The FBI has issued a direct warning to remaining members of ShinyHunters, urging them to come forward after Dutch authorities arrested a man the bureau describes as one of the alleged leaders of the prolific hacking and extortion group.
FBI Cyber Division Assistant Director Brett Leatherman announced the development Tuesday, saying ShinyHunters and its alleged co-conspirators have breached more than 140 organizations since 2025 and received at least $70 million in extortion payments.
The warning follows the Sept. 15 arrest of 24-year-old Amsterdam cybersecurity professional Pepijn van der Stap, whose employer identified him as the suspect in the Dutch investigation. Dutch police say Van der Stap is suspected of playing a role within ShinyHunters and participating in a criminal organization.
“You’ve heard about the arrest of your colleague,” Leatherman said in a video released by the FBI. “We’re confident you’ve seen or heard things in recent days that the public has not.”
FBI puts remaining ShinyHunters members on notice
The FBI’s message goes beyond announcing the arrest, directly addressing other people investigators believe remain involved with ShinyHunters.
Leatherman said other cybercrime groups have previously believed anonymity or associates would protect them, only for arrests and seized infrastructure to provide investigators with additional evidence about remaining participants.
“The longer you stay in this, the more we learn about you,” Leatherman said. “You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
The bureau says ShinyHunters and alleged co-conspirators have compromised more than 140 organizations since last year and collected at least $70 million through extortion.
ShinyHunters has become one of the most active data theft and extortion operations tracked by BreachNews, with attacks frequently involving compromised corporate accounts, identity infrastructure, third-party services and cloud-based platforms.
Dutch court keeps Van der Stap detained
The FBI warning came the same day Dutch authorities released additional details about Van der Stap’s case.
As BreachNews reported earlier Tuesday, Dutch police arrested Van der Stap in Amsterdam on Sept. 15 as part of an investigation into ShinyHunters.
The Rotterdam District Court has now ordered that Van der Stap remain in pre-trial detention for another 90 days while the investigation continues.
Dutch police said investigators seized several data storage devices during the operation and are continuing to examine them. Authorities said additional arrests have not been ruled out.
Police also clarified that Van der Stap was not arrested as part of the investigation into the ShinyHunters breach involving Dutch telecommunications provider Odido.
Dutch authorities have not publicly detailed which specific ShinyHunters intrusions Van der Stap is suspected of participating in. ShinyHunters has reportedly denied that he is associated with the group.
Police uncover alleged plans for two murders
Dutch police also disclosed a separate allegation after examining information found on Van der Stap’s seized laptop.
Investigators said a large amount of information was discovered on the device, including details concerning two murders that were allegedly intended to take place outside the Netherlands.
Police said there are indications that Van der Stap gave the orders and that he is now suspected of attempted solicitation of two murders.
The allegations have not been proven in court. Dutch authorities emphasized that the suspected murder plots are separate from the ShinyHunters investigation.
Police have not publicly identified the alleged targets or disclosed where the killings were purportedly intended to occur.
Warning follows major FBI data theft
The FBI’s public warning comes days after ShinyHunters claimed responsibility for compromising the bureau’s own recruitment infrastructure.
On Sept. 24, BreachNews reported that the FBI was investigating unauthorized activity affecting FBIjobs.gov after ShinyHunters claimed it breached the recruitment system and obtained sensitive information.
ShinyHunters claimed it stole between 2 TB and 3 TB of data and gained access to multiple services. The group initially claimed that a previously unknown Oracle PeopleSoft vulnerability provided its initial access.
The FBI subsequently confirmed that employee information was among the data stolen during the intrusion, according to reporting reviewed by BreachNews.
As BreachNews reported in a follow-up, ShinyHunters provided journalists with a dataset containing approximately 5,000 purported FBI personnel records as evidence supporting its breach claims.
Some of the exposed personnel were reportedly associated with sensitive FBI operations and investigations, significantly increasing the potential impact of the stolen information.
The FBI has not confirmed ShinyHunters’ claim that it obtained the full 2 TB to 3 TB of data or all of the additional internal access described by the group.
ShinyHunters says FBI attack was not extortion
Despite ShinyHunters’ long history of financially motivated data theft and extortion, the group has claimed its FBI operation was not intended to generate a ransom payment.
ShinyHunters has said the intrusion was intended to challenge the FBI’s public characterization of the group’s tactics and credibility rather than extort the U.S. government.
The group has claimed it does not intend to sell or publicly release the FBI data. Those assurances cannot be independently verified.
ShinyHunters initially characterized its access method as a new Oracle PeopleSoft zero-day. Subsequent research has focused on the group’s ability to bypass web application firewall protections designed to mitigate CVE-2026-35273 through specially encoded requests.
The FBI has not publicly confirmed which vulnerability or attack technique was used to compromise FBIjobs.gov.
Arrest did not stop ShinyHunters activity
The timeline surrounding Van der Stap’s arrest is significant because ShinyHunters continued conducting high-profile operations after he was taken into custody.
Dutch authorities arrested Van der Stap on Sept. 15, before the FBIjobs.gov intrusion became public and before several subsequent operations attributed to ShinyHunters.
The continued activity means the arrest did not dismantle the broader ShinyHunters operation. It also leaves unanswered questions about Van der Stap’s alleged role within the group and the identities of other participants investigators may be pursuing.
The FBI’s decision to publicly address remaining ShinyHunters members suggests U.S. authorities are attempting to capitalize on the Dutch arrest and information gathered during the investigation.
Dutch police have explicitly said further arrests remain possible, while the FBI is now telling other alleged members that investigators are continuing to gather information about them.
Van der Stap remains in pre-trial detention as Dutch authorities continue investigating his alleged involvement with ShinyHunters, participation in a criminal organization and the separate allegations involving the attempted solicitation of two murders.
The broader international investigation into ShinyHunters remains ongoing.












