Dark Web Hitman Site: Rotterdam Woman Arrested After Paying $1,400
A 45-year-old woman was arrested in Rotterdam on September 12, 2026, suspected of involvement in ordering a contract killing via a dark web hitman site.
A 45-year-old woman was arrested in Rotterdam on September 12, 2026, suspected of involvement in ordering a contract killing via a dark web hitman site. The intended victim, called Jerom by RTL Nieuws, is a Rotterdam businessman who suspects the order came from ex-in-laws following a bitter divorce. The client paid $1,400 (€1,200) in Bitcoin as a deposit, and the full asking price was $9,000. The website turned out to be a scam. The murder was never carried out. Under Dutch law, ordering a killing is still a criminal offence even when the hitman does not exist.
The man knew something was wrong for a year. He didn’t know what, exactly, but he knew enough to keep looking over his shoulder every time he left the house. He’d been through a bitter divorce. Relations with his ex-in-laws had collapsed. His elderly mother lived with him, and he worried her too.
What he didn’t know until recently was that someone had placed a detailed murder order on a dark web website advertising contract killings. The order listed his address, included a recent photograph of him, described the layout of his house, and specifically noted the alarm system he used. It also noted his elderly mother, though the message was explicit her: “The only demand is that he has to die. I don’t care what happens to the mother.”
The instruction to the supposed hitman: “burn him alive and make sure he doesn’t survive.”
On September 12, 2026, Dutch police arrested a 45-year-old woman in Rotterdam in connection with that order. She has no registered address. Police suspect her of being “involved” in organising the contract killing. They have not confirmed whether she was the person who placed the order directly or whether she played another role.
The intended target, identified by RTL Nieuws under the pseudonym Jerom, spoke after the arrest. “I am incredibly relieved that the police have identified a suspect. I lived in uncertainty for a year. I was constantly looking over my shoulder.”
I was constantly looking over my shoulder.”
The Website: A Scam That Has Been Running for Over a Decade
Before getting into the arrest, it’s worth understanding the site at the centre of this case, because it tells you a lot who uses these services and why.
The dark web assassination site that took Jerom’s would-be killer’s money operates under several rotating names: Besa Mafia, Camorra Hitmen, and Colombian Hitmen are among the labels it has worn over the years. It claims to arrange professional contract killings anywhere in the world in exchange for Bitcoin. It looks credible enough to fool desperate people. It has never, as far as law enforcement can establish, actually killed anyone.
What it has done is collect Bitcoin payments from hundreds of people across multiple countries and deliver nothing. No hitman, no attack, no follow-through. It is, in the practical sense, an elaborate scam that preys on people in the worst moments of their lives, when hatred has eclipsed judgment enough to make them believe clicking through a dark web marketplace and uploading a photograph of someone they want dead is a reasonable plan.
The site administrator has publicly denied being a fraud. When RTL Nieuws contacted them, the anonymous operator responded: “Our website is real. We can easily prove that we kill people if you give us an order to kill someone.” Police and researchers say otherwise. So do the data records, which show hundreds of orders placed and zero murders connected to those orders.
London-based security researcher Chris Monteiro infiltrated the site in 2016 and collected records connected to hundreds of purported murder orders from around the world. That data eventually made its way to RTL Nieuws and, through them, to Dutch authorities. According to Monteiro’s assessment, the site’s operators have earned more than €1 million through their criminal scam, money paid by people who intended to commission murders and instead funded a fraud operation that never intended to carry them out.
This is the uncomfortable heart of the story. The website’s operators are criminals. The people paying them are criminals. The intended victims knew nothing any of it.
How RTL Nieuws Broke This Story Open
The arrest in September 2026 is the result of a long investigative thread that started years earlier and came to a head in 2025.
RTL Nieuws obtained data from the hacked source files, Monteiro’s infiltration of the site, and spent considerable time mapping its Dutch footprint. What they found was deeply unsettling: at least seven Dutch citizens had been named as murder targets in orders placed through the site between 2016 and 2022. In four of those cases, the clients had actually paid, with payments ranging from €1,000 to nearly €10,000.
The targets were not organised crime figures. They were ordinary people. A teacher. A nurse. A civil servant. A hospital worker. A municipal official. People who went to work, came , and had no idea that someone in their lives had attempted to buy their death.
RTL made an unusual decision: in April 2025, they shared the data they possessed with the Dutch police’s National Investigation and Interventions Unit before publishing, breaking from the standard journalistic convention of not informing subjects of an investigation in advance. They cited the ongoing risk to living people as the reason. Several intended victims had not yet been informed they were targets. Police subsequently contacted those individuals.
Police spokesperson Thomas Aling confirmed the situation: “We’ve already informed several victims, and we’re still investigating the perpetrators. We take these matters very seriously because placing such an order is a criminal offense.”
