The FBI on Tuesday called on ShinyHunters group members to come forward in the wake of the alleged leader’s arrest.
The suspected leader, Pepijn van der Stap, of Amsterdam, was arrested on September 15 in the Netherlands while on probation after serving three of the four-year prison term he was sentenced to in 2023 over hacking and extortion activities.
The Dutch police on Tuesday said the 24-year-old man is suspected of “playing a role within the hacking group ShinyHunters” and of planning two murders.
“After his arrest on September 15, a lot of information was found on his laptop, including about two murders that should be committed abroad. There are indications that the defendant has ordered this,” reads an automated translation of the Dutch police’s announcement.
According to the FBI, the suspect is one of the alleged leaders of the extortion group. Since 2025, the authorities say, he has been involved in the hacking of over 140 organizations and in collecting at least $70 million in extortion payments.
“They often target third-party vendors in cloud-based platforms, stealing sensitive data and extorting victims with threats to publish it,” said FBI Cyber Division Assistant Director Brett Leatherman.
According to Leatherman, other ShinyHunters group members should take notice of the arrest and come forward before the authorities find them.
“To the remaining members of ShinyHunters: You’ve heard about the arrest of your colleague. We’re confident you’ve seen or heard things in recent days that the public has not,” Leatherman said.
“Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours,” he added.
Not extortion, ShinyHunters says
Before the FBI’s statement, the hacking group appeared confident that making headlines over the past week has helped it gain more attention, rather than hurting its business.
Referring to the hack of FBIJobs.gov and the one-week ultimatum it gave to the Bureau to retract a previous report stating the group tends to exaggerate its claims, ShinyHunters now says all was a marketing campaign meant to protect its brand.
The group previously claimed it stole from the FBI’s jobs site the personally identifiable information (PII) and protected health information (PHI) of all current and former FBI employees. It sent a sample list of 5,000 FBI employees to multiple media outlets, stating that it stole 2-3 terabytes of data.
This week, ShinyHunters provided the following statement to the media:
“Since the very beginning of this event we have unequivocally and assiduously emphasised this is NOT extortion, this is NOT ransom, this is NOT financially motivated.
This was all a marketing campaign to protect our business and actively combat disinformation. If we made this statement normally then this much attention to our words and intentions would’ve never been this widespread. We’d have been ignored and disregarded.
However, now everyone knows what the issue is and what we are doing. Everyone is reading about it. We proved our points on several occasions. We do not care what the public says and we are not affected by it nor do we cloud our judgement by external opinions and thoughts.
We understand why many misinterpreted this as extortion and are convinced we would publish this data and/or misuse it such as selling to third parties due to our history in past operations which has never involved a government entity of prominence.
We again want to emphasise that this is not extortion. It never was one to begin with, not a threat, not a ransom, and not financially motivated. Nothing will happen. We are way past this situation in our businesses operations and we confidently believe we have been successful due to seeing a recent influx of success in our operations.
We stand corrected.”
In a fresh statement on its Tor-based leak site, the extortion group says its operations and infrastructure have not been affected by the recent events, warning victim organizations that they should continue negotiations to prevent the leak of stolen data.
“We are eagerly waiting to make examples of those organizations who think they may have gotten a free pass into not paying us few tens of millions of dollars,” the group wrote.
Will ShinyHunters survive?
Some suggest that the group has decided against extorting the FBI due to the implications: the agency would be even more motivated to identify and hunt down ShinyHunters members.
Others, however, suggest that foreign intelligence agencies might have promised ShinyHunters protection in exchange for the data. None of these have been confirmed.
According to GuidePoint Security threat intelligence expert Jason Baker, however, it is unlikely that van der Stap’s arrest by the Dutch police would lead to the extortion group’s demise.
Even subsequent arrests may not result in ShinyHunters’ demise as a whole. Due to the decentralized nature of the operation, the remaining members may change the group’s name or spin off to other hacking gangs.
iCOUNTER director of customer advisory counter fraud lead Jason Brown believes the same.
“An arrest is a disruption, not an ending. ShinyHunters operates like a brand, not a fixed crew. Handles change and members rotate, which is why its current leader is reportedly pinning the FBI hack on someone the group was previously associated with. Arrests like this matter. They create fear and distrust inside the group and give investigators leverage. But the people still operating won’t stop. They’ll adjust,” Brown said.
“Groups like this don’t win with new exploits alone. Their most damaging campaigns have come from going after the people inside vendors, help desks, and SaaS providers who hold privileged access, then using that trust to reach dozens of downstream victims at once. That’s the real exposure for most organizations,” he added.
Related: Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Related: Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Related: NightmareStresser DDoS Service Disrupted in International Operation


