Dutch Police Arrest Suspected ShinyHunters Leader Amid Murder Plot Investigation

News Desk
Dutch Police Arrest Suspected ShinyHunters Leader Amid Murder Plot Investigation
Credit: Google Maps / Corbis via Getty

Key Points

  • Dutch police arrested a 24-year-old Amsterdam man on September 15 over suspected involvement with the ShinyHunters hacking and extortion group.
  • Dutch authorities publicly confirmed the arrest on September 29 and said a Rotterdam court had ordered the suspect to remain in custody for at least another 90 days.
  • Police said information found on the suspect’s laptop included material concerning two alleged murders that were reportedly intended to take place abroad.
  • The alleged murder-related investigation is separate from the inquiry into ShinyHunters, according to Dutch police and Reuters.
  • Amsterdam cybersecurity company Neo Security identified the suspect as Pepijn van der Stap, its former offensive security lead, although Dutch police have not publicly named him.
  • Reuters journalists Raphael Satter, Anthony Deutsch and Andrew Goudsward reported that Van der Stap had previously been convicted of data theft and extortion before publicly presenting himself as a reformed cybersecurity professional.
  • The FBI said the suspect and alleged accomplices had been linked to more than 140 organisations and at least $70 million (€61.7 million) in extortion payments, with attacks frequently involving third-party cloud vendors.
  • The arrest came days before ShinyHunters claimed it had breached the FBI’s recruitment website and stolen between two and three terabytes of data involving employees and applicants.
  • The FBI has been investigating the claimed breach, while ShinyHunters has denied that Van der Stap is connected to the group.
  • Dutch police said the suspect was not arrested as part of the separate investigation into the February cyberattack against telecoms company Odido, which affected approximately 6.39 million people.
  • Police have seized several data-storage devices and said further arrests have not been ruled out.

Amsterdam Times News (ATN) September 30, 2026 – Dutch authorities have arrested a 24-year-old man suspected of having a role in the ShinyHunters cybercrime group, while investigators are separately examining allegations that information on his laptop was connected to plans to have two people murdered abroad. The arrest was made on September 15 but became public on September 29 after the suspect appeared before a Rotterdam court. Dutch police said the investigation remains active, several electronic devices have been seized and additional arrests cannot be excluded. The case has gained further attention because the suspect was identified by his former employer as Pepijn van der Stap, a cybersecurity professional who had previously been convicted of cybercrime before moving into legitimate security work.

What did Dutch police say about the ShinyHunters arrest?

According to the Dutch National Police, the suspect was arrested on September 15 following an investigation by the National Criminal Investigation and Interventions Unit, with the High Tech Crime Unit examining the alleged ShinyHunters connection under the authority of the National Public Prosecutor’s Office. Police said he is suspected of participating in a criminal organisation.

Dutch authorities did not publicly identify the man. However, Reuters journalists Raphael Satter, Anthony Deutsch and Andrew Goudsward reported on September 28 that Benjamin Korper, chief executive of Amsterdam-based cybersecurity company Neo Security, identified the arrested individual as Pepijn van der Stap, the company’s former offensive security lead. Reuters said forensic investigators visited Neo Security’s offices on the night of the arrest.

The identification has not been presented as a formal naming by Dutch police. Reuters also reported that attempts to contact Van der Stap or identify a lawyer or representative for him were unsuccessful.

The distinction is important because the criminal allegations remain under investigation. The arrest itself does not establish that the suspect committed the cyberattacks attributed to ShinyHunters, and the group has rejected the allegation that he was a member.

What evidence did police say they found on the suspect’s laptop?

Dutch police said investigators found a substantial amount of information on the suspect’s laptop following his arrest. Among the material was information relating to two murders that were allegedly intended to be carried out abroad.

Reuters reported on September 29 that Dutch media, including the Dutch news agency ANP, had reported the alleged murder-related material. Reuters said police had not immediately confirmed all details reported by Dutch media and that it was unclear whether the alleged murders had actually taken place.

The Dutch police account states that there were indications the suspect had given instructions connected with the alleged killings. Police therefore suspect him of attempting to incite two murders. The force stressed that this allegation is separate from the investigation into ShinyHunters.

This separation is significant because two investigations are proceeding alongside each other. One concerns alleged participation in an international cybercrime organisation, while the other concerns the alleged attempted commissioning of two killings.

Why was Pepijn van der Stap’s identity linked to the case?

Neo Security identified the suspect as Van der Stap after Dutch police announced the arrest without releasing his name.

Reuters reported that Van der Stap had previously received convictions in 2023 for data theft and extortion. After serving his sentence, he publicly rejected his previous criminal activity and moved into cybersecurity work.

Reuters said Van der Stap had described his experience as a difficult personal journey and had presented the knowledge gained from his earlier activities as something that could be used to protect systems rather than attack them.

Benjamin Korper told Reuters that Neo Security had carried out checks before employing Van der Stap and had monitored him during his employment. Korper said he was shocked by the arrest.

Reuters also reported that Neo Security commissioned an external investigation to establish whether Van der Stap had compromised the company or its customers. At the time of the Reuters report, that investigation had found no evidence that he had attacked his employer or its clients.

How serious are the cybercrime allegations against ShinyHunters?

The wider investigation concerns a hacking and extortion operation that Dutch police have linked to numerous major data breaches.

Dutch police described ShinyHunters as a criminal hacking and extortion group involved in major data leaks, including incidents involving Odido, Pornhub and Ticketmaster.

The FBI has provided assistance to the Dutch-led investigation. FBI Cyber Division Assistant Director Brett Leatherman said the case demonstrated a model of international cooperation in which the country with the strongest legal authority and access takes the lead.

According to the material supplied for this report, Leatherman said the suspect and alleged associates had breached more than 140 organisations since last year and had obtained at least $70 million (€61.7 million) through extortion payments.

The reported method of attack often involved third-party providers and cloud-based systems. That feature has increased concern among organisations that do not necessarily operate the compromised infrastructure themselves but rely on external technology suppliers to process or store sensitive information.

The scale described by investigators also places the case within a broader international effort to disrupt cybercrime groups that combine data theft with extortion.

What happened with the alleged FBI breach?

The Dutch arrest occurred only days before ShinyHunters publicly claimed responsibility for an intrusion involving FBIJobs.gov, the Federal Bureau of Investigation’s recruitment website.

On September 23, CBS News correspondent Nicole Sganga reported that ShinyHunters claimed it had stolen between two and three terabytes of data relating to FBI and Justice Department personnel and applicants. The group said it had used a vulnerability involving Oracle PeopleSoft, a human resources management system.

The Washington Post separately reported that the FBI was investigating the claim and had not yet established whether FBI systems or a third-party system supporting the recruitment website had been compromised. The newspaper also reported that the claimed material potentially included sensitive information about FBI personnel and applicants.

That distinction remains important. A claim made by a criminal group is not, by itself, proof that all of the claimed data was obtained. The FBI’s investigation is therefore central to establishing the scale and nature of the incident.

Reuters previously reported that at least some of the data claimed by ShinyHunters appeared to include sensitive information connected to FBI employees. An internal FBI memo reportedly instructed staff to operate on the assumption that data concerning bureau employees had been stolen while investigators continued assessing the incident.

Why did ShinyHunters say it targeted the FBI?

ShinyHunters said the alleged FBI intrusion was connected to an earlier government advisory concerning the group.

According to Reuters, ShinyHunters initially demanded that the FBI withdraw an advisory about the group. Reuters reported that the hackers later softened their position and said they were no longer setting a deadline for the FBI to rescind the advisory.

The group has also denied that Van der Stap has any association with it and has criticised Dutch police over the investigation. Those statements remain allegations made by the group rather than independently established findings.

The FBI has continued working with Dutch authorities and other international partners as investigators examine information arising from the arrest.

Is the ShinyHunters case connected to the Odido data breach?

Dutch police have made clear that the September arrest should not be treated as an arrest in the separate Odido investigation.

Police said the 24-year-old was arrested as part of the ShinyHunters investigation and was not arrested in connection with the investigation into the Odido cyberattack. The Odido investigation remains open.

The Odido incident itself involved more than six million customers. According to Odido, approximately 6.39 million people were affected by the February cyberattack. The company said the attack occurred on February 5 and 6 and involved a sophisticated form of voice phishing in which attackers impersonated members of its IT staff.

