Skip to main content
Emerging ThreatsMalware & Ransomware

Dutch Police Apprehend Alleged ShinyHunters Leader

Dutch police officer stands near a young man and a laptop, in a daytime law enforcement setting.

"Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments," Brett Leatherman, the FBI’s assistant director for the cyber division, said in a recorded statement on YouTube. That tally — and the arrest that followed — lays bare both the scale of ShinyHunters’ campaign and the urgency driving an international law enforcement response.

Arrest in Amsterdam and 90-day detention ordered in Rotterdam

Dutch National Police arrested a 24-year-old man in Amsterdam whom they accuse of participating in ShinyHunters, the cybercrime group linked to a string of high-profile extortion attacks since 2025, including last week’s attack on the FBI. Officials have not named the accused; independent cybersecurity journalist Brian Krebs identified him as Pepjin van der Stap, described in reporting as a previously convicted cybercriminal who moonlighted as a cybersecurity professional.

A court in Rotterdam ordered the suspect to remain detained awaiting trial for at least 90 days as investigators continue to process evidence and pursue related leads.

Evidence seized: laptop, alleged murder orders, and digital traces

The Dutch National Police said they retrieved a large amount of evidence from the suspect’s laptop, including details about two murders he allegedly ordered abroad. Authorities have not publicly elaborated on the nature of that material beyond the police statement, but the seizure is being treated as a significant development in the broader investigation into ShinyHunters’ activities.

ShinyHunters’ posture: targeting third-party vendors and cloud platforms

Brett Leatherman described a pattern the group has used to amass access and leverage: they "often target third-party vendors in cloud-based platforms, stealing sensitive data and extort victims with threats to publish it." According to Leatherman’s statement, the campaign of breaches attributed to "this cybercriminal and his co-conspirators" stretches back to last year and spans a broad range of sectors — a fact reflected in the named victims this year.

ShinyHunters has been linked to breaches of major cloud platforms, healthcare organizations, universities, technology companies, retailers and education service providers. Specific victims this year named in reporting include Instructure, Salesforce, Snowflake and McKesson.

FBI public posture: seize infrastructure, cultivate cooperation, and press the group

The arrest prompted public comments from senior FBI officials. Leatherman addressed other ShinyHunters members directly in his recorded statement: "You’ve heard about the arrest of your colleague. We’re confident you’ve seen or heard things in recent days that the public has not. Other groups believed anonymity or their friends would protect them, and they were wrong," he said. He added: "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you."

FBI Director Kash Patel also posted about the case on X, saying: "FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest." Leatherman closed his appeal with a direct warning: "You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."

How cloud vendors, healthcare and education providers, and law enforcement are responding

  • Cloud vendors and third-party service providers — cited specifically by Leatherman as frequent targets — will be watched closely by investigators and by customers that rely on their platforms for sensitive data. The arrest and seized infrastructure may reveal compromises tied to vendor relationships and cloud access patterns.
  • Healthcare organizations, universities and education service providers — sectors named among ShinyHunters’ targets — will face renewed scrutiny over incident response preparedness and data protection, given that victims this year included Instructure and McKesson.
  • Law enforcement agencies, including the FBI, will press forward with cross-border collaboration: the arrest in the Netherlands and the Rotterdam detention order underscore international cooperation in trying to disrupt criminal infrastructure and pursue both digital evidence and alleged physical crimes tied to the suspect.

The arrest in Amsterdam — occurring about a week before ShinyHunters claims it broke into FBI systems and stole reams of data containing sensitive information on almost every FBI agent — is being presented by investigators as a pivotal moment that could alter the group’s operational secrecy. Prosecutors and investigators will now face the task of translating seized digital material into courtroom evidence, and the broader community of affected organizations will be watching whether the detained suspect’s laptop and any disrupted infrastructure yield names, methods or recovery leads.

Original reporting: https://cyberscoop.com/shinyhunters-alleged-leader-arrested-netherlands/