Dutch police and the FBI say they have arrested a member of the ShinyHunters cybercrime group, and that the man's seized laptop contained plans to have two people murdered abroad.

In a video message on Tuesday, Brett Leathermann, who leads the FBI's cyber division, said Dutch authorities had taken into custody one of the "alleged leaders of ShinyHunters," crediting the Dutch High Tech Crime Unit with moving quickly to protect victims and preserve evidence, and vowing to pursue the rest of the group.

Dutch police said separately that a 24-year-old man from Amsterdam was arrested on September 15 under Dutch law, appeared in court on Tuesday and has been remanded into custody for at least 90 days. He was arrested for participating in a criminal organization, which police identified as ShinyHunters. Following the seizure of his devices, police said, "a lot of information was found on his laptop, including about two murders that should be committed abroad." He is now also being investigated over that alleged plot, a case Dutch authorities describe as separate from the ShinyHunters investigation.

ShinyHunters is accused of breaking into companies, stealing data and threatening to publish it unless ransoms are paid. Dutch authorities link the group to breaches at Pornhub, Ticketmaster and AT&T, and to an attack on Dutch telecom provider Odido — though police said the arrested man was not detained over the Odido hack.

Security journalist Brian Krebs first reported the arrest, and other outlets have named the suspect as Pepijn van der Stap, whom Bloomberg profiled in 2024 as a security researcher who also moonlighted as a criminal hacker. Reporting by Bloomberg and Reuters said he was arrested at the offices of Neo Security, where he worked as chief technology officer, in a raid that involved flash-bang grenades. Neo Security did not immediately respond to a request for comment, and a representative of ShinyHunters told TechCrunch the suspect "has no association with us."

The arrest lands days after the FBI reportedly told employees that names, addresses, job titles and Social Security numbers were exposed in a "cyber security incident." The FBI has not publicly confirmed a breach, but ShinyHunters said it took data belonging to "mostly all" of the bureau's agents and applicants through its careers site and job application portal. Reporters examining a sample of about 5,000 agents found references to blood and urine samples and to psychiatric reports, raising fears of a serious counterintelligence exposure. The group told TechCrunch it would not publish the data, saying the breach was intended to dispute what it called false allegations against it.