In a stunning turn of events, the Netherlands has seen a dramatic escalation in hacking attacks by the notorious ShinyHunters collective, following the arrest of a key suspect with ties to the group. The 23-year-old individual, Pepijn van der Stap, was previously convicted for his role in data thefts and extortions, but had claimed to be reformed and trying to turn his life around.
Van der Stap’s story is one of contrasts. By day, he worked as a software engineer at the Amsterdam-based cybersecurity startup Hadrian, while volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research group. However, under the pseudonym “Umbreon”, he was secretly using his hacking skills to extort victims and post their data on English-language hacking communities like RaidForums and Breached.
In 2023, van der Stap was sentenced to four years in prison for his crimes, with one year suspended. He claimed to be suffering from PTSD related to childhood trauma, and opted to remain in custody rather than face treatment outside of prison. After being released in December 2025, he cast himself as a reformed hacker in an interview with KrebsOnSecurity just months later.
However, van der Stap’s newfound reputation appears to have been short-lived. He stopped responding to messages after the interview, and his LinkedIn profile remains active, listing him as the offensive security lead at Neo Security, a Dutch company that did not comment on his employment status.
The arrest of van der Stap by Dutch authorities is believed to have occurred around September 16, although details are scarce. The incident has apparently triggered a dramatic escalation in ShinyHunters’ activities, with the group claiming responsibility for stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
The group’s statement suggests that van der Stap may be more closely tied to ShinyHunters than previously thought. The hackers confirmed that the suspect in a recorded telephone call from February 2026, which tricked an Odido employee into logging in at a spoofed website and stealing data on over 6.2 million Dutch people, is indeed a member of their collective.
While authorities in the Netherlands are urging the public to help identify the voice in the recorded call, it remains unclear if they have matched the suspect to a confirmed real-life identity. The ShinyHunters statement also lashed out at the Dutch police, claiming that they are “incompetent” and unable to do anything about their activities.
The events highlight the complex web of relationships between hackers, cybersecurity professionals, and law enforcement agencies. While van der Stap’s story raises questions about rehabilitation and redemption, it also serves as a stark reminder of the ongoing threat posed by groups like ShinyHunters, who seem to operate with impunity despite the efforts of authorities.
For individuals and organizations looking to protect themselves from similar threats, this incident underscores the importance of vigilance and awareness. With hacking groups increasingly using social engineering tactics to gain access to sensitive data, it’s essential to educate employees about the risks and take steps to prevent such attacks. By staying informed and taking proactive measures, we can all play a role in mitigating the impact of these threats.
Source: Krebs on Security — 2026-09-28