
The most interesting detail in this story isn’t the arrest. It’s that the FBI is trying to take a victory lap while simultaneously refusing to confirm that the same hacking group just walked off with sensitive data belonging to its own agents. According to TechCrunch, Dutch police arrested a 24-year-old man from Amsterdam on September 15, naming him as an alleged leader of ShinyHunters, a criminal gang accused of breaching over 140 organizations worldwide.
Independent security journalist Brian Krebs first identified the arrested man as Pepijn van der Stap, who had been profiled by Bloomberg in 2024 as a cybersecurity researcher with a side career extorting companies. Dutch police carried out the arrest at the offices of Neo Security, where van der Stap works as chief technology officer. The raid reportedly involved flash-bang grenades. He has been remanded into custody for at least 90 days and is set to face charges related to participating in a criminal organization.
But the case took a strange turn when investigators examined his seized devices. Police say they found material on his laptop suggesting he was planning two murders abroad. That investigation is being handled separately from the ShinyHunters probe, but it adds a layer to what is already a deeply unusual case.
ShinyHunters operates a fairly standard ransomware-adjacent playbook: break into a company, steal the data, then threaten to publish it unless a ransom is paid. Their alleged victims include Ticketmaster, AT&T, Pornhub, and Dutch telecom provider Odido. The gang’s reach is wide, and their targets have been high-profile enough to affect tens of millions of ordinary people whose personal data ended up on criminal forums.
The FBI breach is the part of this story that deserves more scrutiny. ShinyHunters claims it accessed the bureau’s careers website and job application portal, pulling records that include names, home addresses, job titles, Social Security numbers, and in some cases blood and urine samples and psychiatric reports belonging to agents and applicants. A sample of around 5,000 records has already been reviewed by reporters. The counterintelligence implications are serious. Data like this, if it reached a hostile foreign government, could be used to identify, pressure, or expose undercover personnel.
The FBI has not publicly confirmed the breach. Brett Leatherman, the bureau’s cyber division lead, praised the Dutch arrest but declined to answer questions about the ShinyHunters claim. That silence is telling. Agencies that successfully rebuff attacks tend to say so. The group told TechCrunch the breach was not financially motivated and was instead intended to challenge what they call false public allegations made by the FBI. They say they won’t publish the data. That may be true. But the data still exists, and the FBI’s refusal to acknowledge the incident does nothing to protect the people whose information was exposed.
ShinyHunters also told TechCrunch that van der Stap has no connection to the group. Neo Security did not respond to a request for comment. One arrest, however dramatic the raid, rarely ends a distributed criminal operation. The FBI says it’s going after the rest of the group. What it owes its own employees first is a straight answer about what was taken.