Alleged ShinyHunters Leader Arrested in Amsterdam: What We Know
ShinyHunters arrest: an alleged leader was detained in Amsterdam with FBI support. The suspect, the group's tactics, and what defenders should do next.

On 29 September the FBI and the Dutch National Police announced the arrest of a man they describe as one of the leaders of ShinyHunters. The arrest itself happened two weeks earlier. Dutch police detained the 24-year-old Amsterdam suspect on September 15 under Dutch law, with FBI investigators supporting the operation. cybersecuritynews
The suspect
Dutch police have not named him. Security journalist Brian Krebs and DataBreaches.Net identified him as Pepijn van der Stap (aka Umbreon), who was previously arrested in 2023 over a series of data thefts and extortions, and sources familiar with the case confirmed the name to CBS News. Until recently he worked as the offensive security lead at Amsterdam cybersecurity firm Neo Security, the company told Reuters. Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation +2
He is being held in isolation and is expected to stay in pretrial detention for at least 90 days. Police also say they found information on his laptop about two murders allegedly meant to be carried out abroad, and that this suspicion is not related to the ShinyHunters investigation. None of the allegations have been tested in court. Dutch National Police arrest member of group that claimed to have hacked FBI - CBS News +2
What the FBI says the group did
According to the FBI, ShinyHunters has breached more than 140 organizations since last year and collected at least $70 million in extortion payments, often by going after third-party vendors on cloud platforms. Healthcare has been a frequent target. In August, Health-ISAC warned that the group was using voice phishing to push staff onto fake medical-themed domains, and contacting employees directly on personal phones through calls, voicemails and emails. fbiaha
The timing
The arrest came before the group's most public stunt. The suspect was detained on September 15, before ShinyHunters claimed the FBIJobs.gov hack on September 22. The group says it took two to three terabytes of data; that claim has not been verified. ShinyHunters has also denied any connection to van der Stap. FBI says ShinyHunters leader arrested as Pokemon-themed hacking group faces probe - Dexerto +2
The FBI is not treating this as the end. Cyber Division Assistant Director Brett Leatherman released a video telling the remaining members to turn themselves in, and Dutch police have not ruled out further arrests. Fox Newsnltimes
What it means for defenders
One arrest does not take down a loose collective. The FBIJobs claim was made while the alleged leader was already in custody, which tells you the rest of the group is still active. The methods it relies on (phone calls to staff, lookalike login pages, access through SaaS vendors) don't depend on any one person.
If you are in healthcare or rely on third-party cloud platforms, the practical steps haven't changed. Make your helpdesk verify callers before resetting credentials or MFA. Tell staff that a call to their personal phone about a work login is a red flag. Review which third-party apps are connected to your SaaS tenants. And watch for newly registered domains that imitate yours, since these pages usually go live days before the calls start.
We will update this post as court proceedings in Rotterdam and any US charges become public.