Extortion brands usually die in silence. ShinyHunters is being called out in public — by Dutch police and by the FBI’s cyber leadership on camera. On September 29, 2026, the Dutch National Police (politie.nl) confirmed that a 24-year-old man from Amsterdam was arrested on Tuesday, September 15, suspected of a role inside the ShinyHunters criminal organization. The same day, FBI Cyber Division Assistant Director Brett Leatherman described him as one of the group’s “alleged leaders” and put a scale number on the conspiracy: more than 140 organizations breached and at least $70 million in extortion payments since 2025. Rotterdam court: at least 90 days pre-trial detention. Presumed innocent. Police did not name him.
Primary — politie.nl (Sep 29, Driebergen). Team High Tech Crime, under the National Public Prosecutor’s Office (Landelijk Parket), arrested the Amsterdam suspect on suspicion of participating in a criminal organization. Devices seized; further arrests “not ruled out.” Stan Duijf (police cybercrime lead) said ShinyHunters is responsible for a large number of national and international victims. Police explicitly state the suspect was not arrested in the Odido telecom case — that investigation continues separately. The police release does not name the detainee.
Separate murder-solicitation track, as stated in the release. After the arrest, investigators say a large amount of information on his laptop concerned two murders that were to be committed abroad, with indications he gave the order. Dutch police treat that as a separate suspicion of attempted solicitation of murder — explicitly not part of the ShinyHunters case line. He is held under full restrictions while both tracks continue. This follows the police wording; victim details and overseas case files are not in the release.
FBI framing — Leatherman video (Sep 29), as quoted by CyberScoop and BleepingComputer. “Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments.” Method as stated: often target third-party vendors in cloud-based platforms, steal sensitive data, extort with threats to publish. Leatherman then addressed remaining members directly: arrests change who talks; seized infrastructure shows who is left; contact the Bureau first “while the choice is still yours.” FBI Director Kash Patel posted on X that teams are following leads from the arrest (CyberScoop / BBC). Underwrite 140+ / $70M as FBI-stated, not a CyberMerge tally.
Identity — media attribution, carefully. Independent reporting (Krebs; CyberScoop; others) identifies the detainee as Pepijn van der Stap. Dutch police have not confirmed that name in the Sep 29 release. CyberMerge prints it as media identification only. A ShinyHunters representative has denied association in secondary coverage — treat denials as attributed claims, not fact. The suspect is presumed innocent.
Timing vs the FBI intrusion claim. CyberScoop notes the Sep 15 arrest preceded the group’s claimed FBI systems intrusion publicity (samples circulated mid/late September per BBC / BleepingComputer). BBC reports Dutch police arrested the suspect before the alleged FBI attack; ShinyHunters claimed theft of agent/applicant PII and asked the Bureau to retract a May advisory rather than pay (group claim via BBC). The Bureau has not printed a causal link between the arrest and the claimed FBI breach. Separately live on CyberMerge: prior ShinyHunters victim reporting (cloud/SaaS, healthcare, education). Victim census beyond named public cases and the FBI’s 140+ figure: Undisclosed.
POV — extortion economics meet vendor/cloud supply-chain targeting. The underwrite is not “another ransomware gang.” It is a data-theft-and-leak brand that FBI leadership says monetized ≥$70M by hitting third-party and cloud paths into >140 orgs. Boards should ask: Where does identity federation and SaaS OAuth create the cheapest lateral path into crown-jewel data — and are vendor questionnaires still priced like 2022 phishing risk? Enforcement signal: public surrender call + 90-day Dutch remand + dual investigation tracks. Watch: further arrests, charging documents, whether remaining operators keep cloud/SSO campaigns running, and whether the FBI’s own incident narrative intersects the Dutch case in filings. Victim lists: Undisclosed. Ransom totals beyond the FBI’s $70M floor: Undisclosed.
Underwrite sheet — sourced only: politie.nl Sep 29, 2026 — 24yo Amsterdam man arrested Sep 15; suspected ShinyHunters role / criminal organization; devices seized; further arrests not ruled out; separate suspicion attempted solicitation of two murders abroad; 90-day Rotterdam remand; not the Odido arrest; Duijf quote; unnamed. CyberScoop Sep 29 — Leatherman: alleged leader; >140 orgs; ≥$70M since 2025; third-party/cloud targeting; surrender call; Patel X post; media ID Pepijn van der Stap (Krebs); arrest preceded claimed FBI intrusion publicity. BBC — same arrest window; police murder-solicitation language; group claimed FBI staff PII / advisory dispute. BleepingComputer — Leatherman video quotes; $70M / 140+; Dutch confirmation. Media name = secondary ID. Presumed innocent. Victim list: Undisclosed.
