Connect with us

NEWS

The ShinyHunters Arrest Came Before the FBI Dump

The ShinyHunters arrest the FBI is advertising landed six days before the FBIJobs dump, and Dutch police have not tied the 24-year-old to that breach.

Published

on

Dutch police arrested a 24-year-old Amsterdam man on September 15, six days before ShinyHunters said it breached the FBI jobs portal.

The FBI still used that arrest on September 29 to warn remaining members on camera. The group says the man has no link to it, and Dutch officers have not charged him with the FBIJobs.gov intrusion.

The Arrest Landed Six Days Before the Dump

ShinyHunters told reporters it hit FBI servers on the night of September 21 and started sending samples the next day. A seizure-style banner went up on the jobs site. Apply.fbijobs.gov and the special-agent applicant portal then showed as unavailable.

The man in Dutch custody had already been off the street for nearly a week. That gap is the part the warning video does not linger on. It is also the part that makes the FBI’s line, that this arrest is the lever against the portal dump, a stretch until someone files that charge.

HOW THE DATES ACTUALLY LINE UP

  1. May 15, 2026: The FBI’s Internet Crime Complaint Center posts a public service announcement on ShinyHunters, alert I-051526-PSA.
  2. September 9, 2026: The same 24-year-old tells an interviewer he is a reformed hacker trying to make amends.
  3. September 15, 2026: Dutch officers arrest him in Amsterdam on suspicion of taking part in ShinyHunters.
  4. September 21, 2026: The group says it compromised FBI systems, including the jobs portal.
  5. September 22, 2026: It contacts journalists with screenshots and a sample file, and defaces the applicant site.
  6. September 23, 2026: The FBI says it is investigating a claimed compromise of fbijobs.gov and alleged impact to employee personal data.
  7. September 28, 2026: The group says it never planned to publish the trove and calls the episode a marketing campaign.
  8. September 29, 2026: A Rotterdam court remands the suspect for at least 90 days, and FBI Cyber Division Assistant Director Brett Leatherman records a warning to whoever is left.

Dutch police later confirmed the membership suspicion and named Ticketmaster, Pornhub, and the Dutch telecom Odido among the group’s alleged jobs. They did not name FBIJobs.gov in that charging frame.

A Reformed Hacker, Then Flash-Bangs at the Office

People familiar with the case, and his employer, identified the suspect as Pepijn van der Stap. Dutch police have not named him in their own release. Neo Security executive Benjamin Korper said van der Stap was the firm’s offensive security lead, hired after prison on a second-chance bet that Korper now says blew up in his face.

Van der Stap was convicted in 2023 over a string of data thefts and extortions. At trial he admitted a double life, using the handle Umbreon on English-language crime forums while working as a software engineer at the Amsterdam startup Hadrian and volunteering with the Dutch Institute for Vulnerability Disclosure. The court gave him four years, with one year suspended. He got out in December 2025.

In 2024 he described the old habit in plain terms. “The hacking was very easy for me, and it wasn’t a compulsion,” he said. “My habit was collecting. Collecting data, organizing data, downloading data, creating folders.”

On September 9 he was still selling that turnaround. Six days later, Dutch special intervention officers hit his family home in Amsterdam with flash-bang grenades. Korper said forensic investigators were at Neo Security’s office the same night. Korper also said an outside firm had, so far, found no sign that van der Stap had turned on the company or its clients.

The National Police arrested a 24-year-old Amsterdam man for taking part in a criminal organization, which it identified as ShinyHunters. After the arrest, officers said a laptop held a large amount of information, including details about two murders that were supposed to be carried out abroad, and that there are indications he ordered those killings. That file, they said, is a separate case. He is being held in isolation, limited to his lawyer. Further arrests have not been ruled out. Stan Duijf, who leads Dutch cybercrime investigations, said the group is responsible for a large number of national and international victims, and that it is good a suspect is in custody.

ShinyHunters, asked about the man, was blunt. “That individual has no association with us,” the group said. “Frankly, we are laughing.”

What ShinyHunters Wanted Taken Down

The jobs-site dump was not pitched as a ransom note. The group addressed FBI Director Kash Patel and Leatherman and said it was “severely offended” by a spring advisory. It wanted the bureau to correct or remove that paper within a week. “This is not a ransom, coercion, or extortion,” the message said. “This PSA is NOT financially motivated.”

The document it pointed at is still on the IC3 site: a May 15 notice about a learning-management-system disruption, which then sketched ShinyHunters as a crew that hits tech, finance, and retail and steals millions of customer records at once. The lines the group marked as false are the ones about how it leans on victims.

THE LINES THEY WANTED ERASED

  • The access boast: The advisory said threat actors often use real or exaggerated claims of access to data to push victims toward payment.
  • The harassment claim: It said the crew commonly sends threatening texts and calls to victims and family, and in some cases uses swatting.
  • The fake kompromat: It said actors may falsely claim to hold embarrassing photos or videos that frequently do not exist.

ShinyHunters answered those three points in all caps. It said its threats are real, that it has never swatted corporate staff or texted their families, that it is not a sextortion crew, and that it is not part of “The Com.” Then it used the FBI’s own jobs portal as the exhibit. Hitting the bureau to prove you do not exaggerate stolen-data boasts is a strange kind of rebuttal, and it is the one the group chose.

Agents’ Home Addresses Were in the Sample

The group said it held very sensitive data on almost all FBI agents and on people who had applied for a job. It claimed 2 to 3 terabytes and listed HR systems, MedLink, background-check tools, and investigative stores among the places it said it reached. The FBI has not confirmed any of that scale, and it has not confirmed those system names.

What did move is a sample of about 5,000 records, plus screenshots. Journalists who reviewed a portion said it appeared genuine. Fields in that slice included names, home addresses, phone numbers, Social Security numbers, family contacts, and, in some rows, job assignments down to units that work China, Russia, and cartels. Some names matched public records for bureau officials. Sample files circulating with reporters also included blood and urine results and psychiatric notes. The BBC put the bureau’s headcount at about 38,000, the pool the group claimed to cover.

An internal memo told staff to work from the premise that data on every employee may be out. That is a protective posture, not a forensic finding. On September 23 the FBI National Press Office said only that it was aware of a cybercriminal group claiming a compromise of the fbijobs.gov portal and alleged impact to employee personal data, and that the point of breach is still undetermined, whether at a third party or inside the FBI’s own network.

WHAT THE GROUP CLAIMED AND WHAT IS CONFIRMED

Claim Status
fbijobs.gov taken over and applicant pages knocked offline FBI is investigating unauthorized activity; the site went unavailable after the banner
Data on almost all agents and applicants, 2 to 3 terabytes Unconfirmed; the bureau has not verified volume
Sample of about 5,000 records is real Journalists matched a portion to public records and said it appeared genuine
The arrested man is a ShinyHunters leader who ran the FBIJobs job FBI calls him an alleged leader; Dutch police cite membership in the group; they have not charged the portal attack; the group denies him
Laptop holds orders for two murders abroad Dutch police say that suspicion is a separate case

For agents and applicants, the practical problem does not wait on a charging document. Home addresses and family numbers in a crime group’s hands are already a targeting list, including for foreign services that would pay for that roster.

Leatherman’s Camera Warning Is Aimed at Whoever Is Left

Leatherman’s September 29 video treats the Dutch case as a door into the rest of the crew. He called the suspect one of the alleged leaders of ShinyHunters, a global group he tied to attacks in the United States, the Netherlands, and elsewhere. Since last year, he said, the man and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments. Those are figures for the group’s wider run, not for FBIJobs.gov, which the group said was not about money.

You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.

