Skip to content

Dutch Police Arrest Alleged ShinyHunters Leader Linked to Murder Plot Investigation

Dutch authorities, in coordination with the FBI, have arrested a 24-year-old man from Amsterdam suspected of leading the notorious ShinyHunters hacking group. The suspect, identified as Pepijn van der Stap, is also under investigation for allegedly planning two murders abroad. The arrest follows a series of high-profile data breaches linked to the group, including a recent breach of FBI systems.

Editor, Lazyfounder

Published 6 min read
Dutch Police Arrest Alleged ShinyHunters Leader Linked to Murder Plot Investigation
Image: Image Credits:Bryce Durbin / TechCrunch / Getty Images via source

Dutch authorities, in coordination with the FBI, have arrested a 24-year-old man from Amsterdam suspected of leading the notorious ShinyHunters hacking group. The suspect, identified as Pepijn van der Stap, is also under investigation for allegedly planning two murders abroad. The arrest follows a series of high-profile data breaches linked to the group, including a recent breach of FBI systems.

30 SEC SUMMARY

  • Dutch police, in collaboration with the FBI, arrested a 24-year-old Amsterdam man alleged to be a leader of the ShinyHunters hacking group on September 15.
  • The suspect, Pepijn van der Stap, also faces investigation for planning two murders abroad, separate from cybercrime charges.
  • ShinyHunters is linked to over 140 data breaches, including attacks on Pornhub, Ticketmaster, AT&T, and Odido.
  • The FBI confirmed a recent breach of its systems, with ShinyHunters claiming responsibility and exposing sensitive agent data.
  • Van der Stap was employed as CTO at Neo Security and was arrested during a raid involving flash-bang grenades.

TABLE OF CONTENTS

  • Arrest and Charges
  • ShinyHunters’ Hacking Campaigns
  • Suspect’s Background and Denials
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • A 24-year-old Amsterdam man, Pepijn van der Stap, was arrested on September 15 for alleged involvement with the ShinyHunters hacking group.
  • Dutch police and the FBI conducted the arrest, which involved a raid at Neo Security, where Van der Stap served as CTO.
  • ShinyHunters is linked to over 140 data breaches, including attacks on Pornhub, Ticketmaster, AT&T, and Odido.
  • The FBI recently confirmed a breach of its systems, with ShinyHunters claiming responsibility and exposing sensitive agent data.
  • Van der Stap is also under investigation for allegedly planning two murders abroad, separate from the cybercrime charges.

Arrest and Charges

Dutch police, in collaboration with the FBI, arrested a 24-year-old man from Amsterdam on September 15 on charges of participating in a criminal organization, ShinyHunters. The suspect, identified as Pepijn van der Stap, was taken into custody during a raid at the offices of Neo Security, where he served as Chief Technology Officer (CTO). According to TechCrunch, the raid involved the use of flash-bang grenades.

Van der Stap is accused of being a leader of ShinyHunters, a hacking group linked to over 140 data breaches globally. The group has targeted high-profile organizations, including Pornhub, Ticketmaster, AT&T, and the Dutch telecom provider Odido. However, Dutch authorities clarified that Van der Stap’s arrest is not directly related to the Odido breach.

In addition to cybercrime charges, Van der Stap is under investigation for allegedly orchestrating two murders abroad. Dutch police reported discovering evidence related to the murders on his laptop. The investigation into these allegations is separate from the ShinyHunters case.

ShinyHunters’ Hacking Campaigns

ShinyHunters is a cybercriminal group known for infiltrating companies to steal data and threatening to publish it unless a ransom is paid. According to TechCrunch, the group has claimed responsibility for breaches at major organizations, including Pornhub, Ticketmaster, and AT&T. In July, the group also took credit for a breach at Odido, a Dutch telecommunications provider.

The group gained additional notoriety earlier this month after claiming responsibility for a breach of the FBI’s own systems. The breach exposed sensitive data, including personal information, blood and urine samples, and psychiatric reports of FBI agents and applicants. The FBI acknowledged the incident but has not publicly confirmed ShinyHunters’ involvement.

