Alleged ShinyHunters leader arrested in the Netherlands
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Hacker groups and malware
- ShinyHunters
- Industries
- Government
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
Authorities arrested an alleged leader of ShinyHunters, the notorious cybercrime group responsible for a string of high profile extortion attacks since 2025, including last week’s attack on the FBI.
The Dutch National Police said they arrested a 24-year-old man in Amsterdam accused of participating in the cybercrime group. Officials haven’t named the accused man, but independent cybersecurity journalist Brian Krebs identified him as Pepjin van der Stap, a previously convicted cybercriminal who moonlighted as a cybersecurity professional.
The arrest, which occurred about a week before ShinyHunters claims it broke into FBI systems and stole reams of data containing sensitive information on almost every FBI agent, marks a major development for global law enforcement’s push to track down and arrest the group’s members.
“Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments,” Brett Leatherman, assistant director of the FBI’s cyber division, said in a statement on YouTube Tuesday. “They often target third-party vendors in cloud-based platforms, stealing sensitive data and extort victims with threats to publish it.”
The Dutch National Police said they retrieved a large amount of evidence on van der Stap’s laptop, including details about two murders he allegedly ordered abroad. As the investigation continues, a court in Rotterdam ordered him to remain detained awaiting trial for at least 90 days.
ShinyHunters is among the most prolific cybercrime groups currently in operation. It previously targeted major cloud platforms, healthcare organizations, universities, technology companies, retailers and education service providers. Previous victims of ShinyHunters this year include Instructure, Salesforce, Snowflake and McKesson.
“FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest,” FBI Director Kash Patel wrote in a post on X Tuesday.
Leatherman, who described van der Stap as an alleged leader of the group, pulled further on that thread, speaking directly to other members of ShinyHunters in his recorded statement.
“You’ve heard about the arrest of your colleague. We’re confident you’ve seen or heard things in recent days that the public has not. Other groups believed anonymity or their friends would protect them, and they were wrong,” he said.
“Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you,” Leatherman added. “You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
Latest Podcasts
Government
Supreme Court permits states to use SAVE database for citizenship checks
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
New bill would create federal investigative body for AI-driven hacks
Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges
Technology
CISA outlines improvement plan for CVE program
OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems
Citing China, President Trump doubles down on hands-off approach to AI regulation
Researchers use AI to find widespread software decoder flaw
Threats
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
Policy
Originally published by CyberScoop. © CyberScoop. Written by Matt Kapko.
Fastnexa security experts
Worried ShinyHunters could come after your company?
We test your defences the way groups like ShinyHunters actually break in, then help you close the gaps before they find them.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-29 15:32 UTC
Related stories
- Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Dark Reading · 2026-09-29 · exploited
- Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
CyberScoop · 2026-09-29
- Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
Dark Reading · 2026-09-29
- US Air Force members given over 6 years in prison for cyber theft of more than $2 million
The Record · 2026-09-29
- FBI tells ShinyHunters members to turn themselves in after recent arrest
BleepingComputer · 2026-09-29