Police in the Netherlands have arrested a suspect they believe to be part of the ShinyHunters criminal hacking group. The FBI calls him one of the group’s alleged leaders.
The arrest came Sept. 15 but only went public this week. In between, ShinyHunters did not go quiet. It claimed a breach of the FBI’s own hiring portal. According to Mandiant, it also mass-exploited an Oracle PeopleSoft flaw by slipping past the firewall rules defenders had put up to block it. For defenders, the lesson is short: an arrest is not a patch.
According to a translated statement from Dutch police, the suspect is a 24-year-old Amsterdam man. He was arrested on suspicion of participating in a criminal organization, namely the notorious hacking and data-disclosure crew. Police seized multiple data storage devices and said further arrests are possible. A Rotterdam court ruled Tuesday that he will stay in pretrial detention for at least another 90 days.
“The suspect came into the picture during an investigation by the National Investigation and Interventions Unit. Team High Tech Crime is investigating ShinyHunters, under the authority of the National Public Prosecutor’s Office,” Dutch police said. “ShinyHunters is a criminal hacker and extortion group that has been involved in many major data breaches, such as those of Odido, Pornhub, and TicketMaster.”
Stan Duijf, who oversees the Dutch police’s approach to cybercrime, said via translation: “The arrest of cybercrime suspects is an important intervention within our broad fight. The group ShinyHunters is responsible for a large number of national and international victims. It is good that we have been able to arrest a suspect in the investigation into this group.”
The man may have much bigger problems than a few cybercrime charges. “After his arrest on September 15, a lot of information was found on his laptop, including about two murders that were supposed to be committed abroad. There are indications that the suspect gave the order for this,” police said via translation.
He is now also suspected of attempted incitement to murder. Police said that suspicion is separate from the ShinyHunters investigation and did not identify the intended targets. Police said that suspicion is separate from the ShinyHunters investigation and did not identify the intended targets.
Conflicting Accounts of Who Was Arrested
Dutch police did not name the suspect, which is standard practice in the Netherlands. Security journalist Brian Krebs, citing sources, identified him as Pepijn van der Stap. Van der Stap was convicted in 2023 of data theft and extortion committed under the hacker handle “Umbreon.” Dutch broadcaster RTL has since reported that van der Stap is the suspect accused of ordering the murders. Police have not confirmed his identity.
That reporting doesn’t line up neatly with the police account. Krebs places van der Stap in Almere and Lelystad, not Amsterdam, and dates the arrest to on or around Sept. 16, a day after the date police gave.
The Odido link doesn’t match either. RTL and NL Times initially tied the arrest to the investigation into Odido, the Dutch telecom. Police now say the suspect was not arrested as part of that case.
The Odido breach remains one of the largest in Dutch history. It exposed data on more than 6 million customers in February. Police say it began with a phone call to Odido’s help desk from someone posing as an IT colleague. On Sept. 7, police released a recording of the caller’s voice and asked the public to identify him. That investigation is ongoing.
The Brand Kept Working
A week after the Dutch arrest, ShinyHunters claimed it had compromised FBIjobs.gov. The FBI has not confirmed that. In a brief statement, the bureau said it is aware of a criminal group claiming the breach and is investigating. It said it doesn’t yet know whether attackers got in through the FBI’s own systems or a third-party provider. Some outlets, including Krebs and NL Times, reported the statement as confirmation of the hack. It isn’t.
The motive is contested, too. In a post on its leak site, ShinyHunters said the attack was retaliation for a May FBI advisory it calls false, according to NBC News and Malwarebytes. The group describes that advisory as a “FLASH report.” Outlets have matched it to is the FBI’s May 15 public service announcement. That PSA warned the group harasses victims, in some cases by swatting, and sometimes exaggerates what it has stolen.
Krebs’ sources tell a different story. In their account, the escalation reflects a power struggle inside ShinyHunters, with a teenage member known as Rey taking control of the brand. They say Rey may have planted “Umbreon” imagery in the FBI site defacement to pin the hack on the jailed Dutchman.
