the suspect and his alleged co-conspirators breached more than 140 organizations since last year and took at least 70 million dollars in extortion payments. To the rest of the group, he sent a direct warning: "The longer you stay in this, the more we learn about you."

The methods. BleepingComputer sums up the playbook attributed to the group: target corporate SSO accounts, third-party vendors and SaaS platforms such as Salesforce and Snowflake, steal data, then threaten to publish it.

Why it matters

None of these methods relies on knowledge that the arrest takes away. Taking over an SSO account takes a password, an MFA that can be bypassed, or a help desk that resets without checking. Going through a vendor takes an access that nobody watches. Emptying a SaaS platform takes a connected app or a service account that can export in bulk without an alert.

These are identity governance gaps, not software vulnerabilities. They stay open to anyone who picks up the same playbook, and both the Dutch investigation and the FBI's warning make clear that the group is not one person.

The FBI's figure also recalls the economics of the model: extortion pays when the victim has neither decided in advance how to respond nor kept the logs that show what actually left.

What we think at Sentrix

In order:

  1. Make SSO phishing-resistant. Passkeys or FIDO2 keys for every account that opens SSO, administrators first. Our article on phishing-resistant MFA covers the rollout.
  2. Close the help-desk door. No MFA or password reset without a call-back to a number already on file. The rule is written down, trained and checked.
  3. Review the connected apps of each SaaS platform. Who holds an OAuth token, with which permissions, and when it was last used. What is no longer used gets revoked.
  4. Watch exports. An alert on any unusual bulk download or query, per user and per app, is the last net before extortion.
  5. Keep the register of third parties that hold access. That is the path described in September's four 8-Ks. Our third-party risk module keeps that register and its evidence, and the CTEM continuous exposure module keeps the inventory of exposed identities and access current.
  6. Decide the extortion response before the incident. Who decides, on which criteria, with which legal counsel and which notices to authorities.

For an MSP or MSSP, the stakes multiply: a single compromised SSO account at the provider can open the consoles of all its clients. Separate access per client, phishing-resistant MFA for all staff and a log of every sign-in are the minimum your clients will ask for.

The next step

List the accounts that open your SSO and the apps connected to your SaaS platforms, then note for each the type of MFA and the date of the last review. The lines without an answer are your work plan. If you want us to run the review with you, see our identity and access service or contact us.

Sources

Frequently asked questions

Q01
Does the arrest lower the risk for my organization?
Not much, in the short term. Dutch police speak of one suspect within a group, the investigation continues and the FBI is publicly addressing the remaining members. The methods attributed to the group, taking over corporate SSO accounts, going through third-party vendors and stealing data from SaaS platforms, need no rare tool and no new vulnerability. Other crews already use them.
Q02
Which control best protects an SSO account?
Phishing-resistant multi-factor authentication, with passkeys or FIDO2 hardware keys, for every account that opens SSO, starting with administrators. It goes with a strict help-desk rule: no MFA or password reset without a call-back to a number already on file or the presence of a manager.
Q03
Why is an MSP or MSSP especially exposed?
Because a single SSO account at the provider often opens the consoles of all its clients. The group targets third-party vendors precisely to reach several victims. An MSP must separate its access per client, require phishing-resistant MFA for its staff and be able to say, for each client, who can sign in and from where.

Let's talk about your compliance program.

Last updated: 2026-10-05