Dutch police arrest ShinyHunters hacker accused of planning two murders
- ID
- 29905
- Status
- summarized
- Published
- 30 Sep 2026, 1:27 AM
- Fetched
- 30 Sep 2026, 2:08 AM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/09/29/dutch-police-arrest-shinyhunters-hacker-accused-of-planning-two-murders/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 2.5
- Created
- 30 Sep 2026, 2:10 AM
- Tags
- Audience
- developerssaas_founders
What happened
Dutch police confirmed an unnamed 24-year-old man from Amsterdam was arrested on September 15 under Dutch law for 'participating in a criminal organization' — ShinyHunters — and was remanded into custody for at least 90 days after appearing in court on Tuesday. The FBI says the group is accused of hacking over 140 organizations worldwide, with the Dutch authorities naming data breaches at Pornhub, Ticketmaster, AT&T, and Dutch phone provider Odido. Police also said his seized laptop contained information about two murders to be committed abroad; that investigation is described as separate from the ShinyHunters probe, and the article notes he was not arrested in relation to the breaches themselves.
Why it matters
For most builders this is crime news with no code change attached — the concrete detail worth noting is the extortion model: ShinyHunters is accused of stealing data and threatening to publish it unless victims pay, which means backup-and-restore planning does not address that threat, only exposure does. If you hold customer data, the relevant question is what limits your blast radius when data is copied out, not how fast you can restore. There is no Malaysia-specific hook in this article.
Discussion angle
Data-theft-and-publish extortion is a different failure mode from encrypted ransomware — walk through whether your incident plan (and any cyber insurance or customer contracts) actually covers leaked data rather than downtime, using the 140+ organizations figure as the scale reference.