IT-PUB NEWS

Dutch police arrest ShinyHunters suspect in FBI breach case

01.10.2026 13:03 • Author: IT-PUB
Dutch police arrest ShinyHunters suspect in FBI breach case

Dutch authorities detained a 24-year-old Amsterdam man and say evidence on his laptop also triggered a separate investigation into planned murders abroad.

Dutch police have arrested a suspected member of the ShinyHunters hacking group, in a case that now sits at the intersection of cybercrime, data theft and a much more serious criminal investigation. The arrest came as the group was also claiming responsibility for a breach of FBI systems, pushing the case further into the spotlight. Authorities say the suspect is tied to a network accused of attacks on more than 140 organizations worldwide. Police also say material found on his laptop pointed to two planned murders abroad.

Dutch police say the suspect was arrested on September 15

The FBI and Dutch law enforcement said the arrest took place in the Netherlands, where authorities detained one of the “alleged leaders of ShinyHunters.” In a video message on Tuesday, Brett Leatherman, who leads the FBI’s cyber division, said Dutch investigators “moved quickly to protect victims and preserve critical evidence.”

Dutch police later confirmed that the arrested person is a 24-year-old man from Amsterdam. According to their statement, he was taken into custody on September 15 under Dutch law and was scheduled to appear in court on Tuesday. He has been remanded in custody for at least 90 days.

Police said the arrest was made for “participating in a criminal organization,” referring to ShinyHunters. As IT-PUB News notes, that framing places the case not only in the realm of hacking, but in a broader organized-crime investigation.

Evidence on his laptop opened a second investigation

The most striking part of the Dutch announcement was the claim that police found information on the suspect’s laptop about “two murders that should be committed abroad.” On that basis, he is also being investigated for attempting to orchestrate the killings.

Dutch authorities stressed that this line of inquiry is separate from the ShinyHunters case. In other words, the hacking investigation and the murder-related investigation are being handled as distinct matters.

That distinction matters. It suggests the arrest could have consequences beyond a cybercrime case, while also showing how digital evidence can expose other alleged criminal activity once devices are seized and examined.

ShinyHunters is accused of extortion-style data theft

Authorities describe ShinyHunters as a cybercriminal gang that breaks into companies, steals large amounts of data and then threatens to publish it unless victims pay ransom. Dutch authorities said the group is accused of breaches at Pornhub, Ticketmaster and U.S. telecom giant AT&T.

The group also claimed responsibility for a breach of Dutch phone provider Odido. Dutch authorities said, however, that the man now in custody was not arrested in connection with that attack.

The case has drawn attention because ShinyHunters is not being treated as a one-off hacking crew. Investigators say it has been linked to major incidents affecting consumer-facing companies and telecoms, which can put personal data, account access and private communications at risk.

The FBI breach claim put added pressure on the case

The arrest drew even more attention because it came days after the FBI reportedly told its own agents and employees that their personal information had been exposed in a “cyber security incident.” The information reportedly included names, addresses, job titles and Social Security numbers.

The FBI has not publicly confirmed a breach. ShinyHunters, though, said it obtained personal and sensitive data belonging to “mostly all” of the FBI’s agents and applicants. According to the group, the data came from the bureau’s careers website and job application portal.

Reporters reviewing a sample of around 5,000 agents whose data was allegedly taken from the portal found additional sensitive material, including blood and urine samples and psychiatric reports. That raised concerns about a possible counterintelligence problem if hostile actors were able to access the information.

For the public, the significance is fairly direct: if the claims are accurate, the breach could expose highly sensitive information about law enforcement personnel and applicants, not just ordinary account details. For the FBI, it also underscores the challenge of protecting large digital systems that store personal data at scale.

Media outlets named the suspect, but police have not

Dutch police did not publicly identify the arrested man, but independent security journalist Brian Krebs, who first reported the arrest, and other media outlets named him as Pepijn van der Stap. Bloomberg had previously profiled him in 2024 as a cybersecurity researcher who also allegedly worked as a criminal hacker and extorted companies.

Recent reporting by Bloomberg and Reuters said van der Stap was arrested earlier this month at the offices of Neo Security, where he worked as chief technology officer. Those reports said the raid involved flash-bang grenades.

Neo Security did not immediately respond to TechCrunch’s request for comment. A representative for ShinyHunters, when asked by TechCrunch, said van der Stap “has no association with us.”

Because police have not publicly named the suspect, those identifications remain media reports rather than official confirmation in the source material.

ShinyHunters says the FBI breach was meant to make a point

The group’s response adds another layer to the story. ShinyHunters told TechCrunch that the breach of the FBI’s servers was not financially motivated. Instead, it said the intrusion was meant to challenge public claims made by the FBI, which the group says contain false allegations about it.

ShinyHunters also said it would not publish the stolen FBI data. According to its statement, the breach was “to make a point and to dispute the allegations made against us and we have done so.”

That claim does not make the incident less serious. Even if the data is not published, a breach involving law-enforcement personnel and applicants would still be highly sensitive because of the personal and operational information it may expose.

A cybercrime case with consequences beyond hacking

The arrest shows how a cybercrime investigation can quickly spill into broader criminal territory. On one side is ShinyHunters’ alleged role in high-profile data theft and extortion. On the other is the separate murder-related inquiry triggered by what police say they found on the suspect’s laptop.

It also underlines the pressure on companies and public institutions to protect systems that hold large amounts of personal data. When those systems are breached, the fallout can extend far beyond passwords or account records. In this case, the reported data range includes law-enforcement identities, sensitive personal details and, according to police, material tied to alleged violent plans.

For now, Dutch authorities say the man remains in custody while the investigations continue. The FBI, meanwhile, has not publicly confirmed the breach it was reportedly warning its own staff about, leaving the case suspended between law-enforcement action, cybercrime allegations and an unresolved question over how much data was actually taken.


Improve SEO for a small/medium business website for $50