Amsterdam Arrest Rattles FBI Breach Tale

FBI website open in a browser tab
Photo: Jarretera / Shutterstock

Dutch police have arrested a 24-year-old Amsterdam man tied to the hacker group that claims it stole sensitive personnel files on nearly every Federal Bureau of Investigation (FBI) agent in the country.

Story Snapshot

  • Dutch National Police confirmed arresting a 24-year-old Amsterdam man in a ShinyHunters investigation this month.
  • Multiple outlets identified the suspect as Pepijn van der Stap, a previously convicted cybercriminal.
  • The FBI says it is investigating “unauthorized activity” on its jobs website, but has not confirmed the hackers’ claims.
  • ShinyHunters says it stole 2 to 3 terabytes of data on agents and job applicants, though no independent proof has surfaced.
  • The group’s loose, shifting membership makes it hard to prove one arrested man drove this specific breach.

Arrest Confirmed In Amsterdam

Dutch National Police posted on social media that “it is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters.” The statement did not name the suspect. But cybersecurity reporter Brian Krebs and several other outlets identified him as Pepijn van der Stap, describing him as a previously convicted hacker sometimes called a “reformed” cybercriminal.

The Federal Bureau of Investigation (FBI) confirmed separately that it was looking into claims of unauthorized activity on FBIJobs.gov, the site job seekers use to apply for bureau positions. “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” the agency said in a statement quoted by CNN and The Guardian. The jobs portal reportedly went offline during the incident, matching reports of a real operational disruption.

Hackers Claim Massive Data Theft

ShinyHunters told reporters it broke into the FBI’s job portal using a flaw in Oracle’s PeopleSoft software, then moved into other agency systems built on Amazon’s government cloud servers. The group claimed to have stolen between 2 and 3 terabytes of files, including names, home addresses, Social Security numbers, and in some cases family members’ names of current and former agents. The FBI has not confirmed those specific details.

Reporters at Reuters and 404 Media reportedly received sample data that appeared to match real FBI or Justice Department personnel records. But neither outlet confirmed the samples actually came from the FBI’s own systems, leaving a gap between the hackers’ claims and hard proof. FBI records do show the bureau’s recruiting system runs on the same PeopleSoft and cloud infrastructure the hackers described, which lends some plausibility to the claimed attack path.

A Group Built On Its Own Brand

ShinyHunters has a long history of large data thefts and extortion demands, which makes its claims harder to dismiss outright. But researchers who track the group increasingly describe it less as a fixed organization and more as a shared brand name used by shifting clusters of criminal hackers. That structure makes it difficult to prove that one arrested man in Amsterdam was actually behind the FBI breach, rather than just loosely connected to people who use the same name.

The group’s own actions add to the confusion. After boasting publicly about the breach and demanding the FBI retract a warning it had issued about the group’s tactics, ShinyHunters reportedly went quiet. It later posted that it had “achieved its goals” and might not release the stolen data at all. That shift from loud claims to silence is a pattern security researchers say fits the group’s past extortion campaigns.

What Remains Unverified

No public court filing, indictment, or sworn statement has yet linked the arrested Amsterdam man directly to the FBI jobs website breach. Dutch police confirmed only that the arrest happened within a broader ShinyHunters investigation, not that it settles the FBI case. Neither the Dutch police nor the FBI has released forensic logs, seized devices, or technical evidence proving exactly how the jobs portal was breached or how much data actually left FBI servers.

This gap between public claims and public proof is common in major cybercrime cases. Hacking groups often announce breaches to boost their reputation and pressure victims, while law enforcement agencies stay quiet to protect ongoing investigations and the safety of employees whose data may be at risk. For everyday Americans, the episode is a reminder that government systems holding sensitive personal data remain a target, and that answers about what was actually taken can take months to surface.

For now, the confirmed facts are narrower than the headlines suggest: an arrest happened, an FBI investigation is open, and a hacking group made a bold public claim. Whether that claim holds up under forensic scrutiny is still an open question, one that Dutch courts and federal investigators will need to answer with evidence, not statements.

Sources:

cbsnews.com, theregister.com, thehackernews.com, theguardian.com, globalbankingandfinance.com, jpost.com