Dutch authorities apprehend ShinyHunters cybercriminal charged with plotting two homicides

Dutch authorities apprehend ShinyHunters cybercriminal charged with plotting two homicides

The FBI along with Dutch law enforcement have announced the arrest of an individual associated with the ShinyHunters hacking collective, which is believed to have conducted breaches affecting more than 140 organizations globally. This group also claimed to be behind a recent compromise of the FBI’s internal systems.

Brett Leathermann, leading the FBI’s cyber division, stated in a video message on Tuesday that authorities in the Netherlands apprehended one of the “alleged heads of ShinyHunters.” He remarked that the Dutch High Tech Crime Unit “acted swiftly to safeguard victims and secure vital evidence,” and promised that the FBI would pursue the remaining hackers after this arrest.

In a different announcement, Dutch police verified that a 24-year-old man from Amsterdam, whose name has not been disclosed, was detained under Dutch regulations on September 15. He was set to appear in court on Tuesday and has been held in custody for a minimum of 90 days.

Authorities stated that the individual was arrested for “involvement in a criminal organization,” referring to ShinyHunters.

After his arrest and the confiscation of his devices, police reported that “a substantial amount of information was discovered on his laptop, including details concerning two murders planned to take place overseas.” Consequently, he is also under investigation for attempting to facilitate those murders. Dutch authorities emphasized that this inquiry is “distinct from the investigation into ShinyHunters.”

ShinyHunters is recognized as a cybercrime syndicate accused of infiltrating corporations to expropriate large volumes of data and then threatening to release the information unless a ransom is paid. Dutch authorities allege that the group is involved in data breaches at Pornhub, Ticketmaster, and U.S. telecom behemoth AT&T. The hacking group also claimed responsibility for a breach involving Dutch telecommunications provider Odido. However, officials clarified that the individual taken into custody is not linked to the Odido incident.

Independent security journalist Brian Krebs, who first reported on the arrest, along with other news sources, have identified the arrested individual as Pepijn van der Stap, previously featured in Bloomberg in 2024 as a cybersecurity expert who also engaged in criminal hacking activities to extort businesses.

Based on recent coverage from Bloomberg and Reuters, Van der Stap was arrested earlier this month by local police at Neo Security’s offices, where he holds the position of chief technology officer. The operation reportedly involved the use of flash-bang grenades.

A spokesperson for Neo Security did not respond promptly to TechCrunch’s request for a statement. When queried by TechCrunch, a representative from the ShinyHunters group asserted that Van der Stap “is not affiliated with us.”

The arrest news emerged shortly after the FBI reportedly informed its agents and staff that their personal information, which includes names, addresses, job titles, and Social Security numbers, was compromised during a “cyber security incident.” Although the FBI has yet to officially confirm a breach, the ShinyHunters group claimed to have obtained personal and sensitive data of “almost all” FBI agents and applicants by exploiting its careers website and job application portal.

Among a subset of approximately 5,000 agents whose data was stolen from the portal, reporters discovered information related to agents’ blood and urine tests, in addition to psychiatric assessments, heightening concerns about a significant counterintelligence risk posed by an adversarial government accessing the information.

When approached by TechCrunch, Leathermann refrained from making a statement. An FBI representative declined to address inquiries regarding the arrest.

In their statements, the ShinyHunters hackers insisted that the breach of the FBI’s servers was not financially driven, but aimed at contesting public statements made by the FBI that they claim include false accusations against them. The hackers informed TechCrunch that they do not intend to release the stolen FBI data, stating that the breach was “to make a point and to refute the accusations directed at us, which we have accomplished.”

When you make a purchase through links in our articles, we may receive a small commission. This does not impact our editorial independence.

Leave a Reply