Slovak News

Science & Tech · Netherlands, United States of America

Dutch Police Arrest Suspected ShinyHunters Leader Over FBI Hack Claim

A 24-year-old Amsterdam man, identified as Pepijn van der Stap, has been detained since 15 September in a Dutch investigation into the hacking group ShinyHunters, which claims to have stolen FBI personnel data.

Live version 1 · updated 6 sources · 2 perspectives
Foto: The Jerusalem Post · source

What's new

  • Dutch police confirm a 24-year-old Amsterdam man has been held since 15 September over ties to ShinyHunters
  • FBI director Kash Patel says the suspect is one of the group's alleged leaders
  • Investigators say the suspect's laptop contained material pointing to attempted solicitation of two murders abroad
  • ShinyHunters publicly denies any link to the identified suspect, Pepijn van der Stap

Authorities in the Netherlands have taken a 24-year-old Amsterdam resident into custody, named by security journalists as Pepijn van der Stap, over alleged membership in the ShinyHunters hacking group, which says it broke into FBI systems and took personnel records. The man has been held since his arrest on 15 September, and a Rotterdam court has ordered 90 days of pretrial detention.1346

Arrest and detention

Dutch police confirmed this month's detention of an Amsterdam man, 24, as part of a probe into the ShinyHunters hacking collective, stating: "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters." FBI director Kash Patel said the operation was conducted jointly with Dutch counterparts and characterized the individual in custody as among the group's purported leaders.126

Wire services report that officers used flash-bang devices during the operation to take him into custody, and Dutch forensics teams later inspected the premises of Neo Security, the cybersecurity company employing the suspect. A Rotterdam court ordered 90 days of pretrial detention, and police seized data-storage devices from the suspect's location.26

Cybersecurity reporter Brian Krebs named the detainee as Pepijn van der Stap, who served as offensive security lead at Neo Security, having earlier held a role at cybersecurity firm Hadrian and contributed as a volunteer to the Dutch Institute for Vulnerability Disclosure. Court records show Van der Stap was found guilty of stealing data and extortion back in 2023, and case documents indicate he began his position at Neo Security following his prison release the previous year.3426

Murder allegations

Investigators also believe he may have tried to arrange for two killings overseas, a suspicion that arose after they discovered pertinent information stored on his laptop, according to police. Dutch police said: "information recovered from his laptop led to a separate suspicion that he attempted to solicit two murders abroad." ShinyHunters responded to the allegation by saying, "This was not a threat. Nothing will happen."162

The FBI hack claim

ShinyHunters has claimed responsibility for breaching the FBI's job application site, FBIJobs.gov, and stealing sensitive data on FBI staff and applicants, according to the group's own statements. The purportedly compromised information reportedly covers full names, residential addresses, phone numbers, dates of birth, Social Security numbers, emergency contact information and job assignment records; a single source further reported that details on intelligence-related duties and medical files were also included. The FBI said it was investigating unauthorised activity affecting FBIJobs.gov and stated that "the initial point of compromise, whether within an FBI environment or a third-party provider, remained undetermined."652

According to the BBC, ShinyHunters claimed to have stolen information on all FBI bureau staff, roughly 38,000 employees, including names, roles, badge numbers, home addresses and phone numbers, and said it breached FBI servers on 21 September; the BBC said it had seen a portion of the data and that it appeared genuine. ShinyHunters' claim to have taken between two and three terabytes of material remains unverified, and the FBI has not publicly validated the group's full account of the breach.16

ShinyHunters said the operation was not carried out for money. The group stated: "We again want to emphasise that this is not extortion, it was never one to begin with," and separately described the episode as, "This was all a marketing campaign to protect our business and actively combat disinformation." An FBI advisory issued in May had described ShinyHunters as threat actors who use exaggerated claims to prompt payment.41

ShinyHunters' denial

ShinyHunters has denied that Van der Stap has any connection to the group. The group said: "That individual has no association with us. Frankly, we are laughing," adding separately that the arrest amounted to Dutch police "seeking publicity and public approval following their significant embarrassment." Neo Security's CEO, Benjamin Korper, said he commissioned an independent probe into whether Van der Stap had worked against the firm or its customers, which turned up nothing incriminating; Korper remarked, "Absolutely everybody I talked to is flabbergasted."3542

Van der Stap himself has said he tried to move away from criminal hacking after his 2023 conviction, telling associates, "Working at Hadrian and volunteering at DIVD made me more paranoid about keeping up appearances," and adding, "I was expecting a knock on the door at any time."4

Wider ShinyHunters activity

According to the BBC, ShinyHunters has been tied to numerous victims both domestically and internationally, and the group is thought to have French origins. The group has previously claimed attacks on Rockstar Games in April, a disruptive hack on Canvas in May, and breaches affecting Ticketmaster, according to single-source reporting.13

Officials in the Netherlands say additional arrests connected to the case remain a possibility.1

Why it matters

The case links a European arrest to a claimed breach of United States federal law enforcement personnel data, raising cross-border questions about accountability for large-scale hacking groups. For European readers, it also highlights how Dutch cybercrime units and firms such as Neo Security are drawn into international investigations involving alleged extortion, data theft and, in this instance, allegations of solicited violence.26

Videos

Dutch police arrest suspected member of group that clai | Nonstop NewsWave #Shorts · Nonstop NewsWave

Related stories

Version history

  1. version 1 ·