ShinyHunters stated that the FBI breach was not financially motivated. Instead, the group claimed it was intended to challenge public allegations made by the FBI, which the hackers say are false. The group has not published the stolen FBI data.

Suspect’s Background and Denials

Pepijn van der Stap was profiled by Bloomberg in 2024 as a cybersecurity researcher who allegedly moonlighted as a hacker involved in extorting companies. At the time of his arrest, he was employed as CTO at Neo Security, a cybersecurity firm based in the Netherlands.

Following his arrest, ShinyHunters publicly denied any association with Van der Stap. The group’s statement suggests a potential fracture within the organization or an attempt to distance itself from the allegations. The Dutch High Tech Crime Unit continues to investigate the extent of Van der Stap’s involvement in the group’s activities.

What this means

Lazyfounder analysis — our interpretation, not reported fact.

This arrest underscores the blurred lines between legitimate cybersecurity work and criminal hacking, a growing concern for startups and established companies alike. Founders, especially in high-risk sectors like fintech, e-commerce, and telecom, should take note: even seemingly reputable security professionals may have hidden ties to criminal groups. The ShinyHunters case also highlights the increasing sophistication of cybercriminals, who now target law enforcement agencies themselves.

For startups, this is a reminder to vet not just vendors but also internal security teams rigorously. A single breach—or worse, an insider threat—can expose sensitive data, damage reputation, and invite regulatory scrutiny. The fact that the FBI, one of the world’s most secure agencies, was breached speaks to the scale of the challenge.

Key takeaways

  • A 24-year-old man from Amsterdam, identified as Pepijn van der Stap, was arrested for alleged involvement with the ShinyHunters hacking group.
  • The arrest was part of a joint operation between Dutch police and the FBI, with the suspect also under investigation for planning two murders.
  • ShinyHunters has been linked to data breaches at major organizations, including Pornhub, Ticketmaster, AT&T, and Odido.
  • The FBI recently suffered a breach claimed by ShinyHunters, exposing sensitive data, including personal information and psychiatric reports of agents.
  • The suspect was employed as CTO at Neo Security and was arrested during a high-profile raid at the company’s offices.
  • ShinyHunters denies any association with Van der Stap and claims the FBI breach was not financially motivated.

FAQ

Who is Pepijn van der Stap?

Pepijn van der Stap is a 24-year-old cybersecurity professional from Amsterdam who was arrested on September 15 for alleged involvement with the ShinyHunters hacking group. He served as CTO at Neo Security and has been profiled in the past for his dual role as a researcher and alleged cybercriminal.

What is ShinyHunters?

ShinyHunters is a cybercriminal group known for hacking into companies, stealing data, and threatening to publish it unless a ransom is paid. The group has claimed responsibility for over 140 data breaches, including attacks on Pornhub, Ticketmaster, AT&T, and Odido.

What was the FBI breach about?

ShinyHunters claimed responsibility for a recent breach of FBI systems, exposing sensitive data such as personal information, blood and urine samples, and psychiatric reports of FBI agents and applicants. The group stated the breach was not financially motivated but intended to challenge FBI allegations.

Why was Van der Stap also investigated for murder?

Dutch police found evidence on Van der Stap’s laptop suggesting he was involved in planning two murders abroad. The investigation into these allegations is separate from the cybercrime charges.

What does this mean for startups?

This case highlights the risks of insider threats and the importance of thorough vetting for cybersecurity roles. Startups should ensure robust security protocols, as even high-profile organizations like the FBI are vulnerable to breaches.

Related on Lazyfounder

Sources

  1. TechCrunch · 2026-09-29
    Dutch police arrest ShinyHunters hacker accused of planning two murders

This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

About the author

Editor, Lazyfounder

Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.

More stories by Tarun Mottlia

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in

Contact us

Have a story tip, correction or partnership idea?

Write to us at tarun.kumar@blogy.in or talk to the founder directly. We read every message.

Contact us