Skip to content

Technology·News & analysis

Dutch police arrest a security professional in the ShinyHunters hacking probe

Police arrested a 24-year-old Amsterdam man working in offensive security on suspicion of ties to ShinyHunters, the group behind some of the largest data breaches in recent years.

By Dan Kost aka Poseidan7 min read
Close-up of a person's handcuffed wrists behind their back.
The Squeeze

Dutch police arrested a 24-year-old working in offensive security on suspicion of ties to ShinyHunters, a group behind some of the largest corporate data breaches of the past two years.

That includes the Snowflake customer breach and a 2025 Salesforce campaign hitting roughly 760 organizations, including Google, Adidas, and Cisco. ShinyHunters denies any connection to the suspect. Still, an arrest tied to the group, even a disputed one, is a rare concrete development in an investigation that has mostly produced victim disclosures rather than named suspects.

What to know

  1. Dutch police arrested 24-year-old Pepijn van der Stap, known online as 'Umbreon,' in Amsterdam on September 15 on suspicion of ties to ShinyHunters.
  2. The suspect reportedly worked in a company's offensive security division and had a prior conviction for hacking and extorting more than a dozen companies.
  3. ShinyHunters is linked to breaches at Snowflake, Salesforce, the FBI's systems, and Dutch telecom provider Odido, among dozens of other organizations.
  4. ShinyHunters publicly denied any connection to the arrested individual, saying he 'has no association with us.'
  5. The suspect was scheduled to appear before Rotterdam District Court on September 29.

Dutch police arrested a 24-year-old Amsterdam man on suspicion of ties to ShinyHunters, one of the most active data-extortion groups tracked by security researchers, and the twist is he reportedly had a day job in offensive security.

The arrest

Police arrested Pepijn van der Stap, who goes by the online alias "Umbreon," in Amsterdam on September 15. Officers deployed flashbang grenades during the operation.

  • The suspect: 24 years old, reportedly employed in a company's offensive security division at the time of arrest.
  • The history: convicted in January 2023 for hacking and extorting more than a dozen companies, sentenced to four years with one year suspended.
  • The status: believed to have still been on probation from that earlier conviction when arrested again.

The catch: authorities haven't disclosed specific charges yet or confirmed which, if any, ShinyHunters attacks he's suspected of participating in.

The connection investigators are examining centers on his online alias. "Umbreon" is a Pokémon character, and authorities noted that imagery has recently been used by ShinyHunters itself in its own communications and branding.

That link is circumstantial rather than confirmed, and it's the kind of thin thread that has led to disputed attributions in past hacking investigations.

ShinyHunters pushes back

ShinyHunters publicly denied any connection to the arrested individual. In a statement to reporters, the group said: "That individual has no association with us. Frankly, we are laughing."

That kind of public denial is itself fairly typical behavior for a group willing to talk to journalists and defend its reputation, even mid-investigation. ShinyHunters has a track record of engaging directly with press coverage of its own activities rather than staying entirely silent.

What ShinyHunters has actually done

The group's history explains why any arrest connected to it draws attention. ShinyHunters first became widely known in 2020 for large-scale data theft and extortion, and has escalated significantly since.

The Snowflake breach (2024): the group used stolen contractor credentials to access cloud data belonging to Snowflake customers, exposing records tied to Ticketmaster, AT&T, Santander Bank, and Neiman Marcus, among dozens of other organizations that lacked multi-factor authentication on affected accounts.

The Salesforce campaign (2025): ShinyHunters' most ambitious operation used stolen authentication tokens to access roughly 760 Salesforce customer organizations between August 8 and 18, 2025, exfiltrating an estimated 1.5 billion records. Victims included Google, Adidas, Cisco, Qantas Airways, and Allianz Life.

More recent activity: the group has also been linked to a breach of an FBI system, which ShinyHunters claimed was done to "protect our business," and a February 2026 breach of Dutch telecom provider Odido affecting 6.2 million customers.

ShinyHunters isn't working alone

ShinyHunters' recent campaigns haven't been a solo operation. Security researchers have documented an operational alliance between ShinyHunters, Scattered Spider, and LAPSUS$, three groups that have effectively merged into what's been called "Scattered LAPSUS$ Hunters."

The division of labor: ShinyHunters has confirmed Scattered Spider typically provides initial access to a target's systems, while ShinyHunters itself handles data exfiltration and the eventual data dumps or extortion. LAPSUS$ members have participated directly in high-profile campaigns, including both the Salesforce and Snowflake breaches.

All three groups are believed to draw membership from "The Com," a loosely organized, predominantly English-speaking cybercriminal ecosystem made up mostly of teenagers and people in their twenties who coordinate largely over Telegram and hacking forums rather than through any formal organizational structure.

How the Odido breach happened

The Odido intrusion, which hit a major Dutch telecom provider earlier this year, is especially relevant given this arrest happened on Dutch soil. It reportedly began with a social engineering call: a Dutch-speaking attacker impersonated an IT colleague to convince a customer service employee to hand over system access.

Dutch police released audio of that call publicly on September 8, just a week before this arrest, suggesting investigators had been actively working the Odido case and may have used leads from it in identifying this suspect.

