Dutch police apprehended a 24-year-old Amsterdam man suspected to be a leader of the ShinyHunters hacking group, known for attacks on Ticketmaster, Rockstar Games, and the FBI. The arrest coincides with intensified efforts by international law enforcement to dismantle the group’s operations.

  • Suspect arrested in Amsterdam on September 15
  • ShinyHunters linked to major cyberattacks worldwide
  • FBI urges remaining hackers to surrender

What happened

Dutch police arrested a 24-year-old man from Amsterdam in connection with ShinyHunters, a hacking collective responsible for multiple high-profile cyberattacks. The arrest took place on September 15th, shortly before the group claimed another breach involving the FBI’s website and employee data.

Reports identify the suspect as Pepijn van der Stap, who was previously convicted in 2023 for data theft and extortion. After his release, van der Stap worked with a Dutch cybersecurity firm, Neo Security. Authorities have not officially confirmed his identity, but investigations continue with cooperation from the FBI.

Why it matters

ShinyHunters has been linked to significant data breaches affecting companies like Ticketmaster and Rockstar Games, and more recently, a breach of FBI systems. The arrest of a suspected leader marks a critical step in disrupting their operations and deterring other cybercriminals.

The FBI has publicly highlighted the arrest as an opportunity for other group members to come forward. This signals an ongoing commitment by law enforcement agencies to escalate pressure on cybercrime groups and reduce risks to sensitive data and national security.

What to watch next

Ongoing joint investigations between Dutch authorities and the FBI are expected to yield additional leads about the inner workings and other members of ShinyHunters. Authorities are pursuing further arrests and evidence to dismantle the group's network.

Cybersecurity experts and organizations impacted by ShinyHunters’ breaches will watch closely for developments that could influence their defensive strategies. The public and private sectors may also increase efforts in preventative measures and threat intelligence sharing in response.

Source assisted: This briefing began from a discovered source item from The Verge Policy. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings