Slovak News

Science & Tech · Netherlands

Dutch ‘Reformed’ Hacker Arrested in ShinyHunters Probe

A 24-year-old Amsterdam man previously convicted of hacking and later profiled as reformed has been arrested as investigators examine a possible link to the extortion group ShinyHunters.

Live version 1 · updated 8 sources · 3 perspectives
Foto: The Jerusalem Post · source

What's new

  • Dutch police confirm arrest of Amsterdam man tied to ShinyHunters probe
  • Suspect identified by multiple outlets as Pepijn van der Stap, previously convicted hacker
  • Employer Neo Security says internal review found no evidence he acted against it
  • ShinyHunters denies any association with the arrested man

Authorities in the Netherlands verified that a 24-year-old Amsterdam resident has been taken into custody as part of a probe into ShinyHunters, the hacking and extortion group, just days after international profiles portrayed him as a reformed hacker turned cybersecurity professional. Multiple outlets identified the suspect as Pepijn van der Stap, who was convicted in 2023 of hacking, data theft and extortion.124

From convicted hacker to security professional

An Amsterdam court convicted Van der Stap in November 2023 on charges of data theft and extortion, handing him a four-year prison term. He was released in December 2025 and subsequently said he had disavowed cybercrime.2361

On September 9 he gave an interview to KrebsOnSecurity in which he presented himself as a reformed hacker, describing his past conduct. He described the hacking as something that came effortlessly for him rather than something he felt driven to do. My habit was collecting," he said. He also told NL Times, "I was trying to contribute positively to cybersecurity and was dealing with the consequences of my previous crimes."17

At the time of his arrest he was working as offensive security lead at the Amsterdam-based firm Neo Security. He had earlier worked as a software engineer at the cybersecurity startup Hadrian while volunteering at the nonprofit research group DIVD. His transformation from cybercriminal to security professional received wide international coverage.7851

Arrest and court appearance

According to Dutch and international reports, Van der Stap was arrested and his Amsterdam home searched, with electronic devices seized; sources place the arrest on September 15 or 16. Dutch police, in a statement, said: "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters." He was scheduled to appear before Rotterdam District Court on September 29.4751

Investigators have pointed to Van der Stap's alleged hacker handle 'Umbreon', according to a single-source report, as a possible link to ShinyHunters, which is said to have used the same alias in the breach of the FBI and in a defacement of the ransomware group Cl0p; the same handle reportedly appeared in a 2020 HackForums defacement. However, according to the same report, a voice in a recording connected to the Odido breach did not sound like Van der Stap, and ShinyHunters used Umbreon-linked Pokémon imagery in the FBI hack without this alone establishing his involvement.48

Employer's reaction

Van der Stap's boss at Neo Security, Benjamin Korper, said he had carefully vetted him before hiring him. Korper described his reaction to the arrest as one of shock, saying, "Absolutely everybody I talked to is flabbergasted." He explained that Neo Security brought in an outside firm to look into the matter and reported that, "so far investigators have found no evidence that he acted against his employer or its clients." Korper noted that he had had no contact with Van der Stap following the arrest.2365

ShinyHunters and the wider case

Multiple reports characterize ShinyHunters as an organization notorious for massive data breaches and extortion schemes. It has claimed responsibility for a breach of the FBI's job-application website, which the FBI confirmed had been compromised, and for a February 2026 attack on the Dutch telecom provider Odido, the country's largest mobile carrier. According to a single source, attackers gained access to Odido after a Dutch-speaking caller impersonating an IT employee obtained login credentials from customer service, and stolen data was later published on the dark web after a ransom demand was refused. There is disagreement over the scale of the Odido breach attributed to ShinyHunters — while some reports put the number of affected Dutch individuals above 6.2 million, another source put the customer count at over 6 million.2365

A representative for ShinyHunters denied any connection to Van der Stap, saying: "That individual has no association with us. Frankly, we are laughing." The group separately told Dutch media that the man in the Odido recording was a member of their group and pledged support: "Our team member has our full support – emotionally, mentally, and financially. and that all necessary arrangements, including securing a criminal defense attorney, had already been made."471

ShinyHunters also issued statements aimed at Dutch police following the arrest, saying, according to one source, "The Dutch police will need all the luck in the world – and everyone's prayers – if they want to catch him before we carry out another large-scale data theft," and describing the force as "a big joke." One report said the group's activity escalated after Van der Stap was detained.17

Why it matters

The case touches millions of Dutch telecom customers whose data was allegedly exposed, and it raises questions about vetting and trust in cybersecurity firms that hire people with criminal hacking records. For readers across Europe, it underscores how extortion groups such as ShinyHunters continue to target major infrastructure and public institutions.27

Version history

  1. version 1 ·