ShinyHunters Suspect Arrested — Police Say His Laptop Also Points To Two Alleged Murder Plots

From Cybercrime To Alleged Murder Plots: What Police Say They Found In The ShinyHunters Case

Who Is Pepijn van der Stap? The Hacker Suspect Now Linked To Two Alleged Murder Plots

The ShinyHunters Arrest Takes A Darker Turn

Dutch police say evidence found on the 24-year-old suspect’s laptop led to a separate investigation into alleged attempts to solicit two murders.

A Dutch cybercrime investigation has taken a far more serious turn.

Police in the Netherlands say a 24-year-old man arrested on suspicion of playing a role in the hacking group ShinyHunters is also suspected of attempting to solicit two murders. Investigators say that suspicion arose from information found on the man’s laptop.

The alleged murder plots are not part of the ShinyHunters case itself.

The suspect was arrested on 15 September. On 29 September, a court in Rotterdam ordered that he remain in custody for another 90 days while the investigation continues.

Dutch authorities have not publicly named the man. His former employer, Amsterdam cybersecurity company Neo Security, has identified him as Pepijn van der Stap.

The arrest is significant on its own because ShinyHunters has become one of the most visible names in modern cybercrime. The separate allegation involving two proposed killings pushes the case into very different territory.

What Police Say Happened

The Dutch investigation centres on whether the arrested man played a role in ShinyHunters, a loose cybercriminal operation associated with major data thefts, extortion campaigns and attacks against companies and institutions in several countries.

Police arrested the 24-year-old Amsterdam resident on 15 September.

Investigators seized data-storage devices and began examining their contents. Police have said further arrests are possible.

During that process, investigators say they found information on the suspect’s laptop that led them to suspect he had attempted to solicit two murders.

That wording matters.

The allegation is not that police have established that he personally killed anyone. Nor have authorities publicly said that either alleged killing was carried out.

The allegation is that he attempted to arrange or encourage two murders.

Earlier information circulating around the case described the alleged targets as being abroad. It was initially unclear whether the killings had taken place. The clearest public statement now is that Dutch police are investigating attempted solicitation of two murders and that the suspected conduct is separate from the ShinyHunters investigation.

No public account has yet established who the intended targets were, why they may have been targeted, who was allegedly approached to carry out the killings, or how advanced the alleged plans became.

Those gaps are substantial.

For now, the most important distinction is between what investigators suspect and what has been proved. The man remains a suspect. There has been no conviction in relation to either the ShinyHunters investigation or the alleged murder solicitation.

Who Is The Suspect?

Dutch authorities have referred publicly only to a 24-year-old man from Amsterdam.

Neo Security, where the suspect worked in offensive cybersecurity, has identified him as Pepijn van der Stap.

Van der Stap was already known within the cybersecurity world before this arrest.

He had previously admitted operating under the online alias Umbreon and was convicted in 2023 over data theft and extortion offences. He received a four-year prison sentence, with part of that term suspended.

After leaving prison, he presented himself publicly as someone who had moved away from criminal hacking and towards legitimate security work.

That apparent transformation is one reason the arrest has attracted so much attention.

Only days before he disappeared from public view, Van der Stap had spoken about trying to rebuild his life after his previous convictions. He was working in cybersecurity, a field where former hackers sometimes use the same technical skills legally by testing systems for weaknesses before criminals can exploit them.

His employer has said investigators visited its offices on the evening of the arrest.

The company has not been accused of wrongdoing.

What Is ShinyHunters?

ShinyHunters is a name associated with a long series of data thefts and extortion campaigns.

Unlike a traditional gang with a clear headquarters, membership list and public leadership structure, modern cybercriminal groups can be difficult to define. People may share infrastructure, aliases, access, stolen information or branding without operating like a conventional organisation.

That makes attribution difficult.

It also explains why an arrest connected with a cybercrime investigation does not automatically prove that the person belongs to every operation carried out under the same name.

ShinyHunters itself has denied that Van der Stap is associated with the group.

Police, however, say the man is suspected of playing a role in ShinyHunters.

Those are opposing claims, and the investigation will have to establish what evidence exists behind the alleged connection.

The group has previously been linked to large-scale breaches involving corporate and customer information. More recently, it claimed responsibility for an extraordinary intrusion involving systems connected to the FBI.

Taylor Tailored has previously examined ShinyHunters’ claim that it breached the FBI and stole sensitive employee and applicant data.

That incident increased pressure on law enforcement agencies to identify people behind the group.

The FBI Connection

ShinyHunters recently claimed that it compromised the FBI’s jobs portal and obtained highly sensitive information connected with employees and applicants.

The group said it had acquired large volumes of data.

Some material linked to the claimed breach reportedly included information about thousands of personnel, including details connected with intelligence work.

The full scale and precise technical route into the data have not been publicly established.

The FBI has, however, treated the incident seriously.

Following the Dutch arrest, FBI Director Kash Patel described the suspect as one of the alleged leaders of ShinyHunters and said American investigators were working with Dutch authorities.

That description goes further than the more cautious Dutch wording that the man is suspected of playing a role in the group.

It does not establish guilt.

It does show how important the investigation has become to American law enforcement.

The case also sits inside a much wider problem. Cybercriminal groups increasingly operate across national borders, stealing data in one country, communicating through infrastructure in another and targeting victims scattered around the world.

That forces investigators to rely on international cooperation.

Taylor Tailored’s broader guide to how cyber attacks are used for extortion, fraud and strategic pressure explains why these investigations can quickly become international even when the suspect is physically located in one country.

Why The Murder Allegations Are Separate

The most important new detail is that police have explicitly separated the alleged murder solicitation from the ShinyHunters investigation.

That prevents two different allegations from being blurred together.

The cybercrime inquiry concerns the suspect’s alleged role in a hacking group.

The second inquiry concerns information discovered on his laptop that police say supports suspicion of attempted solicitation of two murders.

Authorities have not said the alleged murder plots were connected with cybercrime victims, ShinyHunters members, rival hackers or any specific criminal dispute.

It would therefore be misleading to assume that the alleged plots formed part of ShinyHunters’ activities.

The connection currently known to the public is the suspect, not necessarily the motive.

That distinction may become one of the most important parts of the case as more evidence emerges.

A 90-Day Detention Does Not Mean A Conviction

On 29 September, a Rotterdam court ordered the suspect to remain in custody for another 90 days.

That gives investigators more time to examine seized devices, communications and other evidence while the suspect remains detained.

It is not a finding of guilt.

Pre-trial detention is part of the investigative process. The eventual case could change substantially depending on what investigators recover, what can be authenticated and whether prosecutors decide the available evidence is sufficient to support formal charges.

Digital investigations can be especially complex.

A laptop can contain messages, accounts, encrypted material, remote-access tools, files copied from other systems and communications involving multiple people. Investigators have to establish who created or controlled particular material, when it was generated and whether it reflects a real plan rather than a conversation taken out of context.

The same problem appears repeatedly in cybercrime cases.

Possessing information is not always the same as stealing it. Using an online alias is not always enough to establish who controlled it at a particular moment. A message can be incriminating, but only if investigators can establish its authenticity and meaning.

That is why the seized devices may become central to both sides of this investigation.

The Arrest Does Not End ShinyHunters

Even if prosecutors eventually prove that the suspect played a significant role in ShinyHunters, one arrest is unlikely by itself to settle the question of who controls the group.

Cybercriminal brands can survive arrests.

People replace one another. Infrastructure moves. Domains change. New aliases appear. Stolen credentials remain usable. Data that has already escaped can continue circulating long after the person who originally obtained it is arrested.

ShinyHunters has already publicly denied that Van der Stap is one of its members.

The practical test will be what happens next.

Investigators will be looking for evidence connecting the suspect to specific attacks, communications, infrastructure or financial activity. They may also try to identify other people through the material seized during the raid.

Police have already said more arrests are possible.

What Happens Next

The immediate next phase will take place largely away from public view.

Investigators can now continue examining the seized devices while the suspect remains in custody.

Three questions matter most.

First, what evidence connects him to ShinyHunters?

Second, what exactly was discovered on the laptop that led police to suspect attempted solicitation of two murders?

Third, were those alleged murder plans ever put into action?

None of those questions has yet been answered publicly in full.

The arrest has nevertheless changed the shape of the story.

What began as a major cybercrime investigation now includes a separate allegation involving attempted solicitation of two killings. The two strands may ultimately remain legally distinct, but they are now attached to the same suspect and the same collection of seized digital evidence.

For investigators, the laptop may therefore be more important than the dramatic raid that brought the case into public view.

What it contains, who created those records and what prosecutors can prove from them will determine whether this becomes one of the most consequential cybercrime prosecutions in Europe — or a much broader criminal case altogether.

Sources

Next Reads

Next
Next

UN Scrambles To Stop Yemen Exploding As Houthi Advance Threatens Crucial Global Shipping Route