> 24-Year-Old Arrested in Dutch Investigation Into ShinyHunters
[AUTHOR: Pierluigi Paganini]
[DATE: 29/09/2026 07:30]
[LANGUAGE: EN]
Dutch police confirm the arrest of a 24-year-old Amsterdam man as part of an investigation into the ShinyHunters hacking group.
Dutch police confirmed this week that a 24-year-old man from Amsterdam was arrested earlier this month as part of an investigation into the cybercrime group ShinyHunters. The suspect appears before Rotterdam District Court today, September 29. Multiple sources, including KrebsOnSecurity, have identified him as Pepijn van der Stap, a Dutch hacker previously known online as “Umbreon.”
“According to three sources familiar with the matter, the Dutch man arrested by authorities this month is Pepijn van der Stap, a convicted cybercriminal from Almere and Lelystad in the Netherlands. Van der Stap was previously convicted in 2023 in connection with a string of data thefts and extortions that prosecutors said earned between €1.5 million and €2.7 million.” states KrebsOnSecurity. “At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle “Umbreon” to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached. By day, however, van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian, while volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research group.”
Het klopt dat er deze maand een 24-jarige man uit Amsterdam is aangehouden in een onderzoek naar de hackersgroep ShinyHunters. Op dinsdag 29 september staat de man voor de raadkamer van de rechtbank Rotterdam. Morgen komen wij met meer info.— Politie Landelijke Opsporing en Interventies (@Pol_Ops_Int) September 28, 2026
This isn’t Van der Stap’s first time facing charges for hacking. He was arrested in January 2023 and accused of hacking and blackmailing more than a dozen companies in the Netherlands and abroad. He later pleaded guilty and was sentenced to four years in prison, with one year suspended, followed by three years of probation.
He was released in December 2025 and later worked as an offensive security lead at Dutch company Neo Security. At the same time, he was still facing civil lawsuits from some of his previous victims.
KrebsOnSecurity spoke with him on September 9, 2026. He described himself as a reformed hacker trying to make amends. He stopped responding to messages soon after. On September 15, Dutch police searched the Amsterdam home he shared with his mother and seized several electronic devices.
The connection to ShinyHunters runs through the “Umbreon” alias. Van der Stap used that handle and Pokémon imagery on BreachForums as early as 2021.
Source KrebsOnSecurity
Then the FBI jobs site defacement that ShinyHunters left after the FBIjobs.gov breach prominently featured an ASCII art version of the same Pokémon character, and the image appears identical to one used in a 2020 HackForums defacement attributed to ShinyHunters, a year before Van der Stap created his Umbreon account. That last detail cuts both ways: either the alias predates him in this context, or the timing coincidence is genuinely awkward. KrebsOnSecurity adds a more pointed interpretation: sources familiar with the investigation say the Umbreon imagery in the FBI defacement may have been a deliberate attempt by ShinyHunters’ current leader, a teenager from Amman, Jordan known as Rey, to pin the hack on Van der Stap. The two reportedly had ongoing bad blood over control of the ShinyHunters brand and data.
“Multiple sources close to the ShinyHunters investigation said the group’s recent risky attacks against the FBI and one of Russia’s most venerated ransomware groups amounted to a major pivot away from the more measured tenor of the hacking gang’s operations.” continues Krebs. “Those sources said the sudden shift came about after ShinyHunters was taken over by a teenage cybercriminal from Amman, Jordan who goes by the nickname Rey and operates as part of a cybercrime group called ScatteredLapsussHunters (SLSH), which experts say is an amalgamation of three hacking groups — Scattered Spider, LAPSUS$ and ShinyHunters.”
The ShinyHunters picture has gotten considerably more complicated. According to Krebs, the group was effectively taken over by Rey, who operates as part of a hybrid crew called ScatteredLapsussHunters, combining elements of Scattered Spider, LAPSUS$, and ShinyHunters. The FBI breach, the extortion attempt against Russian ransomware group Cl0p, and the overall escalation in aggressive behavior all followed Van der Stap’s arrest, which sources described as a major pivot from how the group had been operating. Mandiant told Krebs that ShinyHunters is on track to collect nearly $100 million in extortion payments in 2026 alone.
Dutch police were already investigating a separate incident linked to the ShinyHunters group. The group had breached Odido, the Netherlands’ largest mobile carrier, by tricking an employee into entering their credentials on a fake login page during a phone call. The attack exposed data relating to more than 6.2 million Dutch people.
Police later released a recording of the caller and asked the public to help identify the voice. ShinyHunters confirmed that the voice belonged to one of its members and said it would provide full support, including a criminal defense lawyer.
However, DataBreaches, which had spoken with Van der Stap several times, said the voice did not sound like him. A close friend reportedly reached the same conclusion.
“The one audio clip the police revealed following the Odido hack by ShinyHunters did not sound like van der Stap, whom we have spoken with on the phone numerous times. A close friend of his also said the audio clip of the Odido hacker connected to ShinyHunters was not van der Stap’s voice.” states DataBreaches. “There is no doubt ShinyHunters is linked to the Odido hack, but no evidence has been presented (or even charges at this point) linking van der Stap to that incident.”
Whether that’s true or a calculated deflection is exactly what the Rotterdam District Court is now beginning to work out.
One thread worth following separately: DIVD, the Dutch nonprofit security research group where Van der Stap had previously volunteered, disclosed last week that it was dealing with an internal security incident involving apparent malicious use of AI. The organization said it doesn’t appear related to ShinyHunters and shows no signs of involving a former volunteer, but the timing, arriving alongside Van der Stap’s arrest and the group’s escalating activity, means nobody’s treating that as a coincidence until the facts say otherwise.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, cybercrime)