The investigation that produced the September 2026 Rotterdam arrest is not the only one active. Dutch police opened a second separate criminal probe covering a suspected murder order in the eastern Netherlands, a different case, a different intended victim, the same dark web site. At least 14 separate Dutch assassination orders are under investigation, according to available reporting.
You Still Go to Prison Even If the Hitman Was Never Real
This is the detail most people find surprising when they first encounter this kind of case.
Dutch criminal law does not require that a crime be completed for its attempted commission to be prosecuted. Soliciting a murder, paying someone to kill a person, is a serious criminal offence regardless of whether the person paid was capable of carrying it out, willing to carry it out, or even real. The intent and the attempt are the offence.
This principle was established clearly in Dutch courts in 2021, in a case involving the same website. Imran M., 42 years old, from The Hague, was sentenced to eight years in prison for twice attempting to hire a contract killer to murder his ex-wife. He submitted her photograph, her address, her car details, and offered a bonus payment if the job was completed quickly. He sent money. His ex-wife and their children were forced into hiding for six months while the threat was assessed. They did not know the order while it was active.
The judge who sentenced Imran M. noted he had acted “coldly and clinically” in placing the orders and that he could take no credit for the fact that his ex-wife was still alive. That credit, implicitly, went to the fact that the website was a scam.
The same logic applies to the Rotterdam case. The woman arrested is facing criminal prosecution for attempting to arrange a killing regardless of the outcome. The fact that Jerom is alive does not diminish the crime under Dutch law. It simply means the intended victim is available to give evidence.
The Bitcoin Tracing Problem
One of the reasons these cases take so long to resolve is that cryptocurrency payments are harder to trace than most people assume, and easier to trace than criminals believe.
The person who placed Jerom’s murder order paid $1,400 in Bitcoin as a deposit. The full agreed price was $9,000. Dutch police acknowledge openly that tracing Bitcoin payments is complex and time-consuming. Aling told RTL: “It is a complex operation to trace who made such a Bitcoin payment. That is sometimes quite complicated and takes time.”
Bitcoin is pseudonymous, not anonymous. Transactions are permanently recorded on a public blockchain, as we’ve covered in detail in our piece on the AudiA6 cryptocurrency laundering takedown , where blockchain forensics ultimately connected hundreds of millions in criminal proceeds to specific operators. The same tracing principles that exposed that laundering network can eventually be applied to dark web purchase histories, but it requires time, technical resources, and often cooperation from cryptocurrency exchanges to connect wallet addresses to real identities.
The fact that this case has now produced an arrest suggests Dutch authorities were able to follow that chain at least far enough to identify a specific suspect. The investigation is still ongoing.
Why People Keep Using These Sites
Here’s the part of this story that deserves more attention than it usually gets: this site has been known to be a scam for years. Monteiro’s infiltration was in 2016. The data has been in circulation for nearly a decade. And yet people are still sending money to it.
The explanation isn’t stupidity. It’s desperation combined with ignorance.
People who end up on dark web hitman sites are rarely sophisticated dark web users. They’re not navigating underground forums or understanding operational security. They’re people who have reached a point of extreme anger or fear in their personal lives- a divorce, a custody dispute, a financial conflict, a perceived betrayal- and who Google something like “hire someone to kill” and find their way to a site that appears to offer a solution. The dark web framing lends false credibility. Bitcoin payment sounds untraceable to someone who’s never thought blockchain forensics.
The site’s clientele, as police and researchers have observed, primarily consists of people with relationship-related grievances, ex-spouses, estranged family members, business partners who’ve turned adversarial. They’re not professional criminals. They’re ordinary people who have convinced themselves that paying to have someone killed is a viable response to something that happened in their lives.
As our piece on how dark web scam sites operate and how law enforcement dismantles them documented, the pattern is consistent: criminal scam operators build plausible-looking services, collect cryptocurrency, and deliver nothing, while the clients who paid them are simultaneously defrauded AND building a criminal case against themselves. The Besa Mafia site is simply the most durable example of this model applied to the most extreme possible service.
What This Means for Jerom
The man whose death was ordered via this site says he lived with uncertainty for a year. He knew something was wrong before he knew what it was. He suspected the order might have come from his ex-in-laws. Police have not publicly confirmed the identity of the person behind the order or their relationship to Jerom, only that the arrested woman is suspected of involvement.
He lived in uncertainty because the dark web doesn’t operate with transparency. The order was placed years before it came to RTL Nieuws’s attention. If not for Monteiro’s 2016 infiltration of the site, and for RTL’s decision to that data with police rather than publish it, Jerom might never have known.
The information included in the murder order- his address, his photograph, his alarm system, and the fact that his elderly mother lived with him- was detailed enough that whoever submitted it knew him well. That kind of personal detail doesn’t come from a stranger. It comes from someone with access to his life.
