Alleged ShinyHunters leader arrested; group targeted healthcare

Advertisement

Dutch authorities have arrested an alleged leader of ShinyHunters, a cybercriminal group that has targeted healthcare organizations and their third-party vendors, the FBI said.

The Dutch National Police’s High Tech Crime Unit arrested the suspect under Dutch law with the FBI’s support, Brett Leatherman, assistant director of the FBI’s Cyber Division, said in a Sept. 29 video statement. The FBI did not name the suspect.

Since last year, the suspect and co-conspirators have allegedly breached more than 140 organizations in the U.S., the Netherlands and other countries and collected at least $70 million in extortion payments, Mr. Leatherman said. The group often targets third-party vendors on cloud-based platforms, stealing sensitive data and threatening to publish it.

Mr. Leatherman also warned the group’s remaining members that arrests tend to change who is willing to talk to investigators. “Other groups believed anonymity, or their friends, would protect them, and they were wrong,” he said.

The Health Information Sharing and Analysis Center warned earlier in September that ShinyHunters had used targeted voice phishing campaigns to trick personnel into entering credentials on malicious, medical-themed impersonation domains, the American Hospital Association reported. The group has contacted employees directly on personal devices through calls, voicemails and emails from multiple accounts.

“ShinyHunters is currently one of the most prolific and aggressive cybercriminal groups targeting healthcare and third-party healthcare vendors,” stated John Riggi, national advisor for cybersecurity and risk at the AHA.

Mr. Riggi said the arrest aligns with the FBI’s new cyber strategy, which aims to impose costs on adversaries, support cybercrime victims and work with the private sector, including healthcare.

Advertisement

Next Up in Cybersecurity

Advertisement