A "reformed hacker" narrative, complicated

Van der Stap's story had already been told once before this arrest, and not as a cautionary tale. His path from convicted hacker to security professional was widely covered in international media as a redemption story, and he had been working as offensive security lead at Neo Security, an Amsterdam-based cybersecurity company.

The earlier case: at his 2023 trial, van der Stap admitted to living what he described as a "Dr. Jekyll and Mr. Hyde" double existence, secretly operating under the "Umbreon" handle while building a legitimate security career. Prosecutors said his earlier hacking and extortion spree earned him between €1.5 million and €2.7 million.

That backstory is exactly why this new arrest is drawing attention well beyond typical hacking-case coverage. Dutch forensic investigators visited his workplace the same night he was arrested, suggesting authorities were specifically examining whether his professional access or tools played any role in the alleged renewed activity.

The insider-threat angle

What makes this arrest notable beyond the ShinyHunters connection is the suspect's reported day job. Working in an offensive security role, testing companies' own defenses professionally, while separately facing suspicion of participating in major criminal breaches, is exactly the kind of dual identity security researchers have long worried about across the industry.

It's not a new pattern. Security research and criminal hacking draw on overlapping technical skills, and several past cases have involved security professionals moonlighting on the wrong side of that line. It's a reminder that professional credentials and criminal suspicion aren't mutually exclusive, however uncomfortable that overlap is for the companies employing people in sensitive security roles.

Part of a bigger Dutch enforcement push

This arrest fits into a broader pattern Dutch authorities have flagged publicly. Police and prosecutors say they've noticed a rise in young, Western cybercriminals focused specifically on data and cryptocurrency theft, distinct from the state-linked threats the Netherlands also tracks.

The scale of the problem: Dutch authorities estimated roughly 2.5 million people in the Netherlands fell victim to cybercrime, online scams, threats, or harassment last year alone, a figure officials have described as part of a rapidly changing threat landscape.

The country's National High Tech Crime Unit handles complex cases involving major fraud, critical infrastructure, or international crime rings, exactly the profile this ShinyHunters-linked case fits. Notably, Dutch police also run a diversion program called Hack_Right, aimed at steering young, technically skilled offenders away from continued criminal hacking, an approach that underscores how often these cases involve very young suspects with genuine technical talent rather than traditional organized crime profiles.

What's next

Van der Stap was scheduled to appear before Rotterdam District Court on September 29, the same day this arrest was more broadly confirmed by Dutch police. Formal charges haven't been made public, and it remains unclear whether prosecutors will pursue a case specifically tied to ShinyHunters activity or something narrower.

The bottom line

An arrest connected to ShinyHunters is a rare concrete development in an investigation that has mostly produced victim disclosures rather than named suspects, but the group's public denial and the circumstantial nature of the "Umbreon" alias link mean this is far from a closed case. Whether Dutch prosecutors can make a ShinyHunters connection stick, or whether this turns out to be a narrower case entirely, should become clearer as the Rotterdam court proceedings continue.

Key facts

Suspect
Pepijn van der Stap, 24 (alias 'Umbreon')
Arrest date
September 15, 2026
Location
Amsterdam, Netherlands
Court date
September 29, 2026, Rotterdam District Court
Prior conviction
January 2023, hacking and extortion of over a dozen companies

Got questions?

Quick answers, plain words

Who was arrested?

24-year-old Pepijn van der Stap of Amsterdam, who goes by the online alias 'Umbreon' and reportedly worked in a company's offensive security division.

When and where did the arrest happen?

Dutch police arrested him in Amsterdam on September 15, 2026, deploying flashbang grenades during the operation.

What is he suspected of?

Involvement with ShinyHunters, a cybercriminal group responsible for numerous large-scale data breaches. Authorities have not disclosed specific charges or confirmed his role in particular attacks.

Has he been in trouble before?

Yes. He was convicted in January 2023 for hacking and extorting more than a dozen companies, receiving a four-year sentence with one year suspended, and was reportedly on probation at the time of this arrest.

Why do investigators suspect a ShinyHunters connection?

Authorities noted his use of 'Umbreon,' a Pokémon character, in his online alias, matching imagery the group has recently used. That connection is circumstantial rather than confirmed.

Did ShinyHunters respond?

Yes. The group denied any association with the arrested individual, telling reporters 'that individual has no association with us. Frankly, we are laughing.'

What has ShinyHunters actually done?

The group has been linked to the 2024 Snowflake customer breach affecting companies like Ticketmaster and AT&T, a 2025 campaign against roughly 760 Salesforce customer organizations including Google, Adidas, and Cisco, a February 2026 breach of Dutch telecom provider Odido affecting 6.2 million customers, and a breach of an FBI system.

What happens next?

The suspect was scheduled to appear before Rotterdam District Court on September 29, 2026. Details on formal charges have not been made public.

SourcesThe Register
Topics and tagsCybersecurity, shinyhunters, cybersecurity, hacking

The daily newsletter

Tech news you'll actually get.

One short email a day. Five minutes. Plain words. The daily email is launching soon. Join the early list.

Free. Early list: we'll email you when the first issue goes out.

More in brief