His mother was specifically mentioned in the order and specifically excluded from the instructions what should happen. The client’s words were direct: “I don’t care what happens to the mother.” That callousness sits in a case file now, available to prosecutors.
The Broader Pattern: Dark Web, Real Consequences
What makes this case matter beyond the Netherlands is what it illustrates how the dark web intersects with ordinary human disputes.
The dark web is not populated primarily by sophisticated criminal networks running high-tech operations. As our guide explaining what the dark web actually is makes clear, most dark web activity is mundane, and a significant fraction of what looks like serious criminal infrastructure is fraud operated within the criminal economy itself. The Besa Mafia site scams its clients. The clients would have scammed the targets of their lives.
The victims in these cases, Jerom, Imran M.’s ex-wife, the teacher, the nurse, the municipal official, are not cyber-crime victims in the conventional sense. Their data wasn’t breached. Their accounts weren’t hacked. Someone who knows them uploaded their photograph and address to a murder marketplace and paid to have them killed. That the hitman didn’t exist is legally irrelevant and psychologically inadequate comfort.
For anyone who discovers that their information has appeared in an online context they didn’t choose, whether a data breach or something darker, the starting point is the same: understanding what was exposed and what it might enable. Our guide on what to do when your personal data surfaces online covers the practical steps, though the steps look different when the exposure is a murder contract rather than a stolen password.
The 45-year-old woman arrested in Rotterdam faces prosecution for her suspected involvement in soliciting a contract killing. The investigation is ongoing. Police have not confirmed her specific role, whether she placed the order directly or was connected to it through someone else.
The case that Imran M. established in 2021 gives a sense of the sentencing range under Dutch law: eight years for twice attempting to commission a murder, with the judge specifically noting that credit was not available for the failure to complete the crime. The Dutch public prosecutor’s office has not announced charges yet in the current case.
The RTL Nieuws investigation that produced this case is also still unfinished. Of the 14 Dutch assassination plots identified in the hacked data, the Rotterdam case has now produced an arrest. The eastern Netherlands case has an active investigation. The status of the remaining cases is not publicly confirmed.
The Besa Mafia / Camorra Hitmen site itself remains accessible on the dark web. Its administrator continues to insist the service is real. The cycle continues.
Frequently Asked Questions
No. The website advertises contract killing services but operates as a scam. It accepts Bitcoin payments and does not carry out killings. Researchers and law enforcement have established this pattern across hundreds of documented orders. The site has operated under various names including Besa Mafia, Camorra Hitmen, and Colombian Hitmen.
Why was the woman arrested if no murder happened?
Under Dutch law, soliciting a murder is a criminal offence regardless of whether the hired party was capable or willing to carry it out. The attempt itself constitutes the crime. This principle was established in the 2021 conviction of Imran M., who received eight years for placing orders on the same site.
How did police find out?
British security researcher Chris Monteiro infiltrated the site in 2016 and collected records of hundreds of purported orders. RTL Nieuws obtained this data, investigated the Dutch cases, and shared the data with Dutch police in April 2025.
How many Dutch people were targeted?
RTL Nieuws identified at least seven Dutch citizens as named targets, with four confirmed cases where payments were actually made. Police are investigating 14 separate Dutch assassination plots from the hacked data.
Can Bitcoin payments actually be traced?
Yes, with time and technical resources. Bitcoin transactions are permanently public on the blockchain. Police acknowledge that tracing specific payments to real identities is complex and slow, but it is possible, and in this case appears to have contributed to the arrest.
Written by Muhammad Anas
Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.
Seven Chinese AI Labs Stole 190 Million Claude Exchanges. Here’s How They Did It.
Between May and July 2026, accounts linked to Alibaba’s AI division generated more than three million conversations with…
Greenberg Traurig Data Breach: One Law Firm Hit. Six in Three Weeks. Here’s the Real Story.
Greenberg Traurig confirmed a data breach to Vermont’s Attorney General on September 8, 2026. A ransomware group called…
Operation Alice: One Person Was Running 373,000 Dark Web Sites. Every Customer Is Now a Suspect.
Between March 9 and March 19, 2026, law enforcement agencies from 23 countries quietly dismantled one of the…
Bank of Baroda Data Breach: Why TripleX Released 1TB for Free And Why That’s the Whole Story
When a ransomware group steals data, the usual move is to demand payment. Hand over the money, or…
Infostealer Logs – The Breach That Rarely Gets Reported
Infostealer logs: In the first half of 2025, over 1.8 billion credentials containing saved passwords, usernames, phone numbers,…
Xinbi Guarantee Seized – Inside the $24B Telegram Scam Marketplace
If you ask the average person where the largest criminal marketplaces on the internet are located, they’ll say…
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
