Amsterdam ShinyHunters Suspect Also Investigated Over Two Alleged Murder Orders

News Desk
Amsterdam ShinyHunters Suspect Also Investigated Over Two Alleged Murder Orders
Credit: Google Maps / dutchitchannel.nl

Key Points

  • Dutch police arrested a 24-year-old man from Amsterdam on September 15 in an investigation into the ShinyHunters hacking group.
  • Police say the suspect is being investigated for alleged participation in a criminal organisation linked to ShinyHunters.
  • Information found on a laptop seized after the arrest has also led investigators to suspect the man of attempting to solicit two murders abroad. Dutch authorities stress that this allegation is separate from the ShinyHunters investigation.
  • The suspect’s pre-trial detention has been extended by at least 90 days by the Rotterdam court’s chamber.
  • Dutch police have not publicly named the suspect. Reuters reported that his former employer, Amsterdam-based cybersecurity company Neo Security, identified him as Pepijn van der Stap.
  • ShinyHunters has been associated by authorities and reporting with major data breaches involving organisations including Ticketmaster, Pornhub and Dutch telecoms company Odido.
  • The suspect was not arrested as part of the separate investigation into the Odido hack, according to Dutch police.
  • Police and prosecutors have warned that large-scale cyberattacks and the misuse of stolen data could become more frequent, urging organisations and individuals to strengthen digital security and preventative measures.
  • Reuters reported that ShinyHunters has denied any association with Van der Stap, while attempts by Reuters to reach the suspect or identify a lawyer representing him were unsuccessful.

Amsterdam Times News (ATN) September 30, 2026 – Dutch police have arrested a 24-year-old Amsterdam man suspected of involvement with the ShinyHunters hacking group and are separately investigating allegations that he attempted to arrange two murders abroad. The arrest took place on September 15 during an investigation led by the Netherlands’ National Criminal Investigation and Interventions Unit, while the High Tech Crime Team is examining the suspect’s alleged links to ShinyHunters under the authority of the National Public Prosecution Service. Investigators say information found on a laptop following the arrest prompted the separate murder-related suspicion. The suspect remains in custody, with a Rotterdam court extending his pre-trial detention by at least 90 days.

The central development is the expansion of the investigation from alleged cybercrime activity to a separate allegation involving two attempted murder solicitations. Dutch police have emphasised that the two investigations should not be treated as one case. The suspect’s arrest was made on suspicion of participation in a criminal organisation connected with ShinyHunters, rather than specifically over the cyberattack on Dutch telecoms provider Odido.

What has Dutch police said about the ShinyHunters suspect?

According to the Dutch National Police, the 24-year-old man was arrested on Tuesday, September 15, after investigators from the National Criminal Investigation and Interventions Unit identified him during an inquiry into ShinyHunters. The High Tech Crime Team is conducting the cybercrime investigation under the authority of the National Public Prosecution Service.

Police describe ShinyHunters as a criminal hacking and extortion group connected with numerous major national and international data breaches. Their statement specifically referred to incidents involving Odido, Pornhub and Ticketmaster.

The police have not officially identified the arrested man by name. Reuters, however, reported on September 28 that his former employer, Amsterdam-based cybersecurity company Neo Security, identified him as Pepijn van der Stap. Reuters journalists Raphael Satter, Anthony Deutsch and Andrew Goudsward reported that Van der Stap had worked as the company’s offensive security lead.

A subsequent Reuters report by Charlotte Van Campenhout and Anthony Deutsch said Dutch authorities had not publicly identified the suspect and that Reuters had been unable to reach Van der Stap or establish whether he had legal representation.

Because the Dutch police have not themselves publicly named the suspect, references to his identity should therefore be attributed to the reporting and statements of his former employer rather than presented as an official police identification.

Why is the Amsterdam man also suspected of attempting to arrange two murders?

The separate murder allegation emerged after police examined electronic devices seized following the September 15 arrest.

The Dutch National Police said investigators found information on the suspect’s laptop concerning two murders that were allegedly intended to take place abroad. Police said there were indications that the suspect had given instructions connected with the alleged plans. On that basis, he is also suspected of an attempted solicitation of two murders.

AT5/NH Amsterdam, in a report attributed to its newsroom on September 29, also reported that the information concerning the alleged murder orders was found on the man’s laptop. The outlet stressed, in line with the police account, that the murder allegation is separate from the investigation into ShinyHunters.

Dutch media reports have not established publicly whether the alleged murders actually took place. Reuters reported that it was unclear whether the killings allegedly ordered had occurred.

Other details have also not been disclosed publicly. Dutch reporting citing police said authorities have not provided the countries involved, the identities of the alleged targets or a possible motive.

That distinction is important because the murder allegation remains an investigation and has not been established as a criminal conviction.

What is known about the suspect’s detention?

The suspect remains in custody while investigators continue examining the evidence.

The Dutch police said the suspect is being held under restrictions that limit his communications while the investigation is under way. The Rotterdam court’s chamber has subsequently ordered that his pre-trial detention continue for at least another 90 days.

The extension means investigators have additional time to examine the seized digital material and pursue potential links to the wider cybercrime investigation.

The police have also said that further arrests have not been ruled out. Several data storage devices were seized during the investigation and remain subject to examination.

The extension of detention is a procedural development rather than a finding of guilt. The allegations against the suspect remain subject to investigation and any subsequent judicial proceedings.

Was the suspect arrested over the Odido cyberattack?

No. Dutch police have specifically clarified that the September 15 arrest did not take place as part of the separate case concerning the Odido hack.

ShinyHunters has been associated with the major attack on Odido, the Dutch telecommunications provider, but police said the Amsterdam man was arrested in the wider investigation into the alleged criminal organisation rather than specifically over that incident.