Brett Leatherman, assistant director, FBI Cyber Division

He also said other groups believed anonymity or their friends would protect them, but arrests have a way of changing who is willing to talk, and that the longer remaining members stay in, the more the bureau learns. Patel thanked Dutch partners and said FBI teams were already working new leads from the arrest. The official account posted the video the same day.

The clip is a surrender pitch dressed as a victory lap. It lands after a dump the bureau has not fully scoped, built on an arrest that predates that dump, aimed at people the group itself says are still operating. Some viewers even questioned whether the recording was a real camera sit-down. The sharper read is simpler. The bureau is trying to flip whoever shared servers with the man in isolation, and it is doing that in public because it wants the rest of the crew to feel the clock.

A One-Character Trick Kept PeopleSoft Open

ShinyHunters told journalists the FBI jobs stack sat on Oracle PeopleSoft, a common HR and payroll platform, and that it moved from there into cloud-hosted government systems. The FBI has not adopted that account. Mandiant, which tracks the crew as UNC6240, did document a parallel campaign against PeopleSoft that is hard to ignore next to the group’s screenshots.

The bug is CVE-2026-35273, in PeopleSoft’s Environment Management Hub, the PSEMHUB endpoint. Mandiant says the crew exploited it as a zero-day from May 27, until Oracle shipped an emergency update on June 10. Organizations that blocked the path at a web application firewall, instead of patching, then got beaten by URL-encoding a single character. Attackers requested /%50SEMHUB/ in place of /PSEMHUB/. Some firewalls match the literal string before decoding; PeopleSoft decodes it and still routes to the vulnerable servlet.

Mandiant’s September 25 update said the new wave put web shells on dozens of systems in higher education, technology, IT services, healthcare, agriculture, transportation, and government. That last sector is why the FBIJobs claim is technically plausible even while the bureau still will not say where the hole was. A jobs portal on a vendor HR stack is exactly the kind of third-party edge the September 23 statement left open.

The defacement itself carried a signature from van der Stap’s old life. The banner’s ASCII art was Umbreon, the same Pokémon mark he used when he sold stolen databases years ago. “This site has been seized by ShinyHunters. rooting your systems since ’19;)” sat over that drawing. If the man in the Amsterdam cell was already locked up, someone still on the outside chose his old mascot anyway.

The Group Calls It Marketing and Keeps the Files

On September 28, with the one-week window closing and no public retraction of the May advisory, ShinyHunters changed tone. It said that from the beginning it had decided it would never publish the FBI data, that it had never intended to, and that the confrontation was “a marketing campaign to protect our business and actively combat disinformation.” It argued it had never used the word “deadline,” and that the public had driven the story out of context.

That walk-back does not put the records back on bureau servers. The group did not say it had deleted the trove. Samples already sit with newsrooms. Agents have been told to assume their personal files are gone. The May advisory remains posted. The man Dutch police grabbed is in isolation on a membership case and a separate murder-solicitation file, not on a published FBIJobs indictment.

The louder problem for the bureau is that the crew is treating the arrest as a joke, not a collapse. “Frankly, we are laughing” is a wretched slogan, and it is also a tell: whoever still holds the keys does not think one 24-year-old in Rotterdam ends the enterprise. Leatherman’s invitation to come in while the choice is still theirs is on the table. So are the files, and a 90-day clock that started on September 29.

Harry is the editor and lead writer of STUDIO ONE NETWORKS, an independent title he owns and runs himself. Ten years in journalism, reporting first and editing later, taught him that entertainment and business are one beat seen from two sides: a box office figure is a company number, a streaming deal is a contract, a casting rumour is not a story until someone puts their name to it. He works from the record, whether that is a distributor's statement, a licensing agreement, an interview transcript or a set of published ratings, and checks every number against it before publication. The same rule holds for the rest of the site, which covers news, technology, science, sports, lifestyle, travel, auto and gaming for an audience spread across the world. When he gets something wrong, the article is corrected and the change is noted and dated, under a corrections policy anyone can read. Reader mail is answered by him at support@studioonenetworks.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending