Skip to content

Security2 publishers2 min readPublished

ShinyHunters claimed an FBI jobs-site breach days after Dutch police detained a suspected helper

ShinyHunters claimed a breach of the FBI's jobs site days after Dutch police detained Pepijn van der Stap, 23, on or around September 16. The crew kept working through the arrest, so defenders should not treat the detention as a drop in risk.

The Watch · Security desk

Photograph accompanying ShinyHunters claimed an FBI jobs-site breach days after Dutch police detained a suspected helper
Photo: abcnews.com

What happened

  • KrebsOnSecurity reports that in the same days the remaining ShinyHunters members also extorted Cl0p, the Russian ransomware group.
  • Van der Stap was convicted in 2023 over data thefts and extortions that prosecutors said earned between 1.5 million and 2.7 million euros.
  • Dutch police are asking the public to identify a ShinyHunters member's voice from a February 2026 call used to get into Odido, the country's largest mobile carrier.
  • According to 404 Media, the data taken from apply.fbijobs.gov includes Social Security numbers.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • cost FBI job applicants carry the lasting cost of the breach, because a stolen Social Security number cannot be reset the way a password can.
  • exposure Dutch organisations are the stated target of the group's next large theft. Any of them whose staff can be talked onto a spoofed login page is open to the method used on Odido.
  • precedent By openly paying for a member's defense, the group tells its native-language callers, the people Odido-style intrusions depend on, that an arrest will not end the group's support.

The only ShinyHunters intrusion in this record whose method is described began with a phone call. A Dutch-speaking member got an Odido employee to log in at a spoofed website. The group then used that access to take data on more than 6.2 million Dutch people [12]. ShinyHunters confirmed that the voice on the recording belongs to a member [13]. KrebsOnSecurity reports it is still unclear whether police have matched the caller to a real identity [16].

The reporting treats that caller and Pepijn van der Stap as separate people. Three sources told KrebsOnSecurity that van der Stap is the man detained [3], on suspicion of aiding the group's thefts and extortions [1]. Two said he was arrested on or around September 16 and has been held for questioning since [9]. One said a colleague watched Dutch authorities carry items out of his home [10].

Van der Stap had spoken to KrebsOnSecurity a week before that date [1]. On September 9 he described himself as a reformed hacker trying to make amends [7]. He said he was still dealing with civil lawsuits and restitution to earlier victims, then stopped answering messages [8]. He works as offensive security lead at Neo Security, which did not respond to requests for comment [7]. In his earlier offending he used the handle Umbreon and posted victims' data on RaidForums and Breached [5]. At the same time he held a job as a software engineer at the startup Hadrian [21]. He was arrested about nine months after leaving prison [2].

The group answered the Dutch investigation in a statement shared with NL Times. "Everything has been arranged, including a criminal defense lawyer," it said of the member on the recording [15]. "We do not look down on our staff and members; we take excellent care of them," the statement said [14]. It called the Dutch police "a big joke" [18]. It also said they would need luck "if they want to catch him before we carry out another large-scale data theft in the Netherlands" [17].

KrebsOnSecurity calls the FBI claim and the Cl0p extortion an escalation by the remaining members, and covers the Cl0p episode in a single sentence [2]. With Odido included, the documented activity runs from February 2026 to the days after September 16 [11][19]. The dates show the crew kept operating through the arrest of a suspected helper. Nothing in the reporting shows that the arrest provoked the FBI and Cl0p attacks, or that it removed anything the group needed to carry them out.

What to watch

  • Whether Dutch prosecutors charge van der Stap after questioning, and whether any charge names specific ShinyHunters intrusions.
  • Whether police match the Odido recording to a named person, and whether that person is in custody.
  • Any published detail of the Cl0p extortion, including what was demanded and whether ShinyHunters followed through.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories