Technology

Dutch Police Arrest Man Accused of Leading ShinyHunters Hacking Group

Martin HollowayPublished 5d ago3 min readBased on 7 sources
Reading level
Dutch Police Arrest Man Accused of Leading ShinyHunters Hacking Group
Photo by Federal Bureau of Investigation (FBI) / Public domain

Dutch police have arrested a 24-year-old man from Amsterdam accused of leading the ShinyHunters hacking group.

The arrest took place on September 15 under Dutch law and was announced publicly on September 29. The suspect appeared in court on September 29 and was remanded into custody, meaning ordered to remain in jail before trial, for at least 90 days.

FBI cyber division lead Brett Leathermann confirmed the arrest in a video message on September 29. The FBI and Dutch law enforcement attribute hacks on more than 140 organizations worldwide to ShinyHunters TechCrunch, which operates much like a burglary crew working through many targets. Dutch authorities named data breaches at Pornhub, Ticketmaster, and AT&T in connection with the group.

Earlier in September, ShinyHunters claimed responsibility for a breach of the FBI's own systems. The group claimed to have stolen sensitive information on all FBI bureau staff, around 38,000 people BBC.

Dutch police said the legal basis for detention was participation in a criminal organization, referring to ShinyHunters. Forensic investigators traveled to an Amsterdam office to make the September 15 arrest The Register. Police seized several data carriers, physical devices used to store data, during the operation and are now examining them. Police released part of a call on September 8 and subsequently received 20 tips.

Information found on the suspect's laptop included details about two murders to be committed abroad. Dutch authorities are investigating the suspect for attempting to orchestrate those murders as a separate matter from the ShinyHunters investigation. Police said the suspect was not arrested in relation to the Odido hack.

Identification remains contested. Security journalist Brian Krebs named the arrested man as Pepijn van der Stap. Dutch media identified him as Pepijn van der S. Van der Stap is employed as chief technology officer, the senior executive responsible for technology, of Neo Security. A representative of the ShinyHunters group told TechCrunch that Van der Stap has no association with the group.

The broader context here is attribution under pressure. Law enforcement has paired a computer intrusion case affecting many victims with a violent crime allegation drawn from laptop evidence, while the named group publicly denies the link to the detained individual. An arrest does not immediately reduce exposure from data already stolen, and denials from groups that operate under aliases carry little evidentiary weight either way.

In my view, technology teams should read that sequence carefully. If judicial process confirms that a suspect held a senior security title, it raises questions about vetting, privileged access, and separation of duties inside security vendors and enterprise teams. That concern is structural, not specific to this case. Organizations that grant broad access to small groups of trusted operators accept concentrated risk, and arrests test response plans that often assume the adversary is external. Tighter checks on access can leave teams better prepared.