The FBI and Dutch law enforcement say they have arrested a member of the ShinyHunters hacking group, which the agencies say are responsible for hacks on over 140 organizations around the world. The hackers also claimed responsibility for a breach of the FBI’s own systems earlier this month.
Brett Leathermann, the FBI’s cyber division lead, said in a video message on Tuesday that Dutch authorities had arrested one of the “alleged leaders of ShinyHunters.” Leathermann added that the Dutch High Tech Crime Unit “moved quickly to protect victims and preserve critical evidence,” and vowed that the bureau would go after the rest of the hackers following the arrest.
In a separate statement, Dutch police confirmed that an unnamed 24-year-old man from Amsterdam was arrested under Dutch law on September 15. The man was scheduled to appear in court on Tuesday, and has been remanded into custody for at least 90 days.
The police say the man was arrested for “participating in a criminal organization,” referring to ShinyHunters.
Following his arrest and seizure of his devices, the police said “a lot of information was found on his laptop, including about two murders that should be committed abroad.” As such, he is also being investigated for attempting to orchestrate the murders. The Dutch authorities said this is “separate from the investigation into ShinyHunters.”
ShinyHunters is a cyber criminal gang that are accused of hacking into companies to steal reams of data and then threatening to publish the data if its victims do not pay a ransom. The Dutch authorities said the gang are accused of data breaches at Pornhub, Ticketmaster, and U.S. telco giant AT&T. The hacking group also took responsibility for a breach of Dutch phone provider Odido. However, the authorities said that the man they took into custody has not been arrested in relation to the Odido hack.
Independent security journalist Brian Krebs, who was first to report the arrest, and other media outlets have named the arrested man as Pepijn van der Stap, who was profiled by Bloomberg in 2024 as a cybersecurity researcher who also moonlighted as a criminal hacker who extorted companies.
According to recent reporting by Bloomberg and Reuters, Van der Stap was arrested earlier this month by police at the offices of Neo Security, where Van der Stap is employed as chief technology officer. The raid reportedly involved flash-bang grenades.
A representative for Neo Security did not immediately respond to TechCrunch’s request for comment. When asked by TechCrunch, a representative of the ShinyHunters group told TechCrunch that Van der Stap “has no association with us.”
News of the arrest comes days after the FBI reportedly told its own agents and employees that their personal information, including their names, addresses, job titles and Social Security numbers, were exposed in a “cyber security incident.” The FBI has not yet publicly confirmed a breach, but the ShinyHunters gang said it took personal and sensitive data belonging to “mostly all” of the FBI’s agents and applicants by breaching its careers website and job application portal.