The FBI answered on Tuesday. In a video message, FBI Cyber Division Assistant Director Brett Leatherman said the Dutch National Police had arrested “one of the alleged leaders of ShinyHunters, a group linked to cyberattacks in the United States, the Netherlands, and around the world.”
He then spoke directly to the rest of the group. “You’ve heard about the arrest of your colleague. We’re confident you’ve seen or heard things in recent days that the public has not,” Leatherman said. “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left.”
Why the Details Are Murky
Beyond the arrest itself, almost everything about this case is contested. Dutch police, the FBI, press reports built on anonymous sources, and ShinyHunters’ own leak-site posts disagree on who was arrested, where he lives and when he was taken into custody. They also disagree on whether the FBI was breached at all, and why the group would have gone after the bureau in the first place.
Part of the problem is timing. The arrest also stayed quiet for two weeks. By the time it surfaced, ShinyHunters’ FBI claim had already put the group in the headlines, and the two stories arrived tangled together.
The name itself is part of the problem, too. Google has described ShinyHunters as several affiliated clusters sharing a brand and a playbook rather than a single group. That makes terms like “member” and “leader” slippery.
The group also has a habit of muddying its own record. The FBI warned in May that ShinyHunters sometimes exaggerates what it has stolen, and at least one account of the FBI hack suggests a faction is using it to settle scores inside the group. Law enforcement, meanwhile, has every reason to say as little as possible while its investigations remain open.
The Fix That Wasn’t
The more pressing problem for defenders is PeopleSoft. On Sept. 25, Mandiant reported that ShinyHunters, which it tracks as UNC6240, had renewed mass exploitation of CVE-2026-35273. The group had used the same PeopleSoft flaw as a zero-day against universities between May 27 and June 9, before Oracle issued an emergency fix.
This time, the group went after organizations that had blocked the vulnerable endpoint with firewall rules instead of patching. It got around those rules by disguising a single character in the web address, a trick the firewall didn’t catch but the PeopleSoft server still understood. Mandiant said the group has planted web shells on dozens of systems in higher education, technology, IT services, healthcare, agriculture, transportation and government.
ShinyHunters claims it reached the FBI through PeopleSoft. Neither the FBI nor Mandiant has confirmed that link.
Arrests Haven’t Stopped the Brand Before
That loose structure helps explain why arrests haven’t stuck. French national Sébastien Raoult was sentenced in 2024 to three years in U.S. prison for his role in the crew, and the name carried on without him.
This year alone, ShinyHunters claimed to hav“`e stolen 3.65 terabytes of Canvas data. Instructure later cut an undisclosed deal with the group. In August, ShinyHunters demanded $55.2 million from McKesson over what it claimed were 284 million patient-data records.
Why This Matters to Defenders
It would be easy to read this as a crime story about a hacker, a murder plot and a feud with the FBI. For security teams, though, every thread of it points back to their own environment.
The most immediate risk is the PeopleSoft campaign described above. Any organization that hasn’t applied Oracle’s fix should assume it’s on the list.
The group’s other favorite entry point needs no vulnerability at all. Police say the Odido breach began with one convincing phone call to a customer service desk. SPB reported the same voice-phishing playbook behind the breach at Jack Henry. Verifying the identity of anyone who calls claiming to be from IT is no longer a help-desk courtesy. It’s a front-line security control.
Paying doesn’t close the book, either. Instructure cut a deal with the group in exchange for a promise that the stolen data was destroyed, a promise no one can verify. The FBI warns that data taken in these attacks can be sold or reused to impersonate staff in follow-on attacks. Dutch police say that is already happening: data stolen this year is being widely misused by other criminals, and they expect attacks like these to become more frequent. A breach at a vendor or partner can easily become a phishing lure aimed at your own employees.
Finally, this week offered a lesson in restraint. ShinyHunters’ claims about the FBI became headlines long before anyone could confirm them, and some outlets treated the FBI’s noncommittal statement as confirmation. When a breach claim lands, verify before you escalate.