decrypted · 30 september 2026 · ransomware and cybercrime · supply chain · ai and llm security

ShinyHunters: an arrest, and the front desk that still lets criminals in

On 29 September the FBI announced that a man arrested in the Netherlands on 15 September is one of the alleged leaders of ShinyHunters, the extortion group linked to more than 140 breaches since last year and at least $70 million in payments. The group has reportedly denied any connection to him. Arrests make good headlines, but they patch nothing. What matters for UK boards is how this group gets in, because it is rarely by clever exploits.

What is new

We covered ShinyHunters and the PeopleSoft firewall fix on 28 September. The new part is the arrest. Dutch National Police detained a 24-year-old in Amsterdam, and a Rotterdam court has ordered him held for at least 90 days. The FBI's Brett Leatherman told the rest of the group that "the longer you stay in this, the more we learn about you". No technical evidence tying him to specific breaches is public, so treat "leader" as an allegation.

The front desk, not the lock

Picture an office with a very good lock on every door. Now picture a receptionist who will hand over a master key to anyone who sounds convincing on the phone. BleepingComputer reports that the group targets single sign-on accounts, third-party vendors and software-as-a-service platforms such as Salesforce and Snowflake. Once a criminal holds a genuine employee login, the systems see an ordinary user. They pull data out in bulk, then threaten to publish it unless someone pays.

There is no malware to detect. The signs are an unusual login, a new device on a familiar account, or an export far larger than normal. If nobody watches volume, the first alert is the extortion email.

The UK exposure

The University of Nottingham is the reminder. In June, BleepingComputer reported that ShinyHunters had posted evidence on its leak site, and the university confirmed a breach of its student records system. It told the Information Commissioner's Office and Action Fraud. About 454,600 current students and alumni were affected, with more than 40GB of documents stolen, including passport numbers, ethnicity and disability details. That incident sat within the wider PeopleSoft campaign, which BleepingComputer put at over 100 organisations.

The Secure by Design lesson

Four design decisions would have narrowed this, and none needs a new product.

The cost is mostly process and patience: a few weeks of rollout friction, some annoyed staff and a supplier conversation. Set that against an ICO notification and 454,600 letters. In my opinion, the arrest is worth reading as a prompt for one question: if a criminal rang our helpdesk today, what would stop them?

Also this week

Fake ChatGPT, real malware. Huntress reports that attackers built Custom GPTs impersonating genuine ChatGPT models and promoted them through Google Ads. The bot sent users to a "Service Availability Notice" on a Google Sites page, which coaxed them into running a PowerShell command and starting an eight-stage infection that ends in a remote access trojan. Huntress counted at least 40 incidents from that domain, two confirmed as starting in a Custom GPT. OpenAI removed the first GPT by 25 September, but Huntress found a second still live when it published. A trusted domain is not a trusted author.

A poisoned AI plugin. Security firms including SafeDep, Socket and StepSecurity found credential-stealing code in npm and PyPI packages from MemTensor, a maker of AI memory tooling. The bad releases are npm plugin versions 0.1.21, 0.1.23 and 0.1.25, and PyPI MemoryOS 2.0.34. SafeDep says the attacker obtained publishing tokens by pushing commits that made MemTensor's own release workflow hand them over. The implant can reportedly spread itself into other packages and workflows. Pin to npm version 0.1.20 or PyPI 2.0.33, and rotate any secrets that were exposed. Release pipelines deserve the same access controls as production.

Spectre returns to the JIT. Researchers at VUSec and Scuola Superiore Sant'Anna describe Branch Target Reuse, a Spectre v2 variant, which they say can recover a Linux root password hash within minutes on a fully patched Intel system with default protections. The Linux kernel flaws are CVE-2026-64507 and CVE-2026-64508, and fixes are merged. This is a research result, not a report of attacks. It matters most on shared machines that run untrusted code.

Sources

If you want a second pair of eyes on your sign-in, helpdesk or supplier access, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.