Gaming
Alleged ShinyHunters Leader Arrested Over Hack That Exposed GTA Online’s Daily Earnings
Dutch police have arrested a 24-year-old Amsterdam man accused of leading ShinyHunters, the notorious hacking collective the FBI blames for a wave of corporate breaches — including a leak this year that pulled back the curtain on just how much money Grand Theft Auto Online actually makes.
The Dutch National Police confirmed the arrest in a statement on September 28, though they did not publicly identify the suspect. Reuters later named him as Pepijn van der Stap, who until recently worked as the offensive cybersecurity lead at Neo Security, an Amsterdam-based firm. According to the FBI, Van der Stap has past hacking-related convictions and had presented himself as reformed when he joined the company earlier this year. Investigators, however, allege he had secretly been steering ShinyHunters since 2025 — a claim the group itself denies, along with accusing Dutch authorities of incompetence.
ShinyHunters has become one of the most feared names in cybercrime circles, linked to intrusions at more than 100 companies and institutions worldwide, including Ticketmaster and, remarkably, the FBI itself. But for the video game industry, the group’s most consequential hit came in April, when it breached Rockstar Games and attempted to extort the studio by threatening to publish stolen internal data unless a ransom was paid.
Rockstar refused to negotiate. The group followed through on its threat and released the material anyway. Buried in the leak was a striking revelation: GTA Online, the perennially profitable multiplayer companion to Grand Theft Auto 5, generates more than $1 million in revenue every single day. The figure was so eye-catching — and so evidently positive for Rockstar’s business — that shares in parent company Take-Two actually ticked upward following the disclosure, an unusual silver lining for a company that had just been the victim of a criminal extortion attempt.
The April breach was hardly an isolated incident for Rockstar’s security team this year. In August, a separate hacking group calling itself CyberLeek leaked gameplay footage from the long-awaited GTA 6, prompting Take-Two to issue subpoenas to Microsoft, Discord and X (formerly Twitter) in a bid to unmask those responsible for that leak.
Following news of Van der Stap’s arrest, FBI Cyber Division assistant director Brett Leatherman used the moment to send a pointed message to any remaining ShinyHunters members still at large. “You’ve heard about the arrest of your colleague. We’re confident you’ve seen or heard things in recent days that the public has not,” Leatherman said. “Other groups believed anonymity, or their friends, would protect them, and they were wrong. Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
The arrest adds another layer to what has already been a turbulent year for Rockstar off the back of its security woes. The studio remains embroiled in an employment tribunal brought by the Independent Workers’ Union of Great Britain over its dismissal of 34 staff last October — a move the claimants allege was retaliation for union organizing. Between the labor dispute, the GTA 6 footage leak and now the fallout from the ShinyHunters breach, Rockstar finds itself fending off scrutiny on multiple fronts even as anticipation for its next flagship release continues to build.
Whether Van der Stap’s arrest meaningfully disrupts ShinyHunters’ operations remains to be seen. The group has previously shown resilience even after individual members were identified or detained, and its swift denial of the FBI’s characterization suggests it intends to keep operating. But for a hacking collective built partly on the perception that its members could act with impunity, the very public unmasking of an alleged leader — one who had, by the FBI’s account, been quietly working a cybersecurity day job — may prove to be the kind of crack that widens under pressure.
You must be logged in to post a comment Login