Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data theft and extortion by the ShinyHunters. The arrest has caused a stir in the cybersecurity world, as the ShinyHunters group is known for its aggressive actions and successes in high-profile data thefts. Following the suspect’s arrest, the remaining members of ShinyHunters escalated their attacks, stealing sensitive data from the FBI and extorting money from the Russian ransomware group Cl0p.
See also: ShinyHunters: New wave of attacks – see if your data was leaked and what to do

The arrested person is Pepijn van der Stap, a convicted cybercriminal from Almere and Leylstad. He was previously convicted in 2023 for a series of data thefts and extortions that prosecutors estimated generated between 1.5 million and 2.7 million euros. Van der Stap’s operation was particularly complex, as he managed to combine his everyday life as a software engineer with his illegal activities as a hacker. Using the alias “Umbreon”, van der Stap blackmailed victims and published their data on hacker communities such as RaidForums ShinyHuntersBreached.
By day, he worked as a software engineer at Amsterdam-based cybersecurity firm Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD). Van der Stap's double life highlights how easily hackers can integrate into legitimate businesses, using their knowledge and skills to conceal their illicit activities.
Van der Stap confessed to his crimes and was sentenced to four years in prison, one of which was suspended. He chose to remain in custody rather than return home, citing a lack of better treatment for his psychological problems, including PTSD from childhood trauma. His decision to remain in prison highlights the challenges convicted criminals face in trying to reintegrate into society, especially when they are struggling with psychological problems.
He was released from prison in December 2025. In an interview with KrebsOnSecurity on September 9, 2026, van der Stap presented himself as a repentant hacker trying to make a positive contribution to society. He worked as the head of offensive security at Neo Security but faced ongoing civil lawsuits and compensation related to his past crimes.
See also: ShinyHunters: Claims FBI breach via Oracle PeopleSoft zero-day

Shortly after the interview, he stopped responding to messages, which raises questions about his current status and intentions.
Van der Stap was arrested by Dutch authorities around September 16 and is being held for questioning. Reports indicate that authorities removed items from his residence during the arrest. This move demonstrates the authorities' determination to collect as much evidence as possible to strengthen their case against him.
Dutch authorities have asked for the public’s help in identifying a voice from a recorded call in February 2026, where a ShinyHunters member tricked an employee of Odido, the largest mobile phone provider in the Netherlands, into providing access to data on over 6.2 million Dutch people. The case highlights the vulnerability of organizations to social engineering attacks, where hackers exploit human psychology to gain access to sensitive data.
ShinyHunters confirmed that the suspect in the audio clip is a member of their collection, stating that they are providing full support to their group member, including legal assistance. It remains unclear whether Dutch police have identified the caller's true identity. The support that ShinyHunters is providing to its members shows the solidarity and organization that characterizes such groups, making them more resilient to authorities' attempts to break them up.
See also: ShinyHunters hacked the dark web site of the Cl0p gang

The arrest of van der Stap and the ongoing search to identify other members of the ShinyHunters underscore the complexity of combating cybercrime. Authorities must address not only the technical challenges posed by hackers, but also the social and psychological dimensions that accompany such cases. This case is a reminder of the need for continued vigilance and cooperation among international authorities to address cyber threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
