Opens in a new tab

ShinyHunters Investigation: Dutch Hacker Arrested

Dutch police arrest suspect tied to ShinyHunters as group escalates attacks

The ShinyHunters investigation has led to the arrest of a 23-year-old Dutch cybercriminal suspected of assisting the data theft and extortion group. The arrest was followed by a reported escalation in ShinyHunters activity involving the FBI and ransomware operation Cl0p.

ShinyHunters investigation leads to Dutch arrest

According to three sources cited by KrebsOnSecurity, the arrested man is Pepijn van der Stap, from Almere and Lelystad in the Netherlands. Dutch authorities reportedly arrested him on or around 16 September 2026 and have held him in custody for questioning.

The ShinyHunters investigation concerns suspected assistance with data theft and extortion attacks attributed to the group. One source said a colleague personally witnessed Dutch authorities removing items from Van der Stap’s residence, although the available report does not identify what was seized.

The Dutch authorities had not publicly confirmed his identity in the source material. The identification and reported circumstances of the arrest therefore rely on people described as having knowledge of the matter. No details have been provided about any new charges, the precise evidence being examined or how long he may remain in custody.

Who is the arrested cybercrime suspect?

Van der Stap was previously convicted in late 2023 in connection with a series of data thefts and extortion attempts. Prosecutors said those offences generated between EUR 1.5 million and EUR 2.7 million.

During that trial, he admitted operating under the online identity “Umbreon”. Using this handle, he extorted victims and advertised stolen data on English-language cybercrime forums, including the now-defunct RaidForums and Breached.

In September 2021, the Umbreon account was observed offering a database containing information about 2.3 million people in the Netherlands. This activity formed part of a concealed criminal identity that existed alongside Van der Stap’s legitimate cybersecurity work.

At the time, he worked as a software engineer for Amsterdam cybersecurity company Hadrian. He also volunteered with the Dutch Institute for Vulnerability Disclosure, a non-profit security research organisation. At his trial, Van der Stap described this contrast as a Dr. Jekyll and Mr. Hyde existence.

He confessed to the data theft and extortion activity and received a four-year prison sentence, with one year suspended. He was released from prison in December 2025.

Claims of rehabilitation before the arrest

In an interview with KrebsOnSecurity on 9 September 2026, Van der Stap presented himself as a reformed hacker seeking to rebuild his life and contribute positively to society. At the time of the interview, he was employed as offensive security lead at Dutch company Neo Security.

He said he continued to face civil lawsuits and restitution claims connected with previous victims and was attempting to make amends. Neo Security did not respond to the publication’s requests for comment.

Not long after the interview, Van der Stap abruptly stopped answering messages. Other people close to him were also reportedly unable to contact him during the following two weeks. Sources subsequently connected his disappearance to the reported arrest around 16 September.

Odido intrusion linked to the investigation

A significant part of the ShinyHunters investigation involves an intrusion at Odido, the largest mobile telecommunications provider in the Netherlands. Dutch police have asked the public to help identify a voice captured during a telephone call made in February 2026.

Police believe the recording features a native Dutch-speaking ShinyHunters member. During the call, the attacker allegedly used social engineering to manipulate an Odido employee into logging in through a spoofed service, enabling the intrusion.

This detail is important because the incident appears to have depended on impersonation and employee manipulation rather than exploitation of a publicly identified software vulnerability. No affected product versions or security patches have been identified in relation to the Odido incident.

For the ShinyHunters investigation, the voice recording could provide evidence connecting an individual to the call. The public appeal also indicates that Dutch authorities were actively investigating the intrusion before Van der Stap’s reported arrest.

ShinyHunters activity escalates after arrest

The remaining members of ShinyHunters reportedly increased their activity dramatically in the days immediately following the arrest. The reported incidents included the theft of highly sensitive information from the FBI and an attempt to extort Cl0p, a Russian ransomware group.

The available source does not explain how the FBI data was obtained, what systems were accessed or precisely what information was taken. It also does not establish whether the activity was retaliation for the Dutch arrest or simply part of an existing campaign. Those distinctions remain important because public claims by cybercriminal groups may be incomplete or designed to generate attention.

The reported attempt to extort Cl0p is unusual because it involves one established cybercrime operation targeting another. However, it is consistent with an ecosystem in which threat actors steal from rivals, expose private communications or use access and data as leverage.

As of the article’s publication on 28 September 2026, the ShinyHunters investigation remained active. Van der Stap was reportedly in custody, while other suspected group members appeared capable of continuing data theft and extortion operations.

Why the ShinyHunters investigation matters

The arrest illustrates why removing one suspected participant does not necessarily stop a distributed cybercrime group. ShinyHunters members may operate across different countries, identities and criminal services, allowing remaining participants to continue attacks after an arrest.

The Odido incident also demonstrates the operational value of convincing telephone impersonation. Attackers may not need to defeat security software if they can persuade an employee to enter credentials into a false login service.

What organisations should do now

Organisations should focus on controls directly relevant to the reported activity:

  • Require independent verification of unexpected calls requesting logins, authentication codes or account actions.

  • Train service desk and telecommunications staff to recognise spoofed login workflows and urgent impersonation attempts.

  • Review identity logs for unusual sessions, newly registered devices and access following unsolicited support calls.

  • Prepare a data theft response process covering investigation, legal assessment, stakeholder communication and extortion demands.

The continuing ShinyHunters investigation shows that an arrest can disrupt part of a criminal network without ending the immediate threat. Organisations should treat claims carefully, preserve relevant evidence and respond to confirmed access or data exposure rather than engaging publicly with unverified criminal statements.

Originally reported by krebsonsecurity.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call