· via TechCrunch
Dutch police arrest alleged ShinyHunters leader tied to 140 breaches and FBI intrusion
Dutch police arrested a 24-year-old Amsterdam man identified in reports as an alleged ShinyHunters leader, a gang blamed for 140+ breaches and an FBI portal intrusion.

Arrest in Amsterdam
Dutch police have arrested a 24-year-old man from Amsterdam on suspicion of participating in a criminal organization, a charge that refers to the hacking collective ShinyHunters, according to TechCrunch. The FBI and Dutch authorities accuse the group of breaking into more than 140 organizations around the world, and its members claimed responsibility for an intrusion into the FBI's own systems earlier in September.
Brett Leathermann, who leads the FBI's cyber division, said in a video message on Tuesday that Dutch authorities had arrested one of the alleged leaders of ShinyHunters, adding that the Dutch High Tech Crime Unit had acted quickly to protect victims and secure evidence. He pledged that the bureau would pursue the group's remaining members.
Dutch police confirmed the arrest took place on September 15 under Dutch law, that the man appeared in court on Tuesday, and that he has been remanded into custody for at least 90 days.
Independent security journalist Brian Krebs was first to report the arrest, and coverage by Krebs and other outlets identified the man as Pepijn van der Stap. Bloomberg profiled him in 2024 as a cybersecurity researcher who also moonlighted as a criminal hacker extorting companies. According to recent reporting by Bloomberg and Reuters, police detained van der Stap at the offices of Neo Security, where he works as chief technology officer, in a raid that reportedly involved flash-bang grenades. Neo Security did not respond to a request for comment from TechCrunch, while a representative for ShinyHunters told the outlet that van der Stap has no association with the group.
A laptop with murder plans
According to Dutch police, investigators found substantial material on the man's laptop after seizing his devices, including information about two murders that were to be carried out abroad. He is consequently also under investigation for attempting to orchestrate those killings, a probe the authorities emphasized is separate from the ShinyHunters case.
ShinyHunters' track record
ShinyHunters is described by the authorities as a criminal gang that hacks companies, steals large troves of data, and threatens to publish it unless victims pay a ransom. Dutch officials said the group is accused of breaches at Pornhub, Ticketmaster, and U.S. telecom giant AT&T. The group also claimed responsibility for a breach of Dutch phone provider Odido, though police noted that the arrested man is not being held in connection with that incident.
The FBI breach
The arrest comes shortly after the FBI reportedly warned its own agents and employees that their names, addresses, job titles and Social Security numbers were exposed in a cybersecurity incident. The bureau has not publicly confirmed a breach, but ShinyHunters said it obtained personal and sensitive data on what it described as almost all of the FBI's agents and applicants by compromising the agency's careers website and job application portal.
Within a sample of roughly 5,000 agents whose data was taken from the portal, reporters also found records relating to blood and urine samples and psychiatric evaluations, fueling fears of a serious counterintelligence exposure if an adversarial government were to obtain the material.
Leathermann did not respond when contacted by TechCrunch, and an FBI spokesperson declined to answer questions about the arrest. ShinyHunters, for its part, told TechCrunch that the FBI intrusion was not financially motivated, saying it was intended to dispute what the group calls false allegations the bureau has made about it, and that the stolen data will not be published.
Why it matters
This is one of the most significant cybercrime enforcement actions in recent memory: a single arrest that touches a group blamed for more than 140 breaches, several among the largest data thefts on record, and an unprecedented compromise of the FBI's own recruitment systems. The case also illustrates how cybercrime investigations can spill into the physical world, with authorities saying they found plans for two contract-style killings on the suspect's laptop. The FBI breach, meanwhile, shows that even the agencies pursuing these groups are targets, and that exposed personnel files, medical samples and psychiatric records create risks far beyond ordinary data extortion. Finally, the reported profile of the suspect, a security firm CTO allegedly leading a double life as an extortionist, underlines how blurred the line between security research and criminal hacking has become.
- #cybercrime
- #data-breach
- #fbi
- #shinyhunters
- #security