Open Menu Close Menu
User
Scroll arrow
World

Is the FBI Bluffing ShinyHunters?

A Suspect Was in Custody When Hackers Targeted Cl0p and the FBI

Author
By TheZeal
Published: 1st Oct 2026, 03:09 AM
Illustration of a masked hacker styled as Peter Pan, flanked by two hooded figures in Umbreon inspired masks, reflecting the anonymity and uncertainty surrounding ShinyHunters.
Illustration of a masked hacker styled as Peter Pan, flanked by two hooded figures in Umbreon inspired masks, reflecting the anonymity and uncertainty surrounding ShinyHunters.

The FBI has delivered a blunt message to ShinyHunters following the arrest of a man it describes as one of the hacking group’s alleged leaders: “We know how to find you.”

There is, however, an awkward detail in the timeline.

Dutch police arrested a 24-year-old Amsterdam man on September 15 on suspicion of playing a role within ShinyHunters and participating in a criminal organisation.

Within days, activity under the ShinyHunters name escalated. The group compromised and defaced infrastructure belonging to rival cyber-extortion operation Cl0p, then on September 21 claimed it had breached FBI-related systems and obtained sensitive information concerning bureau personnel.

Whatever the September 15 arrest achieved, it did not stop activity under the ShinyHunters name.

The FBI has also gone further than Dutch authorities in describing the suspect. FBI Cyber Division Assistant Director Brett Leatherman called him “one of the alleged leaders of ShinyHunters.” Dutch police have publicly said only that the man is suspected of playing a role within the group.

ShinyHunters denies that the arrested man has any association with the group.

“That individual has no association with us. Frankly, we are laughing,” a ShinyHunters representative told BleepingComputer.

The conflicting accounts make the FBI’s new warning particularly interesting. Dutch investigators seized several data-storage devices following the arrest, while the FBI says the operation was carried out with its full support. Neither agency has publicly disclosed what investigators have found on those devices.

Nor has the FBI publicly demonstrated that it has identified whoever is currently operating under the ShinyHunters name.

In a video released after Dutch authorities announced the arrest, Leatherman addressed what he called the remaining members of the group, warning that arrests can change who is willing to talk and that seized infrastructure can expose others.

“You know how to find us, and we know how to find you,” Leatherman said. “I suggest you reach out first while the choice is still yours.”

That may reflect genuine confidence in what investigators have uncovered. It could also serve as pressure.

The FBI does not need to reveal exactly what it knows for such a warning to create uncertainty among people whose security depends heavily on anonymity and trust. Questions about what has been recovered, who might talk and which identities investigators may already know can have value even before another arrest is made.

For now, the public evidence does not reveal how strong the FBI’s hand actually is.

The arrest itself is well established. Dutch police say the suspect was detained on September 15 and that several data-storage devices were seized for examination. A Rotterdam court has ordered that he remain in pre-trial detention for at least another 90 days, while police say further arrests have not been ruled out.

Dutch authorities have not publicly named him, but his employer, Amsterdam cybersecurity company Neo Security, identified him to Reuters as Pepijn van der Stap, the company’s offensive security lead.

Van der Stap was already well known in the cybersecurity community.

In November 2023, an Amsterdam court sentenced him to four years in prison, one year suspended, for offences including computer intrusion, extortion, blackmail and other cybercrime. He later publicly distanced himself from his criminal past and returned to legitimate cybersecurity work.

His former online identity has now attracted particular attention.

Van der Stap previously used the hacker alias “Umbreon”, named after the Pokémon character, and used Umbreon imagery while operating on cybercrime forums.

The character has also appeared prominently in recent ShinyHunters activity, including the group’s defacement of Cl0p and imagery associated with the claimed FBI breach.

But that overlap should not be treated as a digital fingerprint identifying Van der Stap.

The Umbreon character had already appeared in a ShinyHunters defacement of HackForums in 2020, before Van der Stap is known to have begun using his Umbreon account on cybercrime forums in 2021. The imagery therefore predates his known use of the alias.

Cybersecurity journalist Brian Krebs has reported another possibility. Citing sources familiar with the investigation, Krebs said there had been tensions over control of the ShinyHunters name and that the prominent use of Umbreon imagery in the FBI defacement may even have been intended to associate the attack with Van der Stap.