Dutch police have previously said a Dutch-speaking caller contacted Odido’s customer service operation while pretending to be an IT employee. The caller persuaded an employee to use a fraudulent login page and provide credentials and a verification code, enabling attackers to gain access to internal systems.

Police later released an audio recording of the suspected caller in an effort to identify him. The authorities said data belonging to more than six million Odido customers had entered criminal hands.

Odido has said it did not pay the ransom and that stolen information was subsequently placed on the dark web.

What other major breaches have been associated with ShinyHunters?

ShinyHunters has been linked in public reporting to a series of major attacks involving large amounts of customer or employee information.

The group has been associated with breaches affecting Ticketmaster and AT&T, as well as an intrusion involving Pornhub. It has also been linked to a wider series of extortion attempts involving organisations using Salesforce systems.

These cases illustrate a recurring feature of modern cybercrime: attackers can seek access not only through an organisation’s own systems but also through suppliers, customer-service operations, software platforms and other third parties.

The Odido investigation provides a clear example of how social engineering can be used alongside technical access. Rather than relying solely on a software vulnerability, investigators say the attackers used a convincing telephone impersonation to persuade an employee to provide access information.

How does the arrest fit into the wider European cybercrime picture?

The ShinyHunters investigation comes as European governments and businesses continue to deal with large-scale data theft.

Recent incidents have included the reported exposure of data involving millions of Polish citizens and the theft of records belonging to hundreds of thousands of French taxpayers. Such cases have increased attention on how government bodies, telecoms companies and private businesses secure large collections of personal information.

The European pattern also demonstrates that cybercrime investigations frequently cross national borders. Data can be stolen in one country, stored elsewhere, transferred through international infrastructure and then used for extortion or other criminal purposes across several jurisdictions.

The Dutch investigation is therefore being conducted with international cooperation, including assistance from US authorities.

What have Dutch authorities said about further arrests?

Dutch police have not ruled out additional arrests.

The force said several data-storage devices were seized during the September 15 operation and that investigators were continuing to examine the material.

Stan Duijf, a Dutch police official responsible for tackling cybercrime, said the arrest represented part of the broader effort against cybercrime and described ShinyHunters as responsible for a large number of national and international victims.

The Rotterdam court has ordered the suspect to remain in pre-trial detention for at least another 90 days while the investigation continues. This does not constitute a finding of guilt, and the allegations against him remain subject to the Dutch criminal justice process.

What is the background to the ShinyHunters investigation?

ShinyHunters emerged as a prominent name in data theft and extortion, becoming associated with attacks in which stolen information was used to pressure organisations into making payments or meeting other demands.

The group’s activities have involved large databases containing personal information. The commercial value of such information can extend beyond the original extortion attempt because stolen records can subsequently be exploited for fraud, identity theft, phishing and further cyberattacks.

The Odido case illustrates this risk. Dutch police said the attackers obtained information on more than six million customers, while Odido says the total number of affected people was approximately 6.39 million.

The investigation into the alleged ShinyHunters structure is also notable because the Dutch suspect had previously moved from cybercrime into legitimate cybersecurity employment. Reuters’ reporting indicates that Neo Security had investigated whether its former employee had compromised its systems or those of its customers and had found no evidence of such activity at the time of publication.

What may happen next in the ShinyHunters investigation?

The immediate next stage is expected to centre on analysis of the electronic devices seized during the September 15 arrest, alongside the continuing examination of the suspect’s alleged role in ShinyHunters.

Dutch police have explicitly said further arrests have not been ruled out. The FBI has also said it is continuing to work with international partners and pursue leads arising from the Dutch operation.

For businesses and cybersecurity professionals, the development may therefore lead to greater attention on third-party access, employee authentication, social-engineering risks and the protection of sensitive databases. Those issues are already evident in the Odido investigation, where attackers reportedly obtained access after impersonating an IT employee and obtaining authentication information from a member of staff.

The investigation could also provide authorities with additional intelligence about the infrastructure, personnel and methods associated with international cyber-extortion operations. However, the extent of any future arrests, prosecutions or additional links between specific incidents will depend on evidence gathered by investigators.

At present, the Dutch suspect remains in custody, the ShinyHunters allegations remain under investigation, and the separate allegations concerning two proposed murders have not been established in court. The FBI’s investigation into the claimed theft of personnel and applicant data is also continuing, meaning the full consequences of the September arrest are not yet known.