
Dutch police have arrested a 24-year-old man on suspicion of involvement with the prolific ShinyHunters cybercrime group.
Cops announced the arrest on Monday night and said the Amsterdam resident would appear before judges at Rotterdam District Court today (Tuesday).
Officers have not named the suspect. However, a company has identified a person they believe to be the suspect as working for them as an offensive security lead. Dutch broadcaster RTL and other newswires have also published a name. chooses not to do so until a name is officially released by law enforcement.
Authorities have not disclosed what conduct he is suspected of or identified any attacks allegedly involving him.
The timing has focused attention on the investigation into the February breach of Dutch telco Odido, which was claimed by ShinyHunters and affected 6.2 million customers. Police have not said whether the individual is suspected of participating in that attack or whether he is the caller heard in an audio recording released this month.
Investigators said the Odido intrusion began when a Dutch-speaking caller posed as an IT colleague and persuaded a customer service employee to provide access to an internal system. Police released part of the call on September 8 and subsequently received 20 tips, including what they described as "some very interesting information that the investigation team can use moving forward."
Reuters reports the suspect was arrested on September 15 and that forensic investigators visited an Amsterdam office to make the arrest that night. They said police deployed flashbang grenades during the operation, although the account does not make clear where they were used. The arrest came a week after the public appeal.
The person the news reports named was convicted several years ago of hacking, data theft, and extortion, and sentenced to four years in prison, one year suspended. He subsequently returned to legitimate cybersecurity work.
ShinyHunters denial that it is linked to the named individual comes days after it boasted of compromising an FBI recruitment system, exclusively telling that it hacked the FBI to "protect our business." The move is part of an escalating run of attacks and extortion attempts attributed to the group. ®