Get all your news in one place.
100's of premium titles.
One app.
Start reading
Medical Daily
Medical Daily
Health
Joseph James

Dutch Police Hold Alleged ShinyHunters Leader, but Patients Hit by Health Vendor Breaches Still Face Scam Risks

Dutch police, working with the FBI, have arrested a man described as one of the alleged leaders of ShinyHunters, an extortion group that has targeted health care companies and the vendors that serve them. FBI Director Kash Patel announced the arrest on September 29, calling ShinyHunters "a global cybercrime and threat actor group linked to cyberattacks in the United States, the Netherlands, and around the world," Fox News reported.

The suspect is a 24-year-old Amsterdam man who was taken into custody on September 15 and ordered held for at least 90 days pending trial. Neither the FBI nor Dutch police publicly named him. He has not been convicted of any crime in this case.

For patients, the arrest is significant but limited. It may disrupt future attacks, but it does not pull back data that has already been stolen and posted online. People whose records were caught up in earlier vendor breaches still face the same risk of scam calls, fake bills, and identity theft that existed before the arrest.


One Arrest, 140 Breaches, and a Vendor Pipeline

FBI Cyber Division Assistant Director Brett Leatherman said the group's reach was broad. "Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments," he said, according to CyberScoop.

Citing sources and security journalist Brian Krebs, CBS News identified the suspect as Pepijn van der Stap, who was convicted in 2023 of data theft and extortion. Dutch authorities suspect him of taking part in a cybercrime group and of attempted incitement to commit two murders abroad, after information about the alleged plans was found on his laptop. A person claiming to speak for ShinyHunters told TechCrunch that the arrested man "has no association with us."

The group's method helps explain why health care is exposed. Rather than attacking hospitals directly, ShinyHunters often goes after the software vendors and cloud services that hold data for many clients at once. A single stolen login at one vendor can open records from many clinics and practices, and patients may never have heard of the company that lost their data.

MedicalDaily previously reported that McKesson narrowed its confirmed data theft to certain applications serving some oncology and multispecialty customers after an August cyberattack that ShinyHunters claimed. The group said it took about 284 million rows of data, a figure McKesson has not confirmed. Patients at practices using those services are among those awaiting notification letters.


Phone Calls Became the Group's Way In

In late August, the Health Information Sharing and Analysis Center (Health-ISAC), a nonprofit that coordinates security warnings for the health sector, issued an urgent threat alert about the group. It said attackers were calling health care employees on personal cell phones while posing as internal IT support.

Callers steered workers to fake login pages on medical-themed web addresses, including domains ending in ".claim" and ".claims." Once an employee typed in a password and a one-time code, the attackers used those credentials in real time to enter systems such as Microsoft 365, SharePoint, and Salesforce. Health-ISAC said, "ShinyHunters is behaving less like a traditional ransomware group and more like an identity- and SaaS-access extortion operation."

That distinction matters. Ransomware usually locks systems and disrupts care. ShinyHunters has typically copied data quietly and then demanded payment to keep it private, so hospitals can keep running while patient information is already gone.


Gaps the FBI Has Not Filled

Several key facts remain undisclosed. The FBI has not said which health care organizations were among the 140 alleged victims, how many patient records were involved in total, or whether U.S. charges have been filed against the man in custody. It has not said whether the United States will seek his extradition.

Officials also have not said whether the arrest has stopped the group's activity or how many members remain at large. Leatherman aimed a warning at remaining members, saying "arrests have a way of changing who is willing to talk."Patel said, "FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest."

The arrest also does not settle what happens to data already released. Stolen records that have been sold or posted online can circulate for years, whether or not anyone is prosecuted. Criminals who buy them later do not need the original group to be active.


Steps for Patients Whose Data May Be Exposed

Patients who receive a breach notification letter from a health care provider or vendor should read it carefully. These letters should describe which types of data were involved, such as insurance numbers, diagnoses, or Social Security numbers, and they often include an offer of free credit monitoring.

Be cautious with unexpected calls, texts, or emails that mention a recent diagnosis, prescription, or bill. Scammers who hold stolen records can sound convincing because they know real details. Hang up and call your doctor's office or insurer using the number on your insurance card or official website instead of the number provided by the caller.

Review Explanation of Benefits statements for visits or services you did not receive, and consider a credit freeze if Social Security numbers were exposed. Do not stop treatment or skip appointments because of a breach.

One alleged leader is in custody, which may slow the group, but the data already taken remains a risk. Patients should expect more notification letters as vendors finish their reviews, and MedicalDaily will follow any U.S. charges or extradition requests.


Key Questions Answered

Who was arrested? A 24-year-old Amsterdam man described by the FBI as one of the alleged leaders of ShinyHunters. He has not been convicted in this case.

Did ShinyHunters target health care? Yes. The group claimed an August attack on McKesson, and Health-ISAC warned it was targeting health sector employees with phone scams.

Does the arrest protect my stolen data? No. Data already stolen or posted online can still be misused.

Which health organizations were affected? The FBI has not named health care victims among the more than 140 organizations allegedly breached.

What should patients watch for? Unexpected calls, texts, or emails that mention diagnoses, prescriptions, or bills, and unfamiliar charges on insurance statements.

Will the suspect face U.S. charges? Officials have not disclosed U.S. charges or an extradition request.

Published by Medicaldaily.com

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.