Patel says Dutch police arrested alleged leader of group accused of hacking FBI | #cybercrime | #infosec


FBI Director Kash Patel said Tuesday that Dutch police arrested an alleged leader of ShinyHunters, the group that is being investigated for stealing bureau employees’ data.

“This morning @FBI and our partners the Dutch National Police are announcing the arrest of one of the alleged leaders of ShinyHunters – a global cybercrime and threat actor group linked to cyberattacks in the United States, the Netherlands, and around the world,” Patel posted on X.

“In coordination with FBI investigators the Dutch High-Tech Crime Unit arrested the suspect under Dutch law. As we speak FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest,” he continued.

“Thank you to our Dutch National Police partners for their continued work with us in this case and the industry partners who shared information with us. The investigation continues.”

On Monday, Dutch police said that they arrested a suspect in connection with ShinyHunters.

“It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters. On Tuesday, September 29, the man will appear before the chamber of the Rotterdam District Court. Tomorrow we will provide more information,” the Dutch police posted on X.

While neither Patel nor the Dutch police named the suspect, Amsterdam-based cybersecurity company Neo Security’s CEO, Benjamin Korper, said it was Pepijn van der Stap, his company’s offensive security lead, Reuters reported.

Korper told the newswire that Dutch forensic investigators visited his office on Sept. 15, the same night that Van der Stap was arrested in a police raid that involved flash-bang grenades.

The announcement of the arrest comes after the FBI said Wednesday that it was investigating ShinyHunters’ claim that it stole the personal information of the bureau’s employees.

ShinyHunters, a cyber-extortion hacking group, said last week that they “hacked the FBI. We hold data on all FBI employees and applicants.”

Screenshot 2026-09-22 at 4.27.13 PM.png

The group claimed that the information on the FBI employees included their phone numbers, names, and addresses.

ShinyHunters hacks companies to steal their data and threatens to publish it on the dark web if not paid. The group said Wednesday that it had hacked into the FBI’s jobs portal, which allowed it to steal sensitive files, including individual agents’ personal information.

The hackers said in a post on their website that the alleged hack was retaliation for the FBI’s public service announcement about the group in May.

FBIjobs.gov leads web users to a server error page as of Sept. 23.

FBIjobs.gov leads web users to a server error page as of Sept. 23.

At least some of the stolen data reportedly included FBI employees’ intelligence assignments and medical records.

An internal memo said the FBI assumes that hackers stole data on all bureau employees, an unnamed source told Reuters.

The FBI said in a statement that it was “working around the clock” to investigate the hack and was “in regular communication with anyone who may be impacted.”

ShinyHunters said in a statement that van der Stap had “no association” with their group and that Dutch police were incompetent. The hacking group said that they were no longer setting a deadline for the FBI to rescind the PSA about them, after previously giving the bureau a week.

“This was not a threat,” ShinyHunters said. “Nothing will happen.”

In 2023, van der Stap was convicted of data theft and extortion, which had received widespread publicity, along with his subsequent public disavowal of cybercrime. Van der Stap acknowledged on his personal website that his journey “hasn’t been a straight line” but said his experience had taught him that “knowledge is for building and protecting, not breaking.”

Korper said he was shocked by the arrest, as he had carefully vetted van der Stap before hiring him, and monitored him during his employment.

“I truly believe that people deserve a second chance, but in this case I was not thanked for it,” Korper said. “Absolutely everybody I talked to is flabbergasted.”

Korper added that he hired an outside firm to investigate whether Van der Stap had hacked Neo Security or its customers, but that investigators have so far found no evidence that he acted against his employer or its clients.

The Neo Security CEO said that he and van der Stap have not been in touch since the arrest.

Reuters was unable to reach van der Stap or identify a lawyer or representative for comment.



Click Here For The Original Source.

——————————————————–

..........

.

.