FBI, Dutch Police Arrest Alleged ShinyHunters Leader
Key Takeaways A 24-year-old Dutch national, identified as Pepijn van der Stap, has been arrested in Amsterdam in connection with the ShinyHunters cyber-extortion group. The suspect is alleged to be a...
Key Takeaways
- A 24-year-old Dutch national, identified as Pepijn van der Stap, has been arrested in Amsterdam in connection with the ShinyHunters cyber-extortion group.
- The suspect is alleged to be a leader within ShinyHunters, a group linked to high-profile breaches affecting organizations like Ticketmaster, Pornhub, and Odido.
- The arrest follows ShinyHunters’ recent claim of breaching FBIJobs.gov and stealing sensitive data on FBI personnel and applicants, though the FBI has not fully corroborated the extent of this breach.
- Van der Stap was previously convicted in 2023 for hacking and extortion, raising questions about his public denial of cybercrime and subsequent return to legitimate security work.
Alleged ShinyHunters Leader Arrested in Joint FBI-Dutch Operation
In a significant development in the global fight against cybercrime, authorities have apprehended an individual suspected of leading the notorious ShinyHunters cyber-extortion group. FBI Director Kash Patel announced the arrest of a 24-year-old Amsterdam resident, detained by Dutch police on September 15. The operation received substantial support from FBI investigators, who continue to pursue leads in the ongoing investigation.
Table Of Content
- Key Takeaways
- Alleged ShinyHunters Leader Arrested in Joint FBI-Dutch Operation
- Suspect Identified as Pepijn van der Stap
- Pre-Trial Detention and Separate Allegations
- FBIJobs.gov Breach Claims and Data Implications
- Prior Conviction and Denials
- Cross-Border Cooperation and Future Outlook
- What You Should Do
Suspect Identified as Pepijn van der Stap
While Dutch authorities have not publicly named the suspect, Benjamin Korper, CEO of Neo Security, identified the individual as Pepijn van der Stap, who serves as the offensive security lead at his company. Director Patel described the detainee as “one of the alleged leaders” of ShinyHunters, extending gratitude to Dutch police and private-sector partners for their crucial information sharing. Patel emphasized the active nature of the investigation.
On September 29, 2026, Director Patel posted on X:
Dutch police confirmed that Van der Stap is suspected of participation in a criminal organization linked to ShinyHunters. This hacking and extortion group has been implicated in high-profile breaches targeting entities such as Ticketmaster, Pornhub, and the Dutch telecommunications provider Odido. Investigators have seized multiple data-storage devices, which are currently undergoing analysis. Authorities caution that additional arrests in connection with the case remain a possibility.
Pre-Trial Detention and Separate Allegations
A Rotterdam court has mandated Van der Stap’s continued pre-trial detention for a period of 90 days. Separately, police revealed that information recovered from his laptop led to suspicion that he attempted to solicit two murders abroad. Officials were careful to stress that these grave allegations are distinct from the ShinyHunters investigation, and all accusations remain unproven until established in a court of law.
FBIJobs.gov Breach Claims and Data Implications
The arrest became public shortly after ShinyHunters asserted a compromise of FBIJobs.gov, the bureau’s official recruitment portal. The group claimed to have exfiltrated sensitive records pertaining to FBI personnel and job applicants. A sample reportedly reviewed by journalists included names, home addresses, telephone numbers, birth dates, Social Security numbers, emergency contacts, and details about relatives and assignments.
The potential exposure of assignment data is particularly concerning. Reports indicate entries referencing personnel involved in operations related to China, Russia, Iran, Hezbollah, human intelligence, surveillance, and covert-access functions. Such information could be exploited for targeted phishing campaigns, identity fraud, doxing, swatting, extortion, or counterintelligence targeting of employees and their families.
The FBI has not yet publicly validated the full extent of the attackers’ claims. The bureau confirmed an investigation into unauthorized activity affecting FBIJobs.gov and the potential exposure of personally identifiable information. However, the initial point of compromise, whether within an FBI environment or a third-party provider, remains undetermined. ShinyHunters’ assertion of stealing between two and three terabytes of material also remains unverified.
Prior Conviction and Denials
Van der Stap had a prior conviction in 2023 for hacking, data theft, and extortion. Following this, he publicly disavowed cybercrime and transitioned back into legitimate security work, creating a stark contrast with the current allegations. Interestingly, ShinyHunters has denied any association between Van der Stap and their group. This denial, coupled with the lack of publicly disclosed technical evidence directly linking him to the FBI incident, suggests that claims about his precise role should be approached with caution. Dutch police have also clarified that his arrest was not part of the separate investigation into the Odido breach.
Cross-Border Cooperation and Future Outlook
Despite the complexities, this coordinated action underscores the effectiveness of cross-border intelligence sharing in converting digital evidence into tangible arrests. Authorities are now meticulously analyzing seized devices, tracing potential collaborators, and developing new leads as the investigation progresses.
What You Should Do
- Monitor for Identity Theft: Individuals concerned about potential data exposure from the FBIJobs.gov breach should closely monitor their credit reports and financial statements for any suspicious activity.
- Implement Multi-Factor Authentication (MFA): Ensure MFA is enabled on all critical accounts, especially those containing sensitive personal information.
- Be Wary of Phishing Attempts: Exercise extreme caution with unsolicited emails, messages, or calls, particularly those requesting personal information or prompting urgent action.
- Update Passwords: Regularly change passwords for important accounts, using strong, unique combinations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.