Dutch law enforcement officials have taken into custody a 24‑year‑old man from Amsterdam as part of a broader investigation into the notorious hacking outfit known as ShinyHunters. According to statements released by the Dutch National Police on September 28, the suspect was detained in connection with a data breach that earlier this year exposed confidential financial figures for Rockstar Games' popular service, GTA Online. While the police initially chose not to disclose the individual's name, a later report from Reuters identified him as Pepijn van der Stap, who serves as the offensive cybersecurity lead at Neo Security, a security firm based in Amsterdam.

Van der Stap's professional background is somewhat paradoxical. He holds a senior position at a legitimate cybersecurity company, yet he also carries a criminal record that includes prior convictions for offenses related to hacking.

He joined Neo Security only this year, but U.S. investigators, particularly the FBI, contend that he has been at the helm of ShinyHunters since 2025.

The hacking group itself has consistently denied any involvement in the GTA Online leak and has even gone so far as to accuse Dutch police of mishandling the case. ShinyHunters has built a reputation for targeting a wide array of organizations. Over the past several years, the group is believed to have breached more than one hundred companies and institutions, ranging from entertainment giants like Rockstar Games to ticketing powerhouse Ticketmaster, and even the Federal Bureau of Investigation itself. Their modus operandi typically involves infiltrating corporate networks, exfiltrating sensitive data, and then leveraging that information for extortion or public exposure.

In April, the group launched a high‑profile attack against Rockstar Games. After gaining unauthorized access to internal systems, ShinyHunters attempted to extort the studio by threatening to release a trove of confidential documents unless a ransom was paid.

Rockstar declined to negotiate, opting instead to stand firm against the blackmail. Undeterred, the hackers went ahead and published the stolen data, which included a startling revelation: GTA Online generates more than one million dollars in revenue each day. This disclosure not only embarrassed the game developer but also highlighted the lucrative nature of its online services. The GTA Online leak added to a string of security challenges that Rockstar has faced in recent months.

In August, a separate hacker collective known as CyberLeek leaked gameplay footage from the highly anticipated title GTA 6. That incident prompted Take‑Two Interactive, Rockstar's parent company, to issue subpoenas to major technology platforms—including Microsoft, Discord, and X (formerly Twitter)—in an effort to trace the source of the leak and hold the perpetrators accountable. Following the arrest of van der Stap, Brett Leatherman, an assistant director in the FBI's Cyber Division, issued a stark warning to any remaining members of ShinyHunters. "Now, to the remaining members of ShinyHunters: You've heard about the arrest of your colleague.

We're confident you've seen or heard things in recent days that the public has not," Leatherman said in a public statement. "Other groups believed anonymity, or their friends, would protect them, and they were wrong. Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left.

The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours." Leatherman's message underscores the growing pressure that law‑enforcement agencies are applying to cybercriminal networks.

By publicly naming a suspect and emphasizing the inevitability of further arrests, the FBI aims to sow doubt among remaining members and encourage defections. The agency's strategy reflects a broader trend in which international cooperation and aggressive legal tactics are being used to dismantle sophisticated hacking groups that operate across borders. Meanwhile, Rockstar Games continues to grapple with internal challenges beyond the realm of cybersecurity. The studio is currently embroiled in an employment tribunal with the Independent Workers' Union of Great Britain (IWU).

The dispute centers on the dismissal of thirty‑four employees in October of the previous year, a move that the union claims was retaliatory and linked to union‑organizing activities. The legal battle adds another layer of complexity to Rockstar's public image, as it navigates both external threats from cyber attackers and internal labor relations issues. The arrest of Pepijn van der Stap marks a significant development in the ongoing saga surrounding ShinyHunters. While it remains to be seen whether additional members of the group will be identified and apprehended, the incident serves as a reminder of the far‑reaching consequences that cyber‑attacks can have on major corporations, especially those that rely heavily on digital revenue streams.

As the investigation proceeds, both industry observers and law‑enforcement officials will be watching closely to see how the case unfolds and what precedents it may set for future cybercrime prosecutions.