FBI and Dutch Police Arrest Alleged ShinyHunters Member Linked to Global Hacks and Murder Plot
Quick Look
- FBI and Dutch authorities arrested a 24-year-old man from Amsterdam suspected of being a leader of the ShinyHunters hacking group, which is linked to over 140 global breaches including AT&T, Ticketmaster, and Pornhub.
- The suspect is also under investigation for allegedly plotting murders abroad after data on two planned killings was found on his seized laptop.
- The arrest follows a separate FBI cyber incident where agents’ personal data was exposed, which ShinyHunters claimed responsibility for, stating it was meant to dispute FBI allegations against them.
AI-generated summary
Why It Matters
ShinyHunters is a cybercriminal group known for stealing data from companies and extorting them by threatening to leak the information. The group has claimed responsibility for breaches at major corporations including AT&T, Ticketmaster, and Pornhub, as well as Dutch telecom provider Odido. The FBI reported a separate cyber incident exposing agents’ personal data, which ShinyHunters claimed responsibility for, stating it was intended to dispute FBI allegations against them.
The FBI and Dutch law enforcement say they have arrested a member of the ShinyHunters hacking group, which the agencies say are responsible for hacks on over 140 organizations around the world. The hackers also claimed responsibility for a breach of the FBI’s own systems earlier this month.
Brett Leathermann, the FBI’s cyber division lead, said in a video message on Tuesday that Dutch authorities had arrested one of the “alleged leaders of ShinyHunters.” Leathermann added that the Dutch High Tech Crime Unit “moved quickly to protect victims and preserve critical evidence,” and vowed that the bureau would go after the rest of the hackers following the arrest.
In a separate statement, Dutch police confirmed that an unnamed 24-year-old man from Amsterdam was arrested under Dutch law on September 15. The man was scheduled to appear in court on Tuesday, and has been remanded into custody for at least 90 days.
The police say the man was arrested for “participating in a criminal organization,” referring to ShinyHunters.
Following his arrest and seizure of his devices, the police said “a lot of information was found on his laptop, including about two murders that should be committed abroad.” As such, he is also being investigated for attempting to orchestrate the murders. The Dutch authorities said this is “separate from the investigation into ShinyHunters.”
ShinyHunters is a cyber criminal gang that are accused of hacking into companies to steal reams of data and then threatening to publish the data if its victims do not pay a ransom. The Dutch authorities said the gang are accused of data breaches at Pornhub, Ticketmaster, and U.S. telco giant AT&T. The hacking group also took responsibility for a breach of Dutch phone provider Odido. However, the authorities said that the man they took into custody has not been arrested in relation to the Odido hack.
Independent security journalist Brian Krebs, who was first to report the arrest, and other media outlets have named the arrested man as Pepijn van der Stap, who was profiled by Bloomberg in 2024 as a cybersecurity researcher who also moonlighted as a criminal hacker who extorted companies.
According to recent reporting by Bloomberg and Reuters, Van der Stap was arrested earlier this month by police at the offices of Neo Security, where Van der Stap is employed as chief technology officer. The raid reportedly involved flash-bang grenades.
A representative for Neo Security did not immediately respond to TechCrunch’s request for comment. When asked by TechCrunch, a representative of the ShinyHunters group told TechCrunch that Van der Stap “has no association with us.”
News of the arrest comes days after the FBI reportedly told its own agents and employees that their personal information, including their names, addresses, job titles and Social Security numbers, were exposed in a “cyber security incident.” The FBI has not yet publicly confirmed a breach, but the ShinyHunters gang said it took personal and sensitive data belonging to “mostly all” of the FBI’s agents and applicants by breaching its careers website and job application portal.
Among the sample of 5,000 or so agents who had data stolen from the portal, reporters have also found data relating to agents’ blood and urine samples, as well as psychiatric reports, which sparked fears of a major counterintelligence challenge to prevent an adversarial government from obtaining the data.
When contacted by TechCrunch, Leathermann did not comment. An FBI spokesperson declined to comment on our questions relating to the arrest.
For their part, the ShinyHunters hackers reiterated that the breach of the FBI’s servers was not a financially motivated attack, but was intended to challenge public claims made by the FBI, which the hackers say contain false allegations about the group. The hackers told TechCrunch that they will not publish the stolen FBI data, and added that the breach was “to make a point and to dispute the allegations made against us and we have done so.”
What to Watch
AI outlook — possibilities, not facts
Additional members of the ShinyHunters group will be arrested in connection with the global hacking campaign.
Likely · Within weeks
The suspect will face charges related to both cybercrime and attempted murder plotting.
Possible · Within months
Open Questions
- What is the full extent of the data stolen from the FBI’s career portal?
- Has the suspect been formally charged with attempting to orchestrate murders?
- Will the seized laptop data lead to additional arrests in the ShinyHunters network?
- Is there any connection between the suspect’s role at Neo Security and the alleged hacking activities?







