Finn's Take· TL;DRA suspected leader of one of the world's most prolific cybercrime gangs was already sitting in a Dutch jail cell when his own group pulled off one of its most audacious stunts yet — hacking the FBI's jobs website. Dutch National Police confirmed that the suspect, a 24-year-old from Amsterdam, was arrested on September 15 — meaning he was already in custody days before ShinyHunters announced it had hacked the FBI jobs website, which was first reported on September 22.
FBI Director Kash Patel, in a post on X, did not name the person arrested by the Dutch National Police, but said they are one of the alleged leaders of ShinyHunters — what he called "a global cybercrime and threat actor group linked to cyberattacks in the United States, the Netherlands, and around the world." Police also did not name the man, but Reuters reported that cybersecurity company Neo Security identified him as Pepijn van der Stap, the company's offensive security lead. Dutch investigators visited the office on September 15 — the same day van der Stap was arrested in a police raid that involved flash bang grenades.
ShinyHunters, a prolific cybercriminal group known for large-scale data theft and extortion, claimed on its dark web leak site that it had breached the FBI and stolen "sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job." ShinyHunters told 404 Media that it hacked into the jobs portal using a zero-day vulnerability in Oracle's PeopleSoft human-resources platform, a tactic it has used before. The stolen haul allegedly included two to three terabytes of data — intelligence assignments, medical records, and personal details on agents and their families.
The hackers said their attack was "not financially motivated," and demanded that the FBI remove a report they claimed contained false allegations about the group. They gave a deadline of September 29 to do so, though they did not explicitly say they would publish the stolen data. The FBI did not comply. The bureau is not explicitly tying the Dutch man's arrest to the FBI hack, which seemingly occurred after the man was detained, but is using it to warn other members of the ShinyHunters criminal ring.
Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments. A Mandiant researcher told KrebsOnSecurity that ShinyHunters has been enjoying a successful extortion spree so far this year, and is on track to pull in nearly $100 million in extortion payments from cybercrime victims in 2026. Among the group's highest-profile targets was the Canvas learning management system: in late April 2026, Canvas LMS, operated by private company Instructure, was affected by a data breach and outage , and Canvas was hacked again on May 7, with its login page replaced with a ransomware message by ShinyHunters, who threatened to release Canvas' sensitive data unless its ransom was paid by May 12.
Following a forensic search of the suspect's laptop, he is also being investigated separately over an alleged attempt to incite two contract murders abroad — Dutch police stressed that this allegation is unrelated to the ShinyHunters investigation. Officials did not release additional details about that separate case. The revelation that a cybercriminal suspect's seized devices also revealed alleged murder plots underscores just how dangerous and far-reaching these criminal networks have become.
The arrest forms part of a wider investigation by the National Criminal Investigation and Interventions Unit and the High Tech Crime Team, conducted under the authority of the National Public Prosecutor's Office. The FBI wasted no time leveraging the moment. FBI Cyber Division Assistant Director Brett Leatherman addressed the remaining members of ShinyHunters directly: "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left. The longer you stay in this, the more we learn about you."
ShinyHunters has operated with remarkable boldness — hacking a company that sells identity theft protection, breaching the educational backbone used by hundreds of universities, and now targeting the FBI itself. But Tuesday's announcement signals that international law enforcement is closing the distance. With one alleged leader in custody, seized devices in forensic labs, and a public ultimatum issued to remaining members, the group's era of operating in the shadows may be growing shorter by the day.