Dutch national police (Politie Landelijke Opsporing en Interventies) have confirmed the arrest of a 24-year-old Amsterdam man in connection with the ShinyHunters investigation, according to an official statement posted on X. The suspect is expected to appear before a judge. This is one of the more significant law-enforcement actions against a group that has become synonymous with large-scale data theft, credential-driven SaaS compromises, and extortion-by-leak campaigns.
Do not mistake this arrest for the end of the threat. ShinyHunters has operated less like a rigid hierarchical gang and more like a brand and ecosystem — overlapping clusters of actors, affiliates, and buyers moving through BreachForums-style marketplaces. Arrests of individuals associated with this ecosystem have historically produced temporary disruption, followed by reconstitution under the same or adjacent branding. The group's tradecraft — stolen credentials, MFA gaps, OAuth token abuse, mass exfiltration from cloud data platforms, and extortion — is now commoditized. Other actors already run the same playbook.
If your organization uses Snowflake, Salesforce, or any SaaS platform holding bulk customer data, this post is your checklist. The defensive lessons here are current, concrete, and actionable today.
Technical Analysis: The ShinyHunters Playbook
Who and what is at risk
ShinyHunters and associated clusters (tracked by various vendors under overlapping names, including activity tied to the 2024 Snowflake campaign and the 2025 Salesforce/Salesloft Drift data-theft wave) do not exploit software vulnerabilities in the traditional sense. There is no CVE here — and that is precisely the point. Their attack surface is identity and configuration debt:
- Stolen credentials harvested by infostealer malware (Raccoon, Vidar, Lumma-class stealers) and purchased on criminal marketplaces
- Accounts without MFA, or with MFA susceptible to fatigue/push-bombing
- OAuth tokens and connected-app grants in platforms like Salesforce, where a compromised third-party integration (the 2025 Salesloft Drift incident being the canonical example) yields bearer tokens that bypass login controls entirely
- Cloud data warehouses (Snowflake being the highest-profile case) where demo/legacy accounts without MFA and without network policies allowed bulk customer data exfiltration affecting over a hundred downstream organizations
Attack chain (defender's view)
- Credential/token acquisition — infostealer logs, credential stuffing against SaaS portals, or theft of OAuth refresh tokens from a compromised integration partner.
- Initial access — direct login to the SaaS/data platform. No malware touches your endpoint. From your SOC's perspective, the first observable event is an anomalous legitimate login.
- Reconnaissance and staging — enumeration of databases, schemas, objects, and API-accessible records. In Snowflake incidents, actors ran bulk
SELECTqueries and used client tooling to stage exports. - Exfiltration — large-volume downloads via the platform's native export, or commodity exfil tooling (
rclone,megacmd, similar) on endpoints, moving data to MEGA or actor-controlled cloud storage. - Extortion — victim contact, proof-of-theft samples, and listing on leak forums under the ShinyHunters brand.
Exploitation status
This is not theoretical. The Snowflake campaign (2024) impacted organizations including Santander, Ticketmaster, and Advance Auto Parts, and was directly linked in court proceedings and vendor reporting to ShinyHunters-associated actors. The 2025 OAuth-token campaign against Salesforce customers via Salesloft Drift affected hundreds of organizations, including security vendors themselves. The tradecraft is mature, repeatable, and actively in use in 2026 — which is exactly why law enforcement keeps making arrests and why your detections need to assume the next operator is already testing your tenant.
Detection & Response
The detections below target the behavioral core of this playbook: commodity exfil tooling on endpoints, bulk database extraction, and risky OAuth consent — the three choke points where you can actually see this activity before the extortion email arrives.
---
title: Commodity Exfiltration Tool Execution (Rclone / MEGA / Similar)
id: 3f8a1c42-9b2d-4e71-a6c3-7d5e9f0b2a14
status: experimental
description: Detects execution of rclone, megacmd, or similar cloud-sync exfiltration tools with copy/sync/move operations — a hallmark of data-theft extortion groups including ShinyHunters-associated actors.
references:
- https://attack.mitre.org/techniques/T1567/002/
- https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html
author: Security Arsenal
date: 2026/09/15
tags:
- attack.exfiltration
- attack.t1567.002
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\rclone.exe'
- '\megacmd.exe'
- '\mega-cmd.exe'
- '\winscp.exe'
- '\filezilla.exe'
selection_cmd:
CommandLine|contains:
- 'copy'
- 'sync'
- 'move'
- 'put'
condition: selection_img and selection_cmd
falsepositives:
- Legitimate IT backup/sync workflows using rclone (baseline authorized usage per host and service account)
level: high
---
title: Bulk Database Export Utility Execution Outside Admin Context
id: 91c4d7a8-2e6f-4b39-c5d1-8a3e0f7b6c52
status: experimental
description: Detects execution of database dump/export utilities by non-database-admin accounts — consistent with staged bulk data extraction preceding extortion.
