top of page

No Safe Haven, No Knockout: What the ShinyHunters Arrest Does and Does Not Change

13 hours ago
5 min read
The arrest of an alleged ShinyHunters leader in Amsterdam disrupted the group but did not stop it. Days later, the group claimed a breach of the FBI's own recruitment portal.
The arrest of an alleged ShinyHunters leader in Amsterdam disrupted the group but did not stop it. Days later, the group claimed a breach of the FBI's own recruitment portal.

On September 29, the FBI and the Dutch National Police announced the arrest of a 24-year-old Amsterdam man they describe as one of the alleged leaders of ShinyHunters, a cyber extortion group blamed for breaches at more than 140 organizations. The arrest is a real win for international law enforcement. However, it is a disruption, not a knockout. The group denies the man is a member; it escalated after he was detained, and it claims to have stolen data on thousands of FBI employees a week after his arrest. The lessons for security leaders lie in that sequence, not in the headline.


The Announcement Behind the Headline

FBI Director Kash Patel summarized the news in four words: "No safe haven." His message was clear. Attack Americans from behind a keyboard anywhere in the world, and the FBI will find you.


The facts behind the message are more measured. The Dutch National Police say officers from the High Tech Crime Unit arrested the suspect at his Amsterdam home on September 15 on suspicion of participating in a criminal organization. A court has ordered 90 days of pretrial detention. Investigators also found material on his laptop that they say shows he attempted to arrange two murders abroad, a separate allegation that is not part of the ShinyHunters case.


Brett Leatherman, who leads the FBI's Cyber Division, said the suspect and his co-conspirators have allegedly

"breached more than 140 organizations and taken at least $70 million in extortion payments."

Officials have not named the suspect. Reporting by Brian Krebs, Bloomberg, and Reuters identifies him as Pepijn van der Stap, a convicted hacker who once used the alias "Umbreon." He was sentenced in 2023 to four years in prison, with one year suspended, for a string of data thefts and extortions. At the time of his arrest, he was reportedly working as chief technology officer of a Dutch cybersecurity firm while on supervised release.


ShinyHunters, for its part, told multiple outlets that the man "has no association" with the group. Readers should treat both the FBI's "alleged leader" label and the group's denial as claims under investigation.


Lesson One: Arrests Disrupt, Brands Survive

ShinyHunters is not a fixed team with a fixed roster. It is closer to a brand. Since 2020, different individuals have operated under the name, and French police arrested several suspected members in 2025. The group kept going. It now overlaps with a loose coalition of English-speaking hackers that researchers call Scattered LAPSUS$ Hunters.


That structure explains what happened next. On September 21 and 22, about a week after the Amsterdam arrest, ShinyHunters claimed it had broken into the FBI's own recruitment portal, FBIjobs.gov, and stolen data on current and former employees and applicants. The site was defaced and taken offline. The FBI has confirmed only that it is aware of the claims and is investigating. Reuters and 404 Media partially verified a sample of roughly 5,000 personnel records. The group's larger claims, including two to three terabytes of data and a new Oracle PeopleSoft vulnerability, remain unverified.

The arrest came first. The escalation came after. That order matters.

For practitioners, the point is simple. Removing one operator from a brand-based criminal network changes the roster, not the threat. Plan for continuity of attacks, not for a pause.


Lesson Two: The Reformed Hacker Problem

The most uncomfortable detail in this story is not the arrest. It is where the suspect was working. A man convicted of extorting companies was, by his own public profile, leading offensive security at a legitimate firm and describing himself as reformed.


The security industry has long debated hiring former offenders. Many have made honest transitions, and their skills are real. Nevertheless, this case shows the cost of getting it wrong. An insider with a criminal history, privileged tools, and client access is a high-value asset for any group he chooses to serve. Employers that hire from this pool need continuous monitoring, strict access limits, and a plan for what happens if the past returns.


For government and law enforcement agencies that contract with private security firms, the question is equally direct. Do you know who is on the vendor's team, and who is monitoring them?


Lesson Three: The Phone Call Beat the Firewall

ShinyHunters is also blamed for the September breach at Odido, the largest mobile carrier in the Netherlands, which exposed data on millions of customers. Dutch police say the Amsterdam arrest is not connected to that case. However, the method deserves attention. Police released a recording of a Dutch-speaking caller who talked his way past an Odido help desk employee by using convincing internal jargon and posing as an IT colleague.


No zero-day was needed. A confident voice and the right vocabulary opened the door. This is the same pattern seen in the group's earlier campaigns against Ticketmaster, AT&T, and others. The weakest link is still a person under time pressure who wants to be helpful.


An Analyst's View

Patel's post is a message in a perception war, and it should be read as one. The FBI published an advisory on ShinyHunters in May; the group retaliated by defacing the bureau's own hiring site, and the bureau answered with a high-profile arrest announcement. Each side is competing for the narrative of who is winning.


The honest assessment is that both things are true. Dutch investigators did serious work, seized evidence, and secured pretrial detention on serious charges. At the same time, the group's most damaging public act came after the arrest, and the FBI has not yet told its own employees the full scope of what was taken. Deterrence is real, but it is slower than the adversary.


What Organizations Should Do Now

  1. Harden the help desk. Require callback verification through a known number before resetting credentials or granting access, and train staff that fluent jargon is not proof of identity.

  2. Vet and monitor security hires. Treat anyone with privileged access as a standing risk, whatever their history. Log activity, limit scope, and review regularly.

  3. Prepare for retaliation cycles. Public enforcement actions invite public responses. Agencies and companies that name adversaries should assume they will be targeted next.

  4. Practice breach notification before you need it. The FBI's delayed clarity to its own workforce is a warning. Know what you will tell your people, and when, before an incident forces the question.


The Bottom Line

The arrest in Amsterdam is a legitimate step against one of the most active extortion crews in the world. It is not the end of ShinyHunters, and the group made that point within days. Security leaders should take the win, note the sequence, and invest where this case points: the help desk, the insider, and the incident response plan.


OSRS can help. OGUN Security Research and Strategic Consulting provides threat intelligence assessments, insider risk reviews, social engineering resilience training, and executive advisory services for government, law enforcement, and private-sector leaders. Contact us to schedule a briefing or a readiness assessment for your organization.


Enjoyed this article? Share it with a colleague who needs to see it. Stay informed by subscribing to our email list and following us on Google News, Twitter, and LinkedIn for more exclusive cybersecurity insights and expert analyses.


Intelligence. Protection. Strategy. www.ogunsecurity.com


About the Author

Dr. Sunday Oludare Ogunlana is the Founder and CEO of OGUN Security Research and Strategic Consulting LLC, Professor of Cybersecurity, national security scholar, and television commentator. He advises government, academic, and private-sector organizations on intelligence, cybersecurity, and emerging technology threats.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page