Dutch Police Crack Down on Shiny Hunters as Arrested Hacker’s Past Catches Up with Him
A dramatic escalation in cyberattacks by the notorious hacker group ShinyHunters has left authorities scrambling to keep pace. The group’s sudden surge in activity comes just days after Dutch police arrested a 23-year-old convicted cybercriminal, Pepijn van der Stap, who had previously bragged about his exploits online under the alias “Umbreon.” Van der Stap was accused of aiding ShinyHunters in their data thefts and extortions, which have targeted some of the world’s most prominent organizations.
Van der Stap’s arrest marks a significant turn of events for the 23-year-old, who had seemingly reformed his ways. Just last month, he gave an interview to KrebsOnSecurity, in which he professed to have turned his life around and was working as an offensive security lead at the Dutch company Neo Security. However, his claims of redemption may have been short-lived, as authorities took him into custody on or around September 16.
ShinyHunters’ recent attacks have left many organizations reeling. The group’s most high-profile heist to date occurred in February, when they social engineered their way into Odido, the Netherlands’ largest mobile telecommunications provider, and stole sensitive data on over 6.2 million people. Dutch authorities have been urging the public for help in identifying a voice from a recorded telephone call that was used to carry out the intrusion.
The group’s brazen attacks are a testament to their skills and organizational prowess. ShinyHunters’ tactics often involve sophisticated social engineering techniques, which they use to trick unsuspecting employees into divulging sensitive information or accessing secure systems. Their eventual goal is usually to extort large sums of money from the organizations they’ve targeted.
The arrest of Van der Stap has sent shockwaves through the cybercrime community. His past exploits had been well-documented online, and his claims of reforming his ways were met with skepticism by many in the security industry. It now appears that he may have been playing a double game all along, using his supposed reformation as a smokescreen to continue his nefarious activities.
The fallout from Van der Stap’s arrest is still unfolding, but one thing is clear: ShinyHunters’ attacks will likely continue until they are brought to justice. As the security community continues to grapple with the aftermath of these attacks, it’s essential for organizations and individuals alike to remain vigilant and take proactive steps to protect themselves from these types of threats.
In practical terms, this means staying up-to-date on the latest security patches and software updates, being cautious when interacting with unknown emails or phone calls, and having robust incident response plans in place. By taking these measures, we can all do our part in preventing these types of attacks and keeping our sensitive information safe from falling into the wrong hands.
Source: Krebs on Security — 2026-09-28