references:
- https://attack.mitre.org/techniques/T1005/
- https://attack.mitre.org/techniques/T1530/
author: Security Arsenal
date: 2026/09/15
tags:
- attack.collection
- attack.t1005
- attack.t1530
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\mysqldump.exe'
- '\pg_dump.exe'
- '\sqlcmd.exe'
- '\bcp.exe'
- '\mongoexport.exe'
filter_known_dba_accounts:
User|contains:
- 'svc_sql'
- 'svc_backup'
- 'dba_'
condition: selection and not filter_known_dba_accounts
falsepositives:
- Scheduled maintenance scripts — tune the filter to your actual DBA service accounts
level: medium
---
title: OAuth Consent Grant to High-Risk Permissions (Entra ID)
id: 6b2e9d15-4a7c-4f88-b3e6-2c9d1a5f8e37
status: experimental
description: Detects admin or user consent grants to OAuth applications requesting broad data-access scopes — the persistence/access mechanism abused in SaaS token-theft campaigns such as the Salesforce/Salesloft Drift wave.
references:
- https://attack.mitre.org/techniques/T1528/
- https://attack.mitre.org/techniques/T1550/001/
author: Security Arsenal
date: 2026/09/15
tags:
- attack.persistence
- attack.t1528
- attack.credential_access
- attack.t1550.001
logsource:
product: azure
service: auditlogs
detection:
selection:
OperationName:
- 'Consent to application'
- 'Add app role assignment to service principal'
- 'Add OAuth2PermissionGrant'
TargetResources|contains:
- 'Mail.Read'
- 'Mail.ReadWrite'
- 'full_access_as_app'
- 'offline_access'
- 'Files.Read.All'
- 'Sites.Read.All'
- 'Directory.Read.All'
falsepositives:
- Legitimate enterprise app onboarding — alert-tune by approved application IDs
level: high
// Hunt: ShinyHunters-style SaaS compromise pattern — anomalous sign-in followed by
// high-volume activity and/or new OAuth consent within a short window.
// Tables: SigninLogs + AuditLogs (Sentinel), DeviceProcessEvents (Defender)
let lookback = 14d;
let suspiciousSignins =
SigninLogs
| where TimeGenerated > ago(lookback)
| where ResultType == 0
| summarize
SigninCount = count(),
Locations = make_set(Location),
IPs = make_set(IPAddress),
Apps = make_set(AppDisplayName),
FirstSeen = min(TimeGenerated),
LastSeen = max(TimeGenerated)
by UserPrincipalName, bin(TimeGenerated, 1h)
| where SigninCount > 50 or array_length(Locations) > 2;
suspiciousSignins
| join kind=leftouter (
AuditLogs
| where TimeGenerated > ago(lookback)
| where OperationName has_any ("Consent to application", "Add OAuth2PermissionGrant")
| extend ConsentTarget = tostring(TargetResources[0].displayName)
| summarize Consents = make_set(ConsentTarget) by Identity, bin(TimeGenerated, 1h)
) on $left.UserPrincipalName == $right.Identity, TimeGenerated
| project TimeGenerated, UserPrincipalName, SigninCount, Locations, IPs, Apps, Consents
| order by TimeGenerated desc;
// Follow-up: check the same users' endpoints for exfil tooling
DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where FileName has_any ("rclone.exe", "megacmd.exe", "mysqldump.exe", "pg_dump.exe", "mongoexport.exe")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessAccountName
| order by TimeGenerated desc
-- Hunt for exfiltration and bulk-export tooling execution across the fleet
-- ShinyHunters-style data theft: rclone/MEGA exfil and DB dump utilities
SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Exe =~ '(?i)(rclone|megacmd|mega-cmd|mysqldump|pg_dump|mongoexport|bcp)\.exe$'
OR CommandLine =~ '(?i)(rclone (copy|sync|move)|megacmd .*put)'
