Authorities have arrested a 24-year-old man from Amsterdam in connection with an investigation into the cybercrime group ShinyHunters, as they intensify efforts to identify members of the hacking operation after it allegedly stole sensitive FBI data.
What happened
Dutch police arrested the man on September 15 as part of an investigation by the country's High Tech Crime Unit into ShinyHunters, a cybercrime and extortion group linked to numerous large-scale data breaches. Police announced the arrest on September 28 but did not initially identify the suspect.
Dutch police did not publicly identify the suspect, but Benjamin Korper, CEO of Amsterdam-based cybersecurity company Neo Security, identified him as Pepijn van der Stap, the company's offensive security lead. Korper told Reuters that Dutch forensic investigators visited the company's office on the night of the arrest, during a police raid involving flash-bang grenades.
The arrest comes as ShinyHunters faces growing international scrutiny over a series of large-scale data breaches and extortion campaigns. The group recently claimed it had stolen terabytes of sensitive personnel information from US FBI servers, including information relating to employees' intelligence assignments and medical records.
Dutch police said they are investigating the suspect for allegedly participating in a criminal organization linked to ShinyHunters. Authorities seized several electronic devices and are examining them as part of the investigation, saying further arrests have not been ruled out.
ShinyHunters has denied that Van der Stap is associated with the group, while Neo Security said an external investigation had found no evidence, so far, that he had compromised the company or its clients.
Going deeper
Van der Stap had previously been convicted in 2023 of data theft and extortion. Afterward, he presented himself as someone who had left cybercrime behind and moved into legitimate security work. His personal website described his experience as having taught him that “knowledge is for building and protecting, not breaking.”
Korper told Reuters that Neo Security had carefully vetted Van der Stap before employing him and had monitored his activities. The company also commissioned an external investigation after his arrest to determine whether he had compromised Neo Security or its clients. At the time of Reuters' report, investigators had found no evidence that he had hacked his employer or its customers.
The backstory
Google's Mandiant unit said in September that ShinyHunters had resumed large-scale exploitation of a vulnerability in Oracle PeopleSoft, adapting its tactics to get around defensive measures deployed after earlier attacks. The campaign affected organizations across sectors, including higher education, healthcare, technology, agriculture, transportation, and government. Investing.com
ShinyHunters has also claimed responsibility for the FBI incident. The group said it obtained information on almost all FBI agents and people who had applied for jobs with the bureau. A sample it released allegedly contained names, addresses, Social Security numbers, assignments, and family information. Reuters was able to partially verify some of the information but could not establish that the data had been stolen directly from FBI internal systems as ShinyHunters claimed.
Go deeper:
- ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says
- ShinyHunters hackers say they breached FBI, stole data on bureau employees
What was said
Dutch cybercrime official Stan Duijf said in a statement that “The arrest of cybercrime suspects is an important intervention in our broad fight.” He added that ShinyHunters was responsible for a large number of national and international victims and described the arrest of a suspect in the investigation as a positive development.
Van der Stap's employer, meanwhile, expressed shock over the arrest. Korper told Reuters he truly believes that “people deserve a second chance,” but in this case he was not thanked for it.
He added that “absolutely everybody” he had spoken to was “flabbergasted” by the development.
ShinyHunters rejected the allegation that Van der Stap was associated with the group, calling the Dutch police incompetent. In response to the FBI dispute, the group also softened its previous threat against the bureau, saying, “Nothing will happen.”
Why it matters
Cybercrime can have serious consequences for the people behind attacks, extending far beyond the immediate investigation. Arrests can lead to criminal charges, prison sentences, financial penalties, and the seizure of devices and other assets used in alleged offenses.
The ShinyHunters investigation illustrates how cybercriminals can also face consequences years after an alleged attack. Law enforcement agencies can trace digital activity, identify suspects, and collaborate across borders to build cases against individuals involved in cybercrime.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQS
Why do cybercriminals steal data?
Stolen data can be used for several purposes, including extortion, fraud, identity theft, and resale on criminal marketplaces. Sensitive information can also provide attackers with additional opportunities to target an organization or its employees.
Why are international investigations important in cybercrime cases?
Cyberattacks frequently cross national borders. An attacker may be located in one country, use infrastructure in another, and target an organization somewhere else. International cooperation allows law enforcement agencies to share evidence and coordinate investigations and arrests.
