Alleged ShinyHunters leader arrested in the Netherlands
Dutch police arrested alleged ShinyHunters leader Pepijn van der Stap in Amsterdam; the group is blamed for 140+ breaches and $70M extortion.
Dutch National Police arrested a 24-year-old man in Amsterdam, identified by journalist Brian Krebs as Pepijn van der Stap, an alleged leader of ShinyHunters. The FBI says the group breached more than 140 organizations since 2025 and collected at least $70 million in extortion payments, often targeting third-party vendors on cloud platforms; victims include Instructure, Salesforce, Snowflake and McKesson. A Rotterdam court ordered him detained for at least 90 days, and police say evidence from his laptop includes details of two murders he allegedly ordered abroad. The arrest came about a week before ShinyHunters claimed it broke into FBI systems and stole sensitive data on nearly every FBI agent.
- Pepijn van der Stap, 24, arrested in Amsterdam; detained at least 90 days
- FBI alleges 140+ breached organizations and $70 million in extortion payments
- Group frequently targets third-party vendors on cloud platforms
- Arrest preceded ShinyHunters' claimed theft of data on nearly every FBI agent
- Seized laptop reportedly contains details of two murders allegedly ordered abroad
Full article688 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The arrest of a 24-year-old man in Amsterdam, which occurred a week before ShinyHunters hacked the FBI, marks a major turning point for law enforcement’s push to track down the group’s members.
Listen to this article
0:00
Learn more.
Authorities arrested an alleged leader of ShinyHunters, the notorious cybercrime group responsible for a string of high profile extortion attacks since 2025, including last week’s attack on the FBI.
The Dutch National Police said they arrested a 24-year-old man in Amsterdam accused of participating in the cybercrime group. Officials haven’t named the accused man, but independent cybersecurity journalist Brian Krebs identified him as Pepjin van der Stap, a previously convicted cybercriminal who moonlighted as a cybersecurity professional.
The arrest, which occurred about a week before ShinyHunters claims it broke into FBI systems and stole reams of data containing sensitive information on almost every FBI agent, marks a major development for global law enforcement’s push to track down and arrest the group’s members.
“Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments,” Brett Leatherman, assistant director of the FBI’s cyber division, said in a statement on YouTube Tuesday. “They often target third-party vendors in cloud-based platforms, stealing sensitive data and extort victims with threats to publish it.”
The Dutch National Police said they retrieved a large amount of evidence on van der Stap’s laptop, including details about two murders he allegedly ordered abroad. As the investigation continues, a court in Rotterdam ordered him to remain detained awaiting trial for at least 90 days.
ShinyHunters is among the most prolific cybercrime groups currently in operation. It previously targeted major cloud platforms, healthcare organizations, universities, technology companies, retailers and education service providers. Previous victims of ShinyHunters this year include Instructure, Salesforce, Snowflake and McKesson.
“FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest,” FBI Director Kash Patel wrote in a post on X Tuesday.
Leatherman, who described van der Stap as an alleged leader of the group, pulled further on that thread, speaking directly to other members of ShinyHunters in his recorded statement.
“You’ve heard about the arrest of your colleague. We’re confident you’ve seen or heard things in recent days that the public has not. Other groups believed anonymity or their friends would protect them, and they were wrong,” he said.
“Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you,” Leatherman added. “You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
Latest Podcasts
Government
As AI world debates security, NVIDIA releases open source tools for agents
Supreme Court permits states to use SAVE database for citizenship checks
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
New bill would create federal investigative body for AI-driven hacks
Technology
Threats
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud