FBI warns ShinyHunters members to come forward after alleged leader’s arrest

Assistant Director of the FBI's Cyber Division Brett Leatherman. Courtesy: FBI
“You know how to find us, and we know how to find you,” said Brett Leatherman, assistant director of the FBI’s Cyber Division. “I suggest you reach out first while the choice is still yours.”
The FBI’s top cyber official on Tuesday warned remaining ShinyHunters members to contact investigators while they still have a choice, suggesting authorities could have made undisclosed progress against the hacking group that recently claimed to have stolen troves of highly sensitive bureau personnel records.
“You know how to find us, and we know how to find you,” Brett Leatherman, assistant director of the FBI’s Cyber Division, said in a YouTube video posted by the bureau. “I suggest you reach out first while the choice is still yours.”
Leatherman’s remarks accompanied Dutch authorities’ announcement Tuesday that they had arrested an alleged leader of the group. The suspect and his alleged co-conspirators have breached more than 140 organizations and collected at least $70 million in extortion payments since last year, he said.
“We’re confident you’ve seen or heard things in recent days that the public has not,” Leatherman said, addressing the remaining members. “Other groups believed anonymity or their friends would protect them, and they were wrong.”
“Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left,” he added. “The longer you stay in this, the more we learn about you.”
The video marks a significant escalation in the FBI’s public confrontation with ShinyHunters and offers one of its clearest statements to date that investigators may be closing in on the group’s remaining members.
A representative for ShinyHunters did not immediately respond to a request for comment.
Leatherman’s warning comes a day after ShinyHunters told Nextgov/FCW it would not publish the larger trove of FBI data it claims to possess, cryptically describing its confrontation with the bureau as a “marketing campaign.” Its statement did not say the records had been deleted. The FBI declined to comment on the group’s statement.
It’s possible the group could still sell parts or all of the data to foreign intelligence services or other willing buyers, said retired Lt. Gen. Robert Skinner, who led the Defense Information Systems Agency from 2021 to 2024.
“I would never take a criminal’s word for anything,” said Skinner, who is now board chairman at Axonius Federal Systems. “If they’re saying it now, they probably won’t do it now, but that doesn’t mean that they won’t do it in the future.”
In its initial claim over the intrusion last week, ShinyHunters demanded the FBI retract a public warning about its tactics, addressing its message directly to Leatherman and FBI Director Kash Patel.
The disputed May 15 advisory described harassment, swatting and exaggerated claims about stolen information among the tactics used to pressure victims. ShinyHunters denied those practices and maintained its confrontation with the FBI was not financially motivated.
Last week, the group supplied Nextgov/FCW with an apparent sample containing roughly 5,000 entries, including names, home addresses, phone numbers and information about spouses and siblings. Online searches of multiple names confirmed employment with the FBI.
The exposed records identified personnel in sensitive intelligence and surveillance roles, including analysts working on China, Russia, Hezbollah and cartels. The information also identified employees involved in human intelligence and electronic surveillance, as well as the Remote Operations Unit, which develops specialized tools to target computers and networks. Sensitive medical information was also listed.
Congressional staff are in touch with the bureau, according to two people familiar with the matter who spoke on the condition of anonymity to discuss the communications.
The incident follows other cyberattacks involving the bureau and its leadership this year. In March, pro-Iran hacking group Handala published material from FBI Director Kash Patel’s personal email account, which the bureau said contained historical information unrelated to government business. Separately, a suspected China-linked intrusion into an FBI system earlier this year exposed surveillance targets’ phone numbers.
NEXT STORY: ShinyHunters says it won’t publish FBI data




