Threat Intelligence Neutral 7

ShinyHunters suspect held: 140+ breaches, $70M extortion

Dutch police have arrested the alleged leader of ShinyHunters, the extortion group behind 140+ breaches and at least $70 million in payments since 2025. The suspect, identified as Pepijn van der Stap, was working at a Dutch security firm and is now linked to two alleged murder plots. The arrest hands investigators a seized laptop likely to expose infrastructure, affiliates, and additional victims.

· 4 min read · Verified by 2 sources ·

Beat this week

Last 7 days · Threat Intelligence

7 stories
7.6 avg impact
0% positive
71% negative
vs prior 7 days -6 -6 stories vs prior 7 days

Impact 7.6/10 (+1 vs prior). Counts are stories in our record, not a market forecast.

Open the change report

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 71 percentage points.

  • 29% neutral
  • 71% negative

This story sits in Threat Intelligence — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

Cybersecurity briefing

Key takeaways

7 impact
Neutralsentiment
2sources
4min read
  1. Dutch police have arrested the alleged leader of ShinyHunters, the extortion group behind 140+ breaches and at least $70 million in payments since 2025.
  2. The suspect, identified as Pepijn van der Stap, was working at a Dutch security firm and is now linked to two alleged murder plots.
  3. The arrest hands investigators a seized laptop likely to expose infrastructure, affiliates, and additional victims.
Drawn from
  • Matt Kapko
  • Emma Roth

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Dutch National Police arrested a 24-year-old man in Amsterdam on September 15, 2026; Krebs on Security and Reuters identified him as Pepijn van der Stap, a previously convicted cybercriminal.
  2. 2FBI Assistant Director Brett Leatherman says the suspect and his co-conspirators breached more than 140 organizations and took at least $70 million in extortion payments since 2025.
  3. 3The arrest came roughly a week before ShinyHunters claimed to have broken into FBI systems and stolen sensitive data on nearly every FBI agent.
  4. 4Van der Stap was convicted in 2023 for data theft and extortion and later joined Dutch cybersecurity firm Neo Security after his release from prison, according to Krebs on Security.
  5. 5Dutch police say evidence on the suspect's laptop included details about two murders he allegedly ordered abroad; a Rotterdam court ordered 90 days of pre-trial detention.
  6. 6ShinyHunters told Reuters van der Stap has 'no association' with the group; named past victims include Ticketmaster, Rockstar Games, Salesforce, Snowflake, McKesson and Instructure.

Who's Affected

ShinyHunters
companyNegative
FBI
companyNegative
Neo Security
companyNegative
ShinyHunters victims (Salesforce, Snowflake, McKesson, Ticketmaster)
companyNegative

The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you.

Brett Leatherman Assistant Director, FBI Cyber Division

Video statement warning remaining ShinyHunters members

Analysis

For cybersecurity teams, the ShinyHunters arrest is less a victory lap than a case study in failure modes. The alleged leader, Pepijn van der Stap, was a convicted cybercriminal who walked out of prison into a job at Dutch firm Neo Security — a reminder that insider risk can sit inside your own industry. Meanwhile, the group's playbook of compromising third-party cloud vendors and extorting victims with data-publication threats remains as relevant to defenders as ever, with the FBI's $70 million figure quantifying the scale of the threat.

The arrest of a 24-year-old Amsterdam man identified as Pepijn van der Stap is the most significant law-enforcement action to date against ShinyHunters, the cybercrime group behind some of the highest-profile data extortion campaigns of the past two years. Dutch National Police took the suspect into custody on September 15, 2026, and a Rotterdam court has ordered him held for at least 90 days pending trial. Authorities have not officially named him, but independent journalist Brian Krebs and Reuters identified him as van der Stap, who was convicted of data theft and extortion in 2023 and later took a role at the Dutch cybersecurity firm Neo Security after his release from prison.

Meanwhile, the group's playbook of compromising third-party cloud vendors and extorting victims with data-publication threats remains as relevant to defenders as ever, with the FBI's $70 million figure quantifying the scale of the threat.

FBI Assistant Director Brett Leatherman quantified the alleged operation in a video statement released Tuesday: the suspect and his co-conspirators have breached more than 140 organizations and collected at least $70 million in extortion payments since 2025. That scale explains why ShinyHunters is regarded as among the most prolific cybercrime groups in operation. Its victims span cloud platforms, healthcare providers, universities, technology companies, retailers and education-services firms, with named targets this year including Instructure, Salesforce, Snowflake and McKesson — alongside earlier, widely reported claims against Ticketmaster and Rockstar Games.

A crucial wrinkle is the timing. The arrest came about a week before ShinyHunters claimed to have broken into the FBI itself and stolen data containing sensitive information on nearly every FBI agent. Either the group continued operating without one of its alleged leaders — evidence of a decentralized, resilient structure — or the FBI-breach claim is opportunistic. ShinyHunters has already told Reuters that van der Stap has 'no association' with the group, a denial that is standard in the immediate aftermath of an arrest and should be treated with caution.

The van der Stap–Neo Security connection may be the most consequential subplot for the security industry. According to Krebs on Security, van der Stap joined the Dutch firm after his release from prison, effectively operating as a defensive security professional while allegedly helping run an extortion enterprise. If confirmed, it is a sharp reminder that insider threat and vetting failures are not limited to victim organizations; they can reside inside the companies entrusted with protecting them.

Equally striking is the allegation that evidence on van der Stap's laptop includes details about two murders he allegedly ordered abroad, described by Dutch police as attempted incitement to commit two murders. That detail blurs the boundary between financially motivated cybercrime and violent crime, and it raises the personal stakes for any co-conspirator weighing whether to cooperate.

The case also illustrates how cybercrime investigations increasingly unfold across borders. Dutch National Police executed the arrest, the FBI is leading the extortion case in the United States, and a Rotterdam court is now managing pre-trial detention — a coordination pattern that has become essential as groups like ShinyHunters operate globally, often from jurisdictions beyond their victims' reach.

What to Watch

Law enforcement is plainly using the arrest as a psychological wedge. Leatherman's warning — 'The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you' — and FBI Director Kash Patel's statement that teams are 'actively working with partners to obtain and execute more leads' signal a deliberate effort to destabilize the group and induce defections. The seized laptop is likely the investigation's most valuable asset, potentially exposing infrastructure, affiliates, victims and additional suspects across multiple countries.

Looking ahead, the arrest is unlikely to end ShinyHunters overnight. Modern extortion groups often operate as loose affiliate networks that can absorb the loss of a single figure, and the claimed FBI breach suggests at least some operational continuity. But the combination of a detained alleged leader, a seized evidence trove and sustained public FBI pressure creates genuine momentum. The coming weeks will reveal whether the FBI breach claim is substantiated and whether the arrest produces follow-on operations and victim notifications. For enterprises, the immediate takeaway is operational: ShinyHunters' signature playbook — compromising third-party cloud vendors and extorting victims with the threat of data publication — demands renewed attention to supply-chain security, third-party risk management and data-exfiltration controls.

Source cluster

Primary reporting

2articles

Cite This Page

"ShinyHunters suspect held: 140+ breaches, $70M extortion." Cyber Intelligence Brief, September 30, 2026. https://getcyberbrief.com/story/shinyhunters-alleged-leader-arrest-netherlands-cyber

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.