ShinyHunters Hacker Arrested in Netherlands Over Alleged Double Murder Plot

TL;DR
- Dutch police arrested a suspected ShinyHunters member in Amsterdam this week, seizing a laptop allegedly containing detailed plans to arrange two murders.
- The suspect is linked to the notorious ShinyHunters crew behind massive breaches tied to Snowflake, AT&T, Ticketmaster, Santander and others affecting hundreds of millions of victims.
- Prosecutors have now added preparation for murder to the cybercrime case, dramatically raising the stakes and potential prison time as forensic and international investigations continue.
Who Was Arrested and How It Happened
Dutch authorities confirmed the arrest of a young man suspected of being an active member of ShinyHunters, the English-speaking cybercrime collective that has terrorized corporate security teams since 2020.
According to police statements released Monday, the suspect was detained in the Amsterdam region following a coordinated operation involving the Dutch National Police's High Tech Crime Team, the Public Prosecution Service, and international partners including the FBI and French authorities. Investigators had been tracking the individual for months as part of an ongoing probe into large-scale data theft and extortion.
Officers seized multiple devices during house searches, including laptops, phones, encrypted drives, and cryptocurrency wallets. The suspect is currently in pre-trial detention, with authorities requesting a 14-day extension while they conduct full forensic analysis. Dutch media report the suspect is in his early 20s and operated under a well-known hacker alias linked to data leak forums.
From Data Theft to Alleged Murder Plot
What started as a routine cybercrime takedown took a shocking turn when detectives examined one of the seized laptops.
Prosecutors say they discovered files detailing plans to organize two murders, including names, photos, addresses, chat logs about hiring intermediaries, and proposed payments. The documents allegedly outline motives, surveillance notes, and encrypted messages discussing execution methods.
Authorities have not publicly identified the intended targets, but sources cited in Dutch press suggest they may have been connected to the criminal underworld or were former criminal associates, not random victims. Police stress the plots had not been carried out, and they are now urgently investigating whether hitmen had been contacted and whether anyone else is at risk.
The suspect now faces investigation for preparation of murder alongside computer intrusion charges, which under Dutch law allows prosecutors to hold him longer and demand broader access to his digital life.
ShinyHunters' Long Trail of Mega-Breaches
The arrest is significant because ShinyHunters is not a low-level crew. Emerging in 2020, the group became infamous for stealing and selling massive databases from companies including Wattpad, Tokopedia, BigBasket, Mashable, and Microsoft's GitHub repository.
The gang rebranded and escalated in 2024 with the Snowflake-linked attack spree, exploiting stolen credentials to breach cloud customers. That campaign was tied to breaches at Ticketmaster affecting over 560 million users, AT&T affecting 73 million current and former customers and a separate incident involving call logs of nearly all mobile customers, plus Santander, Advance Auto Parts, Neiman Marcus, and others.
Security researchers estimate ShinyHunters and its affiliates have extorted tens of millions of dollars in Bitcoin through ransom demands and dark web data sales. The group often works with other collectives like Scattered Spider and Lapsus$, sharing access brokers, SIM-swappers, and extortion tactics.
U.S. authorities previously charged and convicted other alleged ShinyHunters members, including French national Sebastien Raoult, who pleaded guilty in the U.S. in 2024 to conspiracy and aggravated identity theft. The new Dutch arrest suggests law enforcement is now closing in on the next generation of operators who revived the brand.
What the Discovery Means for the Investigation
The alleged murder plans fundamentally change the case from a cybercrime prosecution to a major violent crime investigation.
First, it gives Dutch prosecutors far more leverage. Cybercrime cases often involve lengthy extradition battles, especially with the U.S. seeking suspects for Snowflake-related charges. A domestic murder-preparation charge ensures the suspect remains in Dutch custody while evidence is reviewed.
Second, it opens new lines of inquiry into how cyber profits fund real-world violence. Police are now tracing cryptocurrency transactions to see if payments were made to intermediaries, analyzing Telegram, Signal and Tox chats, and working to identify and warn potential victims.
Third, it highlights the evolving profile of elite cybercriminals. Once seen as keyboard-only offenders, some high-earning data brokers are now accused of operating like organized crime figures, using their wealth and anonymous networks to settle disputes offline.
Prosecutors say more arrests cannot be ruled out, both in the Netherlands and abroad, as forensic experts comb through terabytes of seized data.
What Happens Next
The suspect is expected to appear before an examining magistrate in Amsterdam this week for a closed-door custody hearing. Dutch authorities say they will share relevant breach data with victim companies and foreign law enforcement.
Meanwhile, cybersecurity firms are urging companies to rotate Snowflake and cloud credentials, enforce multi-factor authentication, and monitor for leaked data resurfacing, as takedowns often trigger retaliatory leaks by remaining gang members.
If convicted on both the hacking and murder-preparation charges, the suspect faces years in Dutch prison, followed by possible extradition to the United States or France for additional cybercrime trials.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!