Dutch police confirm arrest in ShinyHunters hacking investigation

Dutch Police Crack Down on ShinyHunters Hacking Group with High-Profile Arrest

In a significant development in the ongoing battle against cybercrime, Dutch police have confirmed that a 24-year-old man has been arrested in connection with the ShinyHunters hacking group. The suspect, identified as Pepijn van der Stap, is no stranger to law enforcement and has previously been involved in high-profile hacking cases.

Van der Stap was arrested on September 15 at his Amsterdam home, where authorities seized electronic devices and are believed to be examining a possible connection between him and ShinyHunters. The investigation into the group’s activities has been ongoing for some time, with police looking into their involvement in several notable breaches, including the recent FBI breach and the defacement of the Clop ransomware gang’s data leak site.

ShinyHunters is a notorious hacking collective known for its brazen attacks on high-profile targets. In 2020, they defaced the HackForums website using Pokémon imagery – a motif that has become synonymous with the group’s activities. Van der Stap himself was previously linked to this alias, having used it as early as 2021 on BreachForums.

But what exactly does ShinyHunters do? In simple terms, they’re a hacking collective that uses social engineering tactics to gain access to sensitive systems and data. They often pose as IT staff or use phishing emails to trick victims into revealing their credentials. This can lead to catastrophic consequences for the affected organizations, with sensitive information being leaked online.

The connection between Van der Stap and ShinyHunters is still unclear at this point, but it’s clear that authorities are taking a close look at his activities. In 2023, he was arrested and charged with hacking and blackmailing over a dozen companies in the Netherlands and worldwide. He later pleaded guilty and was sentenced to four years in prison.

The ShinyHunters group has denied any connection to Van der Stap, claiming that he is not associated with them. However, it’s worth noting that this denial may be a typical threat actor response – one designed to deflect attention from their own activities.

For security-aware individuals and organizations, the takeaway from this story is clear: no matter how seemingly unrelated, all hacking cases are interconnected. Law enforcement agencies will continue to scrutinize these groups and individuals, and it’s only a matter of time before more connections are revealed.

To stay ahead of the threats, it’s essential to remain vigilant and proactive in your cybersecurity efforts. Regularly update software and systems, implement robust security protocols, and educate yourself on the latest social engineering tactics. By doing so, you’ll be better equipped to defend against these types of attacks – and help keep sensitive information safe from falling into the wrong hands.


Source: Bleeping Computer — 2026-09-28