FBI and Dutch Police Arrested Alleged ShinyHunters Hackers Group Leader

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


FBI Director Kash Patel has announced the arrest of an alleged leader of ShinyHunters, the cyber-extortion group linked to attacks across the United States, the Netherlands, and other countries.

Dutch police detained the 24-year-old Amsterdam suspect on September 15 under Dutch law, with FBI investigators supporting the operation and pursuing leads.

Although Dutch authorities did not publicly name the suspect, Neo Security chief executive Benjamin Korper identified him as Pepijn van der Stap, the company’s offensive security lead.

Patel described the detainee as “one of the alleged leaders” of ShinyHunters and thanked Dutch police and private-sector partners for sharing information, emphasizing that the investigation remains active.

Dutch police said Van der Stap is suspected of participating in a criminal organization connected to ShinyHunters, a hacking and extortion operation associated with breaches involving organizations including Ticketmaster, Pornhub and Dutch telecom provider Odido. Investigators seized several data-storage devices and are examining their contents, while authorities have warned that further arrests remain possible.

A Rotterdam court has ordered the suspect to remain in pretrial detention for 90 days. Police also said information recovered from his laptop led to a separate suspicion that he attempted to solicit two murders abroad. Officials stressed that those allegations are distinct from the ShinyHunters investigation, and all accusations remain unproven unless established in court.

The arrest became public shortly after ShinyHunters claimed it had compromised FBIJobs.gov, the bureau’s recruitment portal. The group alleged that it stole records concerning FBI personnel and job applicants.

A sample reviewed by journalists reportedly contained names, home addresses, telephone numbers, birth dates, Social Security numbers, emergency contacts, and details about relatives and assignments.

The exposed assignment data may be damaging. Reuters found entries referencing personnel working on China, Russia, Iran, Hezbollah, human intelligence, surveillance and covert-access functions. Such information could facilitate targeted phishing, identity fraud, doxing, swatting, extortion or counterintelligence targeting of employees and their families.

However, the FBI has not publicly validated the attackers’ full account. The bureau confirmed that it was investigating unauthorized activity affecting FBIJobs.gov and possible exposure of employee personally identifiable information, but said the initial point of compromise, whether within an FBI environment or a third-party provider, remained undetermined. ShinyHunters’ claim that it stole between two and three terabytes of material also remains unverified

Van der Stap had already been convicted in 2023 for hacking, data theft and extortion. He later publicly denied cybercrime and returned to legitimate security work, creating a striking contrast with the new allegations.

ShinyHunters, meanwhile, denied any association between Van der Stap and the group. That denial, coupled with the absence of publicly disclosed technical evidence tying him to the FBI incident, means claims about his precise role should be treated cautiously. Dutch police also clarified that his arrest was not made as part of the separate investigation into the Odido breach.

The coordinated action, however, demonstrates how cross-border intelligence sharing can turn digital evidence into arrests. Authorities are now analyzing seized devices, tracing potential collaborators and developing new leads.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post FBI and Dutch Police Arrested Alleged ShinyHunters Hackers Group Leader appeared first on Cyber Security News.