Dutch police arrest 24-year-old alleged ShinyHunters leader in global cybercrime investigation | #cybercrime | #infosec


Dutch authorities arrested a 24‑year‑old man in Amsterdam as a suspected leader of the ShinyHunters hacking group

Dutch police announced that a 24-year-old man from Amsterdam was arrested on 15 September 2026 on suspicion of playing a role in the cybercrime group ShinyHunters. The suspect has since been identified by cybersecurity industry sources as Pepijn van der Stap, an offensive security lead at an Amsterdam-based firm.

Black-hat criminal hacker group

ShinyHunters

ShinyHunters is a black-hat criminal hacker group notorious cybercrime and extortion group responsible for some of the largest data breaches in history. Utilizing voice phishing, social engineering, and advanced data exfiltration techniques to compromise enterprise systems worldwide.

The arrest forms part of a wider investigation by the National Criminal Investigation and Interventions Unit and the High Tech Crime Team, conducted under the authority of the National Public Prosecutor’s Office. Police seized several data-storage devices for forensic examination and said further arrests could not be excluded. ShinyHunters is described by Dutch authorities as a criminal hacking and extortion group involved in major international data breaches, including incidents affecting Odido, Pornhub, and Ticketmaster. The group has also claimed responsibility for attacks against other prominent organisations, including the FBI and Rockstar Games.

The arrest comes against the background of the February 2026 compromise of Dutch telecommunications provider Odido, in which data concerning more than six million customers was stolen. The subsequent investigation established that the attackers used social engineering rather than a purely technical exploit to obtain initial access. In a recorded telephone call, a Dutch-speaking man impersonated an Odido IT employee and convinced a customer-service employee that an internal technical problem needed to be resolved. The employee was directed to a fraudulent login page and entered a username and password. A further verification code was then provided, allowing the attackers to gain access to Odido’s internal systems. The stolen customer data was subsequently offered on the dark web after Odido refused to pay the ransom. In September, Dutch police publicly released part of the suspect’s voice recording in an effort to identify him.

The September arrest should nevertheless not be interpreted as an arrest for the Odido intrusion itself. Dutch police explicitly stated that the 24-year-old was arrested as part of the investigation into ShinyHunters and that he was not arrested in connection with the Odido hack. Investigators continue to seek evidence identifying those directly responsible for the telecommunications breach. This distinction is important because membership or participation in a cybercriminal organisation does not, by itself, establish responsibility for a specific intrusion.

The forensic examination of the seized devices could nevertheless provide investigators with evidence concerning communications, infrastructure, stolen data, financial transactions, or relationships with other members of the group. Following a forensic search of his laptop, the suspect is also being investigated separately over an alleged attempt to incite two contract murders abroad; Dutch police stressed that this allegation is unrelated to the ShinyHunters investigation.

The arrest also comes as ShinyHunters has attracted renewed international attention following a series of high-profile claims. Most notably, in late September 2026, the group claimed a massive breach of the FBIJobs.gov website, alleging they utilized a vulnerability in Oracle PeopleSoft human resources software to steal sensitive personal information of roughly 38,000 Bureau staff and applicants.

The circumstances and extent of individual incidents vary, and claims by a criminal group do not in themselves establish attribution. Following the public announcement of the Dutch arrest, FBI Director Kash Patel addressed the development on X, calling the suspect “one of the alleged leaders” of the global threat actor group and stating that FBI teams are actively executing new leads based on the arrest. Meanwhile, FBI Cyber Division Assistant Director Brett Leatherman publicly urged the remaining members of ShinyHunters to surrender, while the group itself has issued dark-web denials that the Dutch suspect is associated with them.

Why does it matter?

The Dutch investigation illustrates both the scale and the investigative complexity of contemporary data-theft and extortion networks. ShinyHunters’ alleged activities span different countries, sectors, and attack techniques, while stolen information can be monetised, redistributed, or reused long after the initial compromise.

The Odido case itself demonstrates that large-scale breaches do not necessarily depend on sophisticated exploitation of technical vulnerabilities: social engineering and the manipulation of trusted relationships can provide a pathway into systems containing information on millions of individuals. At the same time, the arrest highlights the importance of distinguishing between group-level attribution and individual criminal responsibility.

Dutch investigators have established a suspected connection between the arrested man and ShinyHunters, but the Odido perpetrators remain under investigation. The case therefore demonstrates how cybercrime investigations increasingly combine technical forensics, social-engineering evidence, infrastructure analysis, and international law-enforcement cooperation to move from a digital intrusion towards identifying the individuals behind it.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!



Click Here For The Original Source.

——————————————————–

..........

.

.