decrypted · 30 september 2026 · ransomware and cybercrime · supply chain · ai and llm security
ShinyHunters: an arrest, and the front desk that still lets criminals in
On 29 September the FBI announced that a man arrested in the Netherlands on 15 September is one of the alleged leaders of ShinyHunters, the extortion group linked to more than 140 breaches since last year and at least $70 million in payments. The group has reportedly denied any connection to him. Arrests make good headlines, but they patch nothing. What matters for UK boards is how this group gets in, because it is rarely by clever exploits.
What is new
We covered ShinyHunters and the PeopleSoft firewall fix on 28 September. The new part is the arrest. Dutch National Police detained a 24-year-old in Amsterdam, and a Rotterdam court has ordered him held for at least 90 days. The FBI's Brett Leatherman told the rest of the group that "the longer you stay in this, the more we learn about you". No technical evidence tying him to specific breaches is public, so treat "leader" as an allegation.
The front desk, not the lock
Picture an office with a very good lock on every door. Now picture a receptionist who will hand over a master key to anyone who sounds convincing on the phone. BleepingComputer reports that the group targets single sign-on accounts, third-party vendors and software-as-a-service platforms such as Salesforce and Snowflake. Once a criminal holds a genuine employee login, the systems see an ordinary user. They pull data out in bulk, then threaten to publish it unless someone pays.
There is no malware to detect. The signs are an unusual login, a new device on a familiar account, or an export far larger than normal. If nobody watches volume, the first alert is the extortion email.
The UK exposure
The University of Nottingham is the reminder. In June, BleepingComputer reported that ShinyHunters had posted evidence on its leak site, and the university confirmed a breach of its student records system. It told the Information Commissioner's Office and Action Fraud. About 454,600 current students and alumni were affected, with more than 40GB of documents stolen, including passport numbers, ethnicity and disability details. That incident sat within the wider PeopleSoft campaign, which BleepingComputer put at over 100 organisations.
The Secure by Design lesson
Four design decisions would have narrowed this, and none needs a new product.
- Phishing-resistant sign-in. Passkeys or hardware security keys on single sign-on and admin accounts mean a convincing phone call cannot hand over a working login.
- Verified helpdesk resets. Make it impossible to add a device or reset a factor on the strength of a phone call alone.
- Least privilege for vendors and integrations. Give each supplier connection only the data it needs, and expire its tokens.
- Less to steal. Collect fewer sensitive fields, and delete them on a schedule. Data you no longer hold cannot be leaked.
The cost is mostly process and patience: a few weeks of rollout friction, some annoyed staff and a supplier conversation. Set that against an ICO notification and 454,600 letters. In my opinion, the arrest is worth reading as a prompt for one question: if a criminal rang our helpdesk today, what would stop them?
Also this week
Fake ChatGPT, real malware. Huntress reports that attackers built Custom GPTs impersonating genuine ChatGPT models and promoted them through Google Ads. The bot sent users to a "Service Availability Notice" on a Google Sites page, which coaxed them into running a PowerShell command and starting an eight-stage infection that ends in a remote access trojan. Huntress counted at least 40 incidents from that domain, two confirmed as starting in a Custom GPT. OpenAI removed the first GPT by 25 September, but Huntress found a second still live when it published. A trusted domain is not a trusted author.
A poisoned AI plugin. Security firms including SafeDep, Socket and StepSecurity found credential-stealing code in npm and PyPI packages from MemTensor, a maker of AI memory tooling. The bad releases are npm plugin versions 0.1.21, 0.1.23 and 0.1.25, and PyPI MemoryOS 2.0.34. SafeDep says the attacker obtained publishing tokens by pushing commits that made MemTensor's own release workflow hand them over. The implant can reportedly spread itself into other packages and workflows. Pin to npm version 0.1.20 or PyPI 2.0.33, and rotate any secrets that were exposed. Release pipelines deserve the same access controls as production.
Spectre returns to the JIT. Researchers at VUSec and Scuola Superiore Sant'Anna describe Branch Target Reuse, a Spectre v2 variant, which they say can recover a Linux root password hash within minutes on a fully patched Intel system with default protections. The Linux kernel flaws are CVE-2026-64507 and CVE-2026-64508, and fixes are merged. This is a research result, not a report of attacks. It matters most on shared machines that run untrusted code.
Sources
- BleepingComputer: FBI tells ShinyHunters members to turn themselves in after recent arrest
- Cyber Security News: FBI and Dutch Police Arrested Alleged ShinyHunters Hackers Group Leader
- BleepingComputer: Nottingham University data breach affects over 450,000 students
- Huntress: Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
- The Hacker News: Compromised MemTensor Packages Deliver sckit Credential Stealer
- The Hacker News: New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
If you want a second pair of eyes on your sign-in, helpdesk or supplier access, get in touch.
More like this
- GitHub switched off two poisoned Actions, then switched them back on 26 september 2026
- EvilTokens is down, but the device login door is still open 23 september 2026
- The LiteLLM breach that leaked 2,500 companies' secrets, and the dependency nobody pinned 13 august 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.