Dutch police arrest ShinyHunters hacker accused of planning two murders
Dutch police arrested an alleged ShinyHunters leader, also suspected of planning two murders, after gang claimed breaches of 140+ firms including the FBI.
Dutch police, working with the FBI, arrested a 24-year-old Amsterdam man on September 15 for participating in the ShinyHunters criminal organization; media identified him as Pepijn van der Stap, CTO of Neo Security. He was remanded into custody for at least 90 days, and evidence seized from his laptop triggered a separate investigation into plans for two murders abroad. ShinyHunters is accused of breaching over 140 organizations including Pornhub, Ticketmaker and AT&T, and recently claimed a breach of the FBI's careers portal exposing personal data of agents and applicants, including psychiatric reports and sample records. The FBI has not confirmed the breach, and the gang says it will not publish the stolen data.
- Dutch police arrested alleged ShinyHunters leader Pepijn van der Stap, 24, on September 15
- He is remanded for 90 days; laptop evidence allegedly shows two planned murders abroad
- ShinyHunters accused of breaching 140+ organizations including Pornhub, Ticketmaster, AT&T
- Gang claimed FBI careers portal breach exposing agents' personal and medical data
- FBI has not confirmed the breach; gang says data will not be published
Full article730 words · extracted from techcrunch.com · click to collapse
The FBI and Dutch law enforcement say they have arrested a member of the ShinyHunters hacking group, which the agencies say are responsible for hacks on over 140 organizations around the world. The hackers also claimed responsibility for a breach of the FBI’s own systems earlier this month.
Brett Leathermann, the FBI’s cyber division lead, said in a video message on Tuesday that Dutch authorities had arrested one of the “alleged leaders of ShinyHunters.” Leathermann added that the Dutch High Tech Crime Unit “moved quickly to protect victims and preserve critical evidence,” and vowed that the bureau would go after the rest of the hackers following the arrest.
In a separate statement, Dutch police confirmed that an unnamed 24-year-old man from Amsterdam was arrested under Dutch law on September 15. The man was scheduled to appear in court on Tuesday, and has been remanded into custody for at least 90 days.
The police say the man was arrested for “participating in a criminal organization,” referring to ShinyHunters.
Following his arrest and seizure of his devices, the police said “a lot of information was found on his laptop, including about two murders that should be committed abroad.” As such, he is also being investigated for attempting to orchestrate the murders. The Dutch authorities said this is “separate from the investigation into ShinyHunters.”
ShinyHunters is a cyber criminal gang that are accused of hacking into companies to steal reams of data and then threatening to publish the data if its victims do not pay a ransom. The Dutch authorities said the gang are accused of data breaches at Pornhub, Ticketmaster, and U.S. telco giant AT&T. The hacking group also took responsibility for a breach of Dutch phone provider Odido. However, the authorities said that the man they took into custody has not been arrested in relation to the Odido hack.
Independent security journalist Brian Krebs, who was first to report the arrest, and other media outlets have named the arrested man as Pepijn van der Stap, who was profiled by Bloomberg in 2024 as a cybersecurity researcher who also moonlighted as a criminal hacker who extorted companies.
According to recent reporting by Bloomberg and Reuters, Van der Stap was arrested earlier this month by police at the offices of Neo Security, where Van der Stap is employed as chief technology officer. The raid reportedly involved flash-bang grenades.
A representative for Neo Security did not immediately respond to TechCrunch’s request for comment. When asked by TechCrunch, a representative of the ShinyHunters group told TechCrunch that Van der Stap “has no association with us.”
News of the arrest comes days after the FBI reportedly told its own agents and employees that their personal information, including their names, addresses, job titles and Social Security numbers, were exposed in a “cyber security incident.” The FBI has not yet publicly confirmed a breach, but the ShinyHunters gang said it took personal and sensitive data belonging to “mostly all” of the FBI’s agents and applicants by breaching its careers website and job application portal.
Among the sample of 5,000 or so agents who had data stolen from the portal, reporters have also found data relating to agents’ blood and urine samples, as well as psychiatric reports, which sparked fears of a major counterintelligence challenge to prevent an adversarial government from obtaining the data.
When contacted by TechCrunch, Leathermann did not comment. An FBI spokesperson declined to comment on our questions relating to the arrest.
For their part, the ShinyHunters hackers reiterated that the breach of the FBI’s servers was not a financially motivated attack, but was intended to challenge public claims made by the FBI, which the hackers say contain false allegations about the group. The hackers told TechCrunch that they will not publish the stolen FBI data, and added that the breach was “to make a point and to dispute the allegations made against us and we have done so.”
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.