WorldNews

Dutch police confirm ShinyHunters suspect’s arrest as FBI examines group’s breach claim

A 24-year-old Amsterdam man was arrested before the group claimed to have breached an FBI jobs site. Dutch authorities have not publicly linked him to that incident.

Exterior of the J. Edgar Hoover FBI Building in Washington, D.C.
File photograph of the J. Edgar Hoover FBI Building in Washington, D.C., taken in May 2024. Tony Webster / Wikimedia Commons (resized and converted to WebP). CC BY 2.0.
LinkedInPostEmail
Save for later

Dutch police said Tuesday that they had arrested a 24-year-old Amsterdam man suspected of involvement with ShinyHunters, the cybercrime group that later claimed to have breached an FBI jobs site. The arrest took place on 15 September, before the group’s claim about the FBI. That timing matters: the Dutch announcement does not establish that the suspect took part in the later incident, whose scope remains under investigation.

A Rotterdam court ordered the man held for a further 90 days on 29 September, according to the Associated Press. Dutch detectives seized data-storage devices and were examining their contents. Police have not ruled out further arrests. The public account therefore marks a significant step in the inquiry into ShinyHunters, while leaving open what investigators may ultimately establish about this suspect’s role.

What authorities have said

Dutch cybercrime chief Stan Duijf described ShinyHunters as responsible for many victims in the Netherlands and abroad, AP reported. He called the arrest a useful intervention against cybercrime. The Dutch police statement, as described by AP, did not mention the claimed FBI breach or coordination with US authorities. It identified the man by his age and Amsterdam residence, rather than publicly naming him.

FBI Director Kash Patel offered a broader characterization, calling the suspect one of ShinyHunters’ alleged leaders and saying Dutch and FBI investigators were pursuing leads together, according to AP. That is Patel’s description of the suspect and the cooperation. It does not, by itself, connect the man to the claimed intrusion at the FBI jobs site, which happened after his arrest.

Dutch police also suspect the man of attempted solicitation of two murders. AP reported that police said the suspicion arose from information found on his laptop and was unrelated to the ShinyHunters investigation. These are allegations under investigation; the reported court order concerns continued detention and does not establish guilt on either suspicion.

A reported identity, with a limit

KrebsOnSecurity identified the arrested man as Pepijn van der Stap, citing three sources familiar with the case. Dutch police had not publicly named the suspect in the material reviewed. The identification should therefore be understood as KrebsOnSecurity’s reporting, rather than as a name released by the authorities.

KrebsOnSecurity reported that Van der Stap had previously used the online name Umbreon and had been convicted in an earlier data-theft and extortion case. According to that account, he was sentenced in 2023 to four years in prison, with one year suspended, and was released in December 2025. Those earlier offenses are background to the person KrebsOnSecurity identified; they are not findings about the current suspicion.

KrebsOnSecurity said it interviewed Van der Stap on 9 September, before the reported arrest. In that interview, he presented himself as a reformed hacker who wanted to make a positive contribution. The publication said he had stopped responding to messages by the time its account appeared. His earlier comments do not address the allegations announced by police on Tuesday.

The separate FBI investigation

The FBI said on 23 September that it was investigating unauthorized activity affecting FBIJobs.gov, CBS News reported. The bureau had not determined whether the breach point lay with a third party or within the FBI enterprise. The Record reported that ShinyHunters defaced the jobs site and that the application portal displayed an unavailable notice during the initial investigation. A disrupted site is visible evidence of an incident, but it does not establish the full scope or origin of any data access.

ShinyHunters claimed to have obtained sensitive information about nearly all FBI agents and job applicants. AP said that sweeping claim could not immediately be verified. CBS reported that sample records supplied by the group appeared to correspond to real personnel, while neither CBS nor the outlets it cited had established that the records came from FBI systems. The Record reported that the group supplied samples of 5,000 records to news outlets that confirmed their legitimacy. Those accounts support treating the samples seriously, without accepting the group’s larger claim as proven.

CBS reported that ShinyHunters objected to how the FBI characterized the group in two warnings issued in May and gave the bureau one week to correct or remove parts of a warning. That account of the group’s motives comes from ShinyHunters itself. The FBI’s inquiry into its jobs site and the Dutch inquiry into a suspected group member remain distinct in the public record, even as Patel has described investigators working together after the arrest.

Other lines of inquiry

A separate Dutch police appeal this month concerned a breach at telecoms provider Odido. Police said a Dutch-speaking caller posed as an IT colleague to gain internal access, after which attackers obtained data on more than six million customers. Odido refused a ransom demand, and the data was posted on the dark web. Police released the caller’s voice to seek tips and said a voice expert judged it to be a real voice rather than one generated by AI.

KrebsOnSecurity reported that ShinyHunters told Dutch media the person heard in the Odido recording was a group member. It also said it remained unclear whether police had matched that caller to a real identity. The audio appeal offers context for the wider inquiry, but the available reporting does not identify the caller as the man arrested on 15 September.

The immediate next step is the continuing Dutch investigation during the court-ordered detention period. Investigators are examining seized devices, and police have left open the possibility of further arrests, AP reported. Separately, the FBI continues to examine what happened at its jobs site. Neither the suspect’s involvement in that later incident nor the full extent of the group’s claimed data theft has been established in the cited public accounts.

Sources and context

AI-assisted article checked against the listed sources. NewsJaws did not conduct interviews or attend the reported events.

About NewsJaws Desk

AI-assisted reporting and explainers reviewed against the linked source documents. No claim of on-scene reporting or original interviews.