The distinction has also been highlighted by Dutch media reporting. ANP, as cited by several Dutch outlets, reported that the suspect was not arrested for involvement in the Odido attack.

Police continue to seek further evidence in the Odido investigation. This means that the arrest should not be interpreted as confirmation that the suspect was responsible for that particular breach.

What is the wider background to ShinyHunters?

ShinyHunters has become associated with large-scale cybercrime involving the theft and attempted exploitation of data.

The Dutch police identified the group as a hacking and extortion organisation connected with significant data breaches affecting organisations in different countries. Its reported targets have included Ticketmaster and Pornhub as well as Odido.

The group has also recently attracted international attention over claims concerning an alleged breach of the US Federal Bureau of Investigation’s jobs website and the theft of sensitive information.

CBS News, in a report by Sarah N. Lynch published on September 29, said US and Dutch authorities had announced the arrest of the suspected ShinyHunters member. CBS also reported that the group had claimed responsibility for the defacement of the FBI’s jobs website and said it had stolen information concerning FBI personnel and applicants.

Reuters separately reported that ShinyHunters had claimed to have obtained terabytes of sensitive personnel information from US FBI servers. According to Reuters, some of the material was reported to include information concerning intelligence assignments and medical records.

Those claims have been part of a wider investigation involving Dutch and US authorities. The arrest therefore comes against a backdrop of international concern about the group’s activities and the possible consequences of large-scale data theft.

What has been reported about Pepijn van der Stap’s previous background?

Reuters reported that Van der Stap had previously been convicted in 2023 over data theft and extortion and later publicly described a move towards legitimate cybersecurity work. His former employer, Neo Security, said he had been employed as an offensive security lead.

According to Reuters reporters Raphael Satter, Anthony Deutsch and Andrew Goudsward, Neo Security chief executive Benjamin Korper said the company had carried out checks before employing Van der Stap and had monitored his work.

Reuters reported that the company commissioned an external investigation after the arrest to determine whether Van der Stap had compromised Neo Security or its customers. At the time of the report, the company said investigators had found no evidence that he had acted against his employer or its clients.

These details are relevant to the chronology but do not establish that the suspect committed the new allegations now under investigation.

What has ShinyHunters said about the arrested man?

ShinyHunters has denied that Van der Stap was associated with the group.

Reuters reported that the group said Van der Stap had “no association” with ShinyHunters and criticised the Dutch police. The statement was reported in the context of the group’s response to the arrest.

That denial contrasts with the Dutch investigation, in which police say the man is suspected of playing a role within ShinyHunters and participating in a criminal organisation.

At this stage, those competing positions remain part of an ongoing investigation. Police allegations and the group’s denial should therefore be distinguished from findings that could ultimately be made by a court.

What did Dutch cybercrime officials say about the wider threat?

Stan Duijf, the Dutch police official responsible for the cybercrime response, said the arrest represented an intervention in the wider fight against cybercrime. In the police statement, Duijf said ShinyHunters was responsible for a large number of Dutch and international victims and welcomed the arrest of a suspect in the investigation.

Dutch police and the Public Prosecution Service have also warned about the expected continuation of major cyberattacks in which stolen information can be exploited on a large scale by criminals.

Authorities have called on companies, institutions and individuals to strengthen their digital security and preventative measures. The warning reflects concerns not only about the initial theft of data but also about what criminals can do with information once it has been obtained.

For businesses, this includes the wider challenge of protecting personal and commercially sensitive information against unauthorised access. For individuals, the risks can include the misuse of stolen personal information following a breach.

What are the next steps in the investigation?

The immediate focus is expected to remain on the evidence seized during the September 15 operation.

Police said several data carriers were confiscated and are being examined. Further arrests remain possible as investigators assess the information and determine whether other individuals may be connected to the alleged criminal activity.

The murder-related allegations will also require separate investigation because Dutch police have expressly stated that they are distinct from the ShinyHunters case.

Authorities have not publicly provided information establishing whether the alleged intended victims were harmed, where the alleged attacks were supposed to take place or what motive may have been involved.

The suspect’s continued detention gives investigators additional time to examine those questions and assess the evidence.

What is the background to this development?

The latest development follows a period of heightened attention around ShinyHunters because of its alleged involvement in major data breaches and extortion activity.

The Netherlands has already been dealing with the consequences of major cyber incidents, including the attack associated with Odido. Police have stressed that the September 15 arrest should not be treated as an arrest in the Odido case itself.

International attention increased further after ShinyHunters claimed to have compromised systems connected with the FBI. CBS News reported that the alleged FBI incident involved the group’s claim that it had obtained data relating to FBI personnel and applicants.

Reuters’ reporting has also placed the arrest in the context of the group’s alleged theft of large quantities of sensitive information from US FBI systems.

Against that background, Dutch investigators are now examining both the suspected cybercrime connection and the separate murder-related allegations. The two matters remain legally distinct.

How could this development affect cybersecurity professionals and organisations?

The development could lead organisations and cybersecurity teams to place continued emphasis on protecting sensitive data, monitoring access to critical systems and maintaining preventative security controls.

The Dutch police and Public Prosecution Service have already warned that major cyberattacks involving the misuse of stolen data could become more frequent and have urged companies, institutions and individuals to strengthen their digital protection.

For cybersecurity professionals, the case also illustrates the importance of examining risks associated with compromised credentials, stolen information and individuals who may have access to sensitive systems. However, the arrest itself does not establish that the suspect compromised his former employer or its customers. Reuters reported that an external investigation commissioned by Neo Security had found no evidence of such activity at the time of its report.

For businesses, the wider implication is that a data breach can extend beyond the initial theft. Information can potentially be copied, traded, published or used in further criminal activity. This is one reason Dutch authorities are calling for stronger preventative measures.