ShinyHunters has resurfaced at a new dark-web address after its website suddenly disappeared, with the cybercrime group denying speculation that law enforcement had taken its infrastructure offline.
The disappearance attracted attention because it happened shortly after an ultimatum ShinyHunters issued to the FBI expired. The group had demanded changes to an FBI advisory describing its operations, while US investigators had simultaneously stepped up pressure on the hackers following the arrest of an alleged member in the Netherlands.
ShinyHunters now says those events had nothing to do with its website going offline. According to the group, it voluntarily moved the site while carrying out infrastructure upgrades following distributed denial-of-service attacks from a rival and separate problems affecting the data centers supporting its infrastructure.
The previous address remains unavailable, but a replacement dark-web site has appeared with additional protections intended to reduce disruption from DDoS attacks. The group confirmed that the new address belongs to its operation, indicating that the earlier outage did not represent the end of its leak platform.
ShinyHunters is particularly well known in the Netherlands because of its February attack against telecom provider Odido. The company says attackers contacted customer service while pretending to be members of its IT department and used voice phishing to obtain access to internal systems.
The attackers ultimately stole information belonging to approximately 6.2 million people. Odido refused to pay the hackers’ ransom demand, after which the stolen information was published on the dark web.
Odido later acknowledged that it initially failed to recognize that such a large amount of information had been taken. Although the compromised account was blocked within roughly an hour, the attackers had already downloaded millions of customer records during that period.
The ShinyHunters investigation recently resulted in the arrest of a 24-year-old Amsterdam man. Dutch authorities have not publicly named him, although multiple reports and his employer have identified him as Pepijn van der Stap, a previously convicted hacker who later moved into professional cybersecurity work.
The FBI has described the detained man as one of ShinyHunters’ alleged leaders. Dutch police say he was arrested on suspicion of participating in a criminal organization, while investigators continue examining digital evidence seized during the operation.
ShinyHunters strongly disputes the authorities’ characterization and says Van der Stap has no connection to its current operation. The group has also denied that his arrest disrupted its activities, while authorities have not publicly detailed all of the evidence they say connects him to ShinyHunters.