Dutch police have arrested a 24-year-old man named Pepijn Van der Stap, who is accused of being involved with the cybercrime group ShinyHunters and orchestrating two murders abroad. The arrest was announced by Brett Leatherman, an FBI official, who described Van der Stap as one of the presumed leaders of the group. However, a spokesperson for ShinyHunters contested this claim. Van der Stap had previously been convicted in November 2023 in another case.
According to Leatherman, the FBI has been monitoring ShinyHunters closely, stating, "The more you stay involved, the more we learn about you. You know how to find us, and we know how to find you. I suggest you contact us first while you still have the opportunity." The FBI recently succeeded in catching members of another cybercrime group called Cl0p, but ShinyHunters has also targeted the FBI itself with a computer attack. This attack was motivated by a federal communiqué that equated them to "The Com," a term described by the group as defamatory.
A spokesperson for ShinyHunters clarified that the attack was not an attempt at extortion and that there was no intention to release the stolen data. Instead, the group stated that the attack was aimed at "protecting our business" and "actively fighting against misinformation."
On October 1st, the French cybersecurity company Sekoia, in collaboration with the British company Beazley Security, released a 40-page report detailing the operations of ShinyHunters. The report noted that the group, which has French roots, has demonstrated resilience by relying on an advanced division of labor. Despite arrests, charges, or convictions, the group has remained active, with new operators using new platforms to continue their activities.
The report highlighted that entire sections of the group's infrastructure have been dismantled by the FBI, the US Department of Justice, and Europol. However, the name ShinyHunters has resurfaced within a few weeks, associated with new operators. While the group's resilience is notable, there have been changes in their operational methods. Traditional phishing and exploitation of massive leaks of identifiers have been replaced by the use of infostealers against poorly secured infrastructures lacking multi-factor authentication.
The group's operations have become increasingly lucrative, with the FBI estimating that ShinyHunters has collected at least $70 million in ransoms since last year after hacking more than 140 organizations. The group is now preparing for a third phase of operations, potentially involving "advanced supply chain compromises" or the theft of authentication tokens.
Dutch Police Arrest Suspect in ShinyHunters Cybercrime Group Amid FBI Investigations
AI-rewritten from original reportingHow it works
shinyhunterscybercrimefbiransomwarecyberattacklaw-enforcement