# ShinyHunters-style SaaS compromise: Entra ID OAuth consent + endpoint exfil-tool audit
# Run as a Global Reader / Cloud App Security admin. Requires Microsoft.Graph module.
Import-Module Microsoft.Graph.Identity.DirectoryManagement -ErrorAction Stop
Connect-MgGraph -Scopes "Directory.Read.All","Application.Read.All","AuditLog.Read.All"
# 1) Find service principals holding high-risk delegated/application scopes
$riskyScopes = 'Mail.Read','Mail.ReadWrite','full_access_as_app','Files.Read.All','Sites.Read.All','Directory.Read.All','offline_access'
$spGrants = Get-MgOauth2PermissionGrant -All
foreach ($grant in $spGrants) {
$granted = $grant.Scope -split ' '
$hit = $granted | Where-Object { $riskyScopes -contains $_ }
if ($hit) {
$sp = Get-MgServicePrincipal -ServicePrincipalId $grant.ClientId
[PSCustomObject]@{
AppName = $sp.DisplayName
AppId = $sp.AppId
CreatedDate = $sp.AdditionalProperties.createdDateTime
RiskyScopes = ($hit -join ',')
ConsentType = $grant.ConsentType
}
}
} | Format-Table -AutoSize
# ACTION: For any app you cannot attribute to a documented business owner,
# revoke with: Revoke-MgOauth2PermissionGrant -OAuth2PermissionGrantId <Id>
# then remove: Remove-MgServicePrincipal -ServicePrincipalId <Id>
# 2) Enforce admin consent workflow (block user self-consent)
Update-MgPolicyAuthorizationPolicy -BodyParameter @{
defaultUserRolePermissions = @{ permissionGrantPoliciesAssigned = @() }
}
# 3) Audit endpoints for exfil tooling footprints (run via your EDR/remote shell)
Get-ChildItem -Path 'C:\Users\*\AppData\Roaming\rclone','C:\ProgramData\MEGAcmd' -Recurse -ErrorAction SilentlyContinue |
Select-Object FullName, LastWriteTime
Get-ChildItem 'C:\Users\*\AppData\Roaming\rclone\rclone.conf' -ErrorAction SilentlyContinue |
ForEach-Object { Write-Warning "Rclone config found: $($_.FullName) — inspect remotes for unauthorized cloud destinations" }
Remediation
There is no patch for this threat class — the fix is configuration, identity hygiene, and monitoring. Prioritize in this order:
1. Kill password-only access to SaaS and data platforms (this week)
- Enforce phishing-resistant MFA (FIDO2/passkeys, or at minimum number-matching push) on every account touching Snowflake, Salesforce, and your IdP. The Snowflake campaign succeeded overwhelmingly on accounts with no MFA.
- In Snowflake specifically: enforce
MFA_ENROLLMENT = REQUIRED, apply network policies restricting allowed source IPs, disable password authentication in favor of key-pair or SSO where possible, and auditACCOUNT_USAGE.LOGIN_HISTORYfor password-type logins from unfamiliar ASNs. - Reference: Snowflake Trust Center and security guidance at https://www.snowflake.com/en/trust-center/ and CISA's guidance on securing cloud data platforms at https://www.cisa.gov.
2. Constrain OAuth and connected apps (this week)
- Require administrator approval for all OAuth consent (the script above enforces this in Entra ID; apply the equivalent in Salesforce via "Admin approved users are pre-authorized" on connected apps).
- Inventory every third-party integration with API/token access to Salesforce, Google Workspace, and M365. The 2025 Salesloft Drift incident proved that your integration vendor's compromise is your compromise. Rotate tokens for any integration you cannot affirmatively verify.
3. Starve the credential supply (this month)
- Deploy infostealer detection on endpoints and monitor for your domains/credentials appearing in stealer-log marketplaces and breach corpora (commercial services or your threat intel provider).
- Force password resets and session revocation for any account found in stealer logs — the token theft, not the password, is often the persistence.
4. Detect bulk access, not just access (ongoing)
- Baseline normal query/download volumes per user and service account in Snowflake, Salesforce, and equivalent platforms. Alert on deviation — an account exporting 40 GB of customer records is an incident regardless of whether the login was "legitimate."
- Egress-filter and alert on
rclone, MEGA, and unsanctioned cloud storage destinations from corporate endpoints.
5. Prepare for the extortion event (before it happens)
- Pre-stage your IR retainer, legal counsel with breach-notification expertise, and a decision framework for extortion demands. Law enforcement (FBI IC3, https://www.ic3.gov, or Europol for EU entities) should be engaged early — these arrests happen because victims report and preserve evidence.
- Preserve SaaS audit logs beyond default retention; Snowflake and Salesforce default windows are too short for the dwell times these actors achieve.
A note on the arrest itself: individual arrests disrupt but do not dismantle brand-based threat ecosystems. Expect the ShinyHunters name to persist, be claimed by successors, and continue appearing in extortion notes. Your controls must assume continuity of the threat, not its conclusion.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.