Skip to content

Product2 publishers3 min readPublished

ShinyHunters defaced the FBI's jobs site a week after Dutch police held an alleged leader

Dutch police detained an alleged ShinyHunters leader on September 15, seven days before the group defaced the FBI's jobs website. The FBI says it is still chasing the rest of the group, so the vendor services and web portals it has used to get in remain the exposure to manage.

The Product Desk · Product desk

Photograph accompanying ShinyHunters defaced the FBI's jobs site a week after Dutch police held an alleged leader
Photo: dexerto.com

What happened

  • The FBI and Dutch authorities blame ShinyHunters for hacks on more than 140 organizations, including Pornhub, Ticketmaster and AT&T.
  • ShinyHunters says it took 2 to 3 terabytes of data on FBI employees and job applicants, with samples showing names, addresses, phone numbers, assignments and family details.
  • Reuters named the suspect as Pepijn van der Stap of Neo Security, who was convicted in 2023 over data theft and extortion and released from prison in December 2025.
  • Dutch police are also investigating him over two murders planned abroad, based on information found on his laptop, in a case they call separate from ShinyHunters.
  • A Rotterdam court has ordered him held for another 90 days.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • contradiction Krebs's report that the Umbreon image may have been planted cuts against the FBI's 'leader' label, and the people directing the group's current attacks have not been publicly identified.
  • exposure People who only applied for FBI jobs sit in the claimed data next to agents, and the counterintelligence risk from leaked blood, urine and psychiatric records stays open whatever the Dutch court decides.
  • decision For companies deciding what this arrest changes, the group's entry routes are what to plan around, since both routes it has described run through vendor services or public portals.

On September 22 the FBI's jobs website showed a message claiming the site had been "seized." The agency's imagery had been swapped for Umbreon, a black Pokemon with yellow rings [4]. Umbreon was the alias Pepijn van der Stap used when he sold stolen databases on cybercrime forums, and his old avatar showed the same Pokemon [5]. He was already in Dutch custody when the image went up [3]. KrebsOnSecurity reported that the current ShinyHunters operation may have used it to pin the FBI hack on him. Nobody has independently confirmed that theory [6].

The story a team tends to tell itself after an arrest headline is short: the leader is held, so the campaign stops. The people closest to the case describe him in different terms. FBI Director Kash Patel called him "one of the alleged leaders" of the group [10]. A ShinyHunters representative told TechCrunch he "has no association with us" [8]. Neo Security, where he worked, said investigators found no evidence he hacked the company or its clients [9]. Dutch police arrested him for "participating in a criminal organization" [22].

The FBI says it will go after the rest of the group [12]. Brett Leatherman, assistant director of its Cyber Division, addressed them directly. "You know how to find us, and we know how to find you," Leatherman said. "I suggest you reach out first while the choice is still yours." [11]

ShinyHunters is accused of stealing data and threatening to publish it unless the victim pays [2]. Both entry routes it has described start in vendor-run or public-facing systems. It said it reached Rockstar Games data in April through a third-party service connected to Snowflake [16]. Rockstar said only a limited amount of non-material company information was accessed [23]. The group said it took the FBI data through the careers website and job application portal [14]. The FBI is still investigating whether that intrusion began in its own systems or at a third-party provider [15]. The group says the FBI attack was not about money. It wants a May advisory that describes it as a data theft, extortion, harassment and swatting operation withdrawn, and the advisory is still online [20].

For the person deciding on Monday what this arrest changes, I'd sort outside systems on two axes. The first is whether the system holds personal data people typed in themselves, such as job applications or customer records. The second is whether someone other than your own team administers the login or connector that reaches it. A system that meets both conditions looks like the two entries the group has described. One was a vendor service tied to a data warehouse [16]. The other was an application portal where the FBI has not ruled out a third-party provider [15]. Systems in that corner go to the front of the credential and connector review, and systems that meet one condition can wait for the normal cycle. The cost is slow, manual work on vendor access, and the public evidence for doing it before the Dutch case resolves is a defacement dated seven days after the arrest [1].

What to watch

  • Whether the FBI finds that its jobs portal breach began in its own systems or at a third-party provider.
  • Whether ShinyHunters publishes the FBI employee and applicant data after telling TechCrunch it would not.
  • Whether Dutch prosecutors tie Van der Stap to specific intrusions or seek custody beyond the current 90 days.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories