FBI and overseas partners arrest alleged ShinyHunters figures after bureau systems targeted
The FBI says it has locked up multiple suspects tied to a September cyber operation that hit the bureau itself, an attack authorities link to the hacking crew known as ShinyHunters.
Breitbart News reported the bureau’s confirmation that agents and foreign partners already moved on several subjects while the probe continues.
The case lands at the center of federal cyber enforcement. A group that claimed it seized FBI applicant systems now faces real arrests, seized leads, and a public warning aimed at anyone still online. The legal stakes are plain: alleged attacks on federal systems, cross-border custody actions, and an open hunt for remaining members.
Overseas arrests put names on the board
Dutch National Police arrested a 24-year-old man the FBI described as “one of the alleged leaders of ShinyHunters.” That custody action came roughly two weeks before another key detention.
Fox News reported the Amsterdam arrest took place on Sept. 15 in a joint operation with the FBI, and framed ShinyHunters as a global cybercrime group tied to wide extortion activity.
Security journalist Brian Krebs and other reports identified the Dutch suspect as Pepijn van der Stap. Dutch police have not officially named him. Krebs and those reports place him as a software engineer at Amsterdam-based cybersecurity startup Hadrian who also volunteered as a security researcher with the Dutch Institute for Vulnerability Disclosure.
Van der Stap was convicted in 2023 for hacking and extorting numerous organizations. He served three years and was on supervised release when the new arrest came.
Federal fugitive hunts and hard arrests remain a core CLN beat, including coverage of the FBI capture of an alleged Medicare fraud ringleader after years on the run.
On September 29, Reuters reported the detention in Jordan of Saif al-Din Khader, who used the alias “Rey.” Reports say he is cooperating with the FBI to help identify other members. The FBI declined to comment on that specific arrest.
Khader confirmed his real identity to Krebs last year. Krebs described him as the “technical operator and public face” of a related group. Security researcher Kevin Beaumont reacted after the news broke.
"Rey got picked up finally."
Beaumont also called him “one of the kids who got into JLR,” tying the suspect to the Jaguar Land Rover breach.
What ShinyHunters claimed against the FBI
In prior coverage of the FBI-targeted incident, ShinyHunters took public credit for defacing apply.fbijobs.gov. The defacement message declared the site “seized by ShinyHunters” and claimed a sweeping data haul.
That message asserted compromise of personally identifiable information and protected health information on incumbent and former FBI employees, plus applicant information, and added that the group held “a lot more than we claim here.”
A ShinyHunters representative told 404 Media, “We hacked the FBI. We hold data on all FBI employees and applicants.” At the time of that earlier reporting, apply.fbijobs.gov and the Special Agent Applicant Portal carried an unavailable status message.
The FBI has not publicly confirmed the full scope of any data compromise. Officials describe an aggressive investigation into the recent cyber incident “allegedly involving ShinyHunters.”
Readers following federal charging actions will recognize the same enforcement pattern seen when federal prosecutors charged a Bellingham man over alleged aid in a cross-border attack plot.
An FBI spokesperson put the bureau’s posture in blunt terms.
"The bureau continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects and we will spare no resource in bringing each of the responsible individuals to justice."
JLR hit shows the wider extortion pattern
The same crew name keeps surfacing in costly private-sector breaches. In late August 2025, Jaguar Land Rover systems were hit in an attack attributed to ShinyHunters and related groups.
Manufacturing halted. Dealer systems went down. Supplier orders were canceled or delayed. Personal payroll data of thousands of employees was stolen. Coverage described the episode as one of the most costly cyberattacks in UK history.
Fox News reporting on the Dutch arrest also linked the group to breaches of more than 140 organizations and at least $70 million in extortion payments. That scale helps explain why FBI Cyber Division leadership is pressing remaining members in public.
National-security arrest stories travel the same lane for CLN readers, including the FBI arrest of an Irvine realtor at LAX on a charge of acting as an unregistered Chinese agent.
FBI Cyber chief warns whoever is left
Last week, Brett Leatherman, assistant director of the FBI’s Cyber Division, released a video message aimed at “remaining members” of ShinyHunters. He framed arrests and seized systems as tools that flip incentives fast.
"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left."
Leatherman kept the pressure on anyone still in the network.
"The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."
The FBI declined further questions about that video, including whether any infrastructure had been seized or whether group members had made contact. Fox News noted FBI teams are still working leads and have not ruled out more arrests as seized electronic devices are examined.
That same federal custody focus shows up in other CLN reporting, such as the case of an Energy Department employee arrested on a charge of aiding Iran-backed Houthis.
What investigators still have to pin down
Authorities have not publicly detailed formal charges, statutes, or case captions tied to the September FBI-targeted operation. Investigators have not said how many total suspects are in custody beyond the multiple subjects already referenced, and they have not released a full public roster of identities.
No public results have been released on the technical method used against FBI systems. Investigators will need to determine the full reach of any applicant or employee data exposure, the value of devices already seized, and whether remaining members attempt contact under Leatherman’s warning.
Khader’s detention basis, charging status, and any extradition path have not been laid out in public detail. Dutch officials have not issued an official public naming of the 24-year-old arrestee even as Krebs and other reports identify him as van der Stap.
Cross-border suspect pickups remain a recurring federal theme, including when ICE took custody of a suspect allegedly tied to a political assassination case abroad.
Law-and-order bottom line
For conservatives watching federal capacity, the sequence matters. A crew that publicly bragged about hitting FBI hiring systems now faces partner arrests in the Netherlands and Jordan, a cooperating detainee per reports, and a Cyber Division chief telling holdouts the window to come in is closing.
Institutional competence is the test. Brag posts do not equal proof in court, and alleged leaders are not convicted on these new claims until a judge or jury says so. But overseas arrests, partner coordination, and an open invitation to flip are how serious cyber cases move from message-board swagger to custody paperwork.
When hackers target the FBI and private payrolls alike, the country needs prosecutors who finish the job, not press releases that fade after one news cycle.