That theory has not been confirmed by Dutch police or the FBI.

What is confirmed is much simpler: Van der Stap was already in custody when the FBI incident occurred.

That does not establish that the FBI has arrested the wrong person. Even if Van der Stap did play a role within ShinyHunters, the activity following his arrest shows that others remained capable of operating under the group’s name.

But it does complicate any suggestion that authorities have already removed whoever is currently directing the operation.

The activity following the arrest was conspicuously bold.

ShinyHunters first turned on rival cyber-extortion group Cl0p, compromising and defacing its dark web infrastructure before attempting to extort the extortionists themselves. TheZeal covered that confrontation in Hackers Hacking Hackers.

Days later came the claimed FBI intrusion.

TheZeal has already examined that incident in detail in ShinyHunters Targets the FBI, including the distinction between evidence that genuine information concerning FBI personnel was compromised and ShinyHunters’ broader claims about penetrating multiple internal bureau systems.

Those broader claims remain unproven.

There is nevertheless growing evidence that the exposed information is serious. Reuters has reviewed material containing sensitive information concerning FBI employees, including medical information and intelligence-related assignments, while an internal FBI memo reportedly instructed personnel to operate on the assumption that information relating to every employee may have been exposed.

That gives the bureau obvious reason to devote substantial resources to identifying whoever was responsible. It does not establish that it has already done so.

ShinyHunters has also softened its own position since its confrontation with the FBI began.

The group said the FBI attack was retaliation for a May advisory that challenged aspects of ShinyHunters’ claims and warned victims not to pay. Following the alleged breach, ShinyHunters gave the bureau one week to correct or remove the advisory.

When BleepingComputer asked whether the alleged FBI data would be released if the bureau refused, the group answered: “No comment.”

That period has now expired.

ShinyHunters subsequently told Reuters that it had never intended to publish the FBI data and that the ultimatum was neither a deadline nor a threat.

“This was all a marketing campaign,” the group said.

Whether that is a clarification of what ShinyHunters always intended or a retreat from its earlier posture cannot be established from outside the group.

Either way, much of the confrontation has become a battle over perception. ShinyHunters wants targets to believe its claims and technical capabilities. The FBI wants ShinyHunters to believe investigators are closing in.

Both have reasons to keep the other side guessing about exactly how much they know.

A separate allegation involving Van der Stap requires considerable caution. It is unrelated to the ShinyHunters investigation, and Dutch police have not said that either planned killing actually took place.

Police say information found on the suspect’s laptop concerned two killings that were allegedly intended to take place abroad. Investigators say there are indications that he may have given instructions for them to occur, and he is therefore suspected of attempting to solicit two murders.

The allegation has not been proven. No finding of guilt has been made, and Dutch police explicitly say that suspicion is separate from their ShinyHunters investigation.

The central issue in the cybercrime case remains the timeline.

A man the FBI calls one of ShinyHunters’ alleged leaders was arrested on September 15. In the days that followed, ShinyHunters compromised Cl0p, claimed to have breached the FBI and continued attracting attention through a wider campaign against Oracle PeopleSoft systems, which TheZeal has covered separately in ShinyHunters Expands Oracle PeopleSoft Attacks.

The arrest may ultimately prove significant. Evidence recovered from seized devices may identify other participants, and additional arrests may follow.

But the public evidence does not yet show that the FBI has identified whoever is currently directing ShinyHunters.

What it does show is an operation that appears increasingly emboldened despite the attention surrounding it.

When BleepingComputer asked ShinyHunters after the FBI incident whether attacking the bureau might bring greater pressure from the United States government to apprehend those responsible, the answer was exactly three words:

“I don’t care.”

Law enforcement has now responded with an arrest, seized devices and a warning from the FBI.

“We know how to find you.”

Perhaps it does.

For now, the bureau has not shown publicly how much of that statement reflects what investigators already know, and how much is intended to make ShinyHunters wonder.

Join the Discussion
What do you think?
No account required. Comment as a guest.
0 COMMENTS:
Home Latest
NZ Videos
Video LibraryLibrary
Menu Menu