NEWS

Alleged ShinyHunters Leader Arrested in the Netherlands

Dutch police arrested a 24-year-old Amsterdam man tied to ShinyHunters on Sept. 15 — a week before the group claimed to hack the FBI.

Dylan H.

News Desk

September 30, 2026
7 min read
Alleged ShinyHunters Leader Arrested in the Netherlands

Dutch Police Arrest Alleged ShinyHunters Leader

The Dutch National Police, working with the FBI, announced on September 29, 2026, the arrest of a 24-year-old man from Amsterdam on suspicion of participating in a criminal organization tied to ShinyHunters, the prolific data-extortion group linked to breaches at more than 140 organizations and at least $70 million in extortion payments since 2025. The man was taken into custody on September 15, 2026 — meaning he was already in Dutch custody a full week before ShinyHunters publicly claimed to have breached an FBI jobs portal and stolen personal data on agents and job applicants, a claim first reported on September 22 by 404 Media. Independent journalist Brian Krebs identified the suspect as Pepijn van der Stap, a previously convicted cybercriminal who had also worked as a cybersecurity professional; Dutch authorities have not officially released his name. A court in Rotterdam has ordered him held in pretrial detention for 90 days.


AttributeValue
Suspect24-year-old man from Amsterdam, identified by press (not police) as Pepijn van der Stap
Arresting agenciesDutch National Police, with FBI support
Arrest dateSeptember 15, 2026
Public announcementSeptember 29, 2026
CourtRotterdam — 90-day pretrial detention ordered
GroupShinyHunters — active since 2025
Alleged scale140+ organizations breached; ≥$70 million in extortion payments
Named prior victims (per Dutch police)Ticketmaster, Pornhub, Odido (Dutch telecom)
Separate allegationSuspected of soliciting two murders abroad, per evidence on his laptop — police say this is unrelated to the ShinyHunters probe
FBI hack claimShinyHunters claimed on Sept. 22 to have breached FBIJobs.gov and stolen agent/applicant PII

Who Is ShinyHunters

ShinyHunters is a data-theft-and-extortion operation that has been one of the most active threat actors CosmicBytez Labs has tracked over the past year, responsible for claimed or confirmed breaches at Panera Bread, Figure Technology, Harvard and the University of Pennsylvania, Telus Digital, ADT, Medtronic, Infinite Campus, 7-Eleven, Instructure/Canvas, Salesforce-connected environments, and dozens of other organizations, frequently via Oracle PeopleSoft and third-party SaaS compromises rather than direct network intrusions. FBI Assistant Director Brett Leatherman said in a statement that "this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments" since the group's activity ramped up in 2025. Dutch police separately tied the suspect to breaches at Ticketmaster, Pornhub, and Dutch telecom provider Odido.

Timeline: Arrest Preceded the FBI Breach Claim

The sequence of events is the most notable element of this story. Van der Stap was arrested in Amsterdam on September 15, but ShinyHunters did not publicly claim the FBI breach until September 22, when the group defaced the FBIJobs.gov portal with a message reading "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS" and began distributing files it said contained names, addresses, phone numbers, and spouse/family information for thousands of FBI agents and applicants. That means an alleged leader of the group was already in Dutch custody when the FBI hack was announced — a detail that has fueled speculation about whether the breach was executed by remaining members, was staged using already-exfiltrated data, or was timed as retaliation for the arrest. The group had separately demanded the FBI retract a May public-service-announcement naming ShinyHunters, setting a September 29 deadline — the same day the arrest was made public.

Evidence, Charges, and the Murder Allegation

Dutch investigators said they recovered a "large amount of evidence" from the suspect's laptop connecting him to the ShinyHunters organization, along with several seized data-storage devices still under analysis. Separately, and — according to Dutch police — unrelated to the ShinyHunters investigation, evidence on the same laptop led to a suspicion that the man had solicited two murders abroad. Police were explicit that this allegation stands apart from the cybercrime case. FBI Director Kash Patel confirmed the arrest publicly, stating that "FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest," and a senior FBI cyber official released an unusual public video urging remaining ShinyHunters members to turn themselves in. Authorities have warned that further arrests are possible as the device analysis continues.

Impact Assessment

Impact AreaDescription
Law enforcement momentumFirst named/identified arrest tied directly to ShinyHunters leadership after more than a year of breaches attributed to the group
Group continuityArrest of an alleged leader does not appear to have stopped operations — the FBI breach claim surfaced a week later, suggesting other members remain active
FBI data exposureIf verified, the FBIJobs.gov compromise exposes PII (names, addresses, phone numbers, SSNs, spouse/family data) on agents and applicants, a significant insider-safety concern
Victim organizationsDozens of previously breached organizations (Ticketmaster, Pornhub, Odido, and the broader 140+ tally) may see renewed scrutiny as case evidence is analyzed
Ongoing investigationSeized storage devices could surface additional victim organizations, co-conspirators, or infrastructure not yet publicly attributed to ShinyHunters
Legal process90-day Dutch pretrial detention with formal charges still pending as investigators build the case

Recommendations

For Organizations Previously Notified of a ShinyHunters-Linked Breach

  • Treat this arrest as a signal, not a resolution — data believed already stolen by ShinyHunters or its affiliates should still be assumed to be circulating or for sale regardless of the group's leadership status.
  • Revisit any outstanding extortion communications tied to your incident; do not resume contact or negotiation based on the assumption the group is disrupted.
  • Confirm with legal counsel and breach-notification counsel whether this development affects any pending regulatory disclosure timelines.

For Security Teams Monitoring Data-Extortion Groups

  • Continue monitoring ShinyHunters' and affiliated leak-site activity — the group has previously rebranded, absorbed, or collaborated with other extortion crews (e.g., its takeover of the Cl0p leak site), and arrests of individual members rarely end group operations.
  • Track Oracle PeopleSoft and Salesforce-connected SaaS exposure specifically, as these remain the group's most consistent initial-access vector across its confirmed victim list.
  • Flag any inbound extortion contact referencing ShinyHunters for law-enforcement coordination — active investigations mean fresh intelligence may be usable by the FBI or Dutch authorities.

For Individuals Potentially Affected by the FBI Data Claim

  • FBI employees, applicants, and their families should watch for phishing, SIM-swap attempts, or physical-safety-related contact that could stem from exposed home addresses and family details.
  • Enable credit monitoring and fraud alerts if notified that your information was part of the FBIJobs.gov-linked exposure.
  • Report suspicious contact referencing personal details to FBI security personnel through official internal channels rather than any address supplied by an unverified party.

Key Takeaways

  1. Dutch police, working with the FBI, arrested a 24-year-old Amsterdam man on September 15, 2026, on suspicion of participating in the ShinyHunters criminal organization; the arrest was publicly announced September 29.
  2. The suspect, identified by journalists (not police) as Pepijn van der Stap, was already in custody a full week before ShinyHunters publicly claimed to have breached the FBI's jobs portal on September 22.
  3. The FBI's Brett Leatherman said the group and its co-conspirators allegedly breached more than 140 organizations and collected at least $70 million in extortion payments since 2025.
  4. A Rotterdam court ordered 90 days of pretrial detention; investigators are still analyzing seized data-storage devices and have not ruled out further arrests.
  5. A separate, laptop-derived allegation that the suspect solicited two murders abroad is being treated by Dutch police as unrelated to the cybercrime case.
  6. The arrest has not visibly slowed ShinyHunters' operations — the FBI breach claim, the Cl0p leak-site takeover, and other recent campaigns suggest the group's broader membership remains active.

Sources