Full Breakdown
ShinyHunters Arrest and Alleged Federal Bureau of Investigation (FBI) Data Breach: A Detailed Overview
By Drooid · · How we work
Core Event
Dutch police arrested a 24-year-old man from Amsterdam on September 15 on suspicion of participating in the cyber-extortion group ShinyHunters. The group later claimed to have stolen “very sensitive data” from the FBI’s jobs portal (FBIJobs.gov).
Background & Context
ShinyHunters, active since 2019, has targeted companies such as Pornhub, Ticketmaster, AT&T, and Dutch telecom Odido. In early 2026 the group announced a breach of the FBI’s hiring website, alleging exfiltration of personal, medical and intelligence-related records of “almost ALL” FBI agents and applicants.
Timeline
- Sept 15 – Dutch High-Tech Crime Unit raids an Amsterdam residence, seizes laptops and storage devices, and arrests the suspect.
- Sept 21 – ShinyHunters claims to have breached FBIJobs.gov, saying it obtained 2–3 TB of data covering nearly all FBI personnel.
- Sept 22 – Justice Department notifies lawmakers that the FBI has designated the incident a cybersecurity incident.
- Sept 24 – FBI acknowledges the claim but does not confirm the extent of the theft.
- Sept 26 – Journalist Ken Dilanian cites an internal FBI memo stating personally identifiable information of FBI employees was exposed.
- Sept 29 – Rotterdam District Court orders the suspect held for a further 90 days; police say the murder-solicitation allegation is separate from the ShinyHunters probe.
Data & Statistics
- ShinyHunters alleges the breach involved 2–3 TB of data covering “almost ALL” current and former FBI employees (? 38,000 records).
- The FBI memo listed Social Security numbers, home addresses, dates of birth and emergency contacts among the compromised fields.
Official Statements & Responses
- Brett Leatherman, assistant director of the FBI Cyber Division, released a video warning remaining ShinyHunters members to contact law enforcement, describing the arrest as a “warning.”
- Benjamin Korper, CEO of Neo Security, identified the arrested individual as Pepijn van der Stap, the firm’s offensive-security lead, and expressed shock.
- ShinyHunters denied any association with the arrested individual, called Dutch police “unskilled and incompetent,” and said the alleged FBI breach was “a marketing campaign.”
Criticism & Opposition
ShinyHunters’ spokesperson refuted the claim that the suspect was a group leader, labeling the police investigation “incompetent” and asserting the individual “has no association with us.” The group argued its FBI-related actions were intended to “combat disinformation” about its tactics.
Conflicting Reports & Gaps
- Identity of the suspect: Bloomberg, TechCrunch and other outlets identify the arrested man as Pepijn van der Stap; ShinyHunters denies any link.
- Connection to the FBI breach: Dutch authorities say the murder-solicitation allegation is unrelated to the ShinyHunters probe, but have not confirmed van der Stap’s involvement in the September 21 breach. The FBI has not publicly confirmed the breach’s scope, only that a cybersecurity incident occurred.
- Extent of data exfiltrated: ShinyHunters claims 2–3 TB; the FBI memo confirms exposure of personal identifiers but does not quantify total volume.
Verbatim Quotes
- “Other groups believed anonymity or their friends would protect them, and they were wrong,” — Brett Leatherman, FBI assistant director
- “Arresting cybercrime suspects is a key intervention in our broad-based fight against this type of crime,” — Stan Duijf, Dutch police cybercrime official
What’s Next
The suspect remains in pre-trial detention pending further court proceedings in Rotterdam. Dutch investigators indicated additional arrests are possible as they examine seized devices. The FBI’s investigation continues, but no public timeline has been announced.
