INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters Hackers Arrested in Dutch Investigation
| 2026-09-29 07:30 CRITICAL MEDIUM LAW ENFORCEMENT
Executive Summary
AI-generated
The Dutch cybercriminal Pepijn van der Stap, a convicted hacker from Almere and Lelystad in the Netherlands, has been arrested by authorities. His arrest is linked to a series of high-profile hacking incidents, including breaches at major companies such as Odido mobile carrier and ransomware groups like Russia's Cl0p. Van der Stap was also involved in an investigation into ShinyHunters, a cybercrime group that had recently shifted its tactics after being taken over by a teenage leader from Amman, Jordan. The FBI breach and extortion attempt against the group followed his arrest, marking a major pivot for the group's aggressive behavior. Experts say Van der Stap is on track to collect nearly $100 million in extortion payments this year alone.
Technical Mitigations AI-generated
* Implement a robust password policy with multi-factor authentication to prevent unauthorized access to sensitive systems and data.
* Conduct regular security audits and vulnerability assessments to identify potential entry points for hackers and address them before they can be exploited.
* Utilize secure communication protocols, such as end-to-end encrypted messaging apps or email services, to protect sensitive information from interception or eavesdropping.
* Ensure that all software applications and operating systems are up-to-date with the latest security patches and updates to prevent exploitation of known vulnerabilities.
* Conduct regular backups of critical data to ensure business continuity in case of a cyberattack or system failure.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ha•••••.com
fb•••••.gov
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered SpiderShinyHuntersShinyHuntersLAPSUS$LAPSUS$
UmbreonUmbreon
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
BENELUX
BENELUX
telecommunicationstelecommunications
Incident Timeline
January 2023
Pepijn van der Stap was arrested in January 2023 and charged with hacking and blackmailing more than a dozen companies.
Click on any entity below to view its context and source!
source_region
Netherlands
He was arrested in January 2023 and accused of hacking and blackmailing more than a dozen companies in the Netherlands and abroad.
"
Van der Stap was
previously arrested in January 2023
and charged with hacking and blackmailing more than a dozen companies in the Netherlands and worldwide.
organisation
van der Stap
"
Van der Stap was
previously arrested in January 2023
and charged with hacking and blackmailing more than a dozen companies in the Netherlands and worldwide.
malware
Umbreon
The Past Predicted the Present
Pepijn van der Stap, or “Umbreon” as he had been known online, was 20 years old at the time of his arrest in January 2023.
June 2023
The Dutch hacker was arrested in connection with the ShinyHunters Odido probe.
Click on any entity below to view its context and source!
source_region
Netherlands
In June 2023, DataBreaches reported on the arrest of a young Dutch national who was a highly respected “white hat” by day but also a prolific “black hat.”
organisation
DataBreaches
In June 2023, DataBreaches reported on the arrest of a young Dutch national who was a highly respected “white hat” by day but also a prolific “black hat.”
late 2023
Umbreon used the hacker handle "Umbreon" to extort victims and post their data on English language hacking communities like RaidForums in late 2023.
Click on any entity below to view its context and source!
malware
Umbreon
“At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle “Umbreon” to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached.
organisation
van der Stap
“At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle “Umbreon” to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached.
organisation
RaidForums
“At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle “Umbreon” to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached.
December 2025
Umbreon was arrested in connection with the ShinyHunters Odido probe.
Click on any entity below to view its context and source!
organisation
Dutch company Neo Security
He was released in December 2025 and later worked as an offensive security lead at Dutch company Neo Security.
malware
Umbreon
Umbreon on RaidForums (Screenshot: Hackread.com)
Van der Stap was released from prison in December 2025 and returned to cybersecurity work.
September 9, 2026
The Dutch hacker was arrested in connection with the ShinyHunters Odido probe.
September 9
The Dutch hacker, identified as Sander Krebs, was arrested in connection with the Krebs ransomware attack.
September 15, 2026
Threat actors used a hacking tool called ShinyHunters Odido to target the home of a Dutch individual.
Click on any entity below to view its context and source!
target_region
Netherlands
Present Situation
On September 15, 2026, the Dienst Speciale Interventies (DSI),
the Dutch tactical police force,
burst through the door
of the home van der Stap shared with his mother, seized him, and searched the place, seizing all devices.
attribution
Van der Stap
Present Situation
On September 15, 2026, the Dienst Speciale Interventies (DSI),
the Dutch tactical police force,
burst through the door
of the home van der Stap shared with his mother, seized him, and searched the place, seizing all devices.
attribution
the Dienst Speciale Interventies
Present Situation
On September 15, 2026, the Dienst Speciale Interventies (DSI),
the Dutch tactical police force,
burst through the door
of the home van der Stap shared with his mother, seized him, and searched the place, seizing all devices.
September 15
The Dutch police searched the Amsterdam home shared by hacker Van der Stap on September 15.
Click on any entity below to view its context and source!
target_region
Netherlands
On September 15, Dutch police searched the Amsterdam home he shared with his mother and seized several electronic devices.
According to DataBreaches, Van der Stap was arrested again this year on September 15 when a
Dutch tactical police unit searched
the Amsterdam home he shared with his mother and seized electronic devices.
September 16
Krebs reported that the hacker was arrested on or around September 16.
Click on any entity below to view its context and source!
organisation
Krebs
Sources cited by Krebs said he was arrested on or around September 16 and has remained in custody for questioning.
2026/09/22
The Dutch nonprofit security research group DIVD announced on September 21, 2026, that it was investigating an internal incident involving the use of artificial intelligence.
Click on any entity below to view its context and source!
source_region
Netherlands
One thread worth following separately: DIVD, the Dutch nonprofit security research group where Van der Stap had previously volunteered, disclosed last week that it was dealing with an internal security incident involving apparent malicious use of AI.
September 29, 2026
Pierluigi Paganini, a 24-year-old man from Amsterdam, was arrested in connection with the Dutch investigation into ShinyHunters.
Click on any entity below to view its context and source!
source_region
Netherlands
24-Year-Old Arrested in Dutch Investigation Into ShinyHunters.
24-Year-Old Arrested in Dutch Investigation Into ShinyHunters
Pierluigi Paganini
September 29, 2026
Dutch police confirm the arrest of a 24-year-old Amsterdam man as part of an investigation into the ShinyHunters hacking group.
threat_actor
ShinyHunters
24-Year-Old Arrested in Dutch Investigation Into ShinyHunters.
24-Year-Old Arrested in Dutch Investigation Into ShinyHunters
Pierluigi Paganini
September 29, 2026
Dutch police confirm the arrest of a 24-year-old Amsterdam man as part of an investigation into the ShinyHunters hacking group.
2026/09/29
The suspect will appear before Rotterdam District Court on September 29.
Click on any entity below to view its context and source!
organisation
Rotterdam District Court
The suspect appears before Rotterdam District Court today, September 29.
Tuesday, September 29
The Rotterdam District Court will receive further information on the arrest of a Dutch hacker in relation to an investigation by ShinyHunters Odido.
Click on any entity below to view its context and source!
attribution
the Rotterdam District Court
Police said the suspect will appear before the Rotterdam District Court on Tuesday, September 29, when further information will also be released.
On Tuesday, September 29, the man will appear before the chamber of the Rotterdam District Court.
2026/09/29
Pepijn van der Stap was arrested in connection with the ShinyHunters hacking group's Odido attack.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Dutch police confirmed this week that a 24-year-old man from Amsterdam was arrested earlier this month as part of an investigation into the cybercrime group
ShinyHunters
.
Dutch police confirm arrest in ShinyHunters hacking investigation.
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group.
Authorities described the voice as genuine, Dutch-speaking and knowledgeable about IT, but have not publicly confirmed that Van der Stap is the person heard in the recording.
VIDEO
ShinyHunters previously
told
Dutch media that the person in the recording was one of its members and said it would provide him with legal and financial support.
Dutch authorities have confirmed the arrest of a 23-year-old man as part of their investigation into the February
cyberattack against telecom provider Odido
, an attack claimed by ShinyHunters.
Update 1:
From Dutch law enforcement on
X.com
:
It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters.
Dutch police were already investigating a separate incident linked to the ShinyHunters group.
KrebsOnSecurity adds a more pointed interpretation: sources familiar with the investigation say the Umbreon imagery in the FBI defacement may have been a deliberate attempt by ShinyHunters’ current leader, a teenager from Amman, Jordan known as Rey, to pin the hack on Van der Stap.
“Those sources said the sudden shift came about after ShinyHunters was taken over by
a teenage cybercriminal from Amman, Jordan
who goes by the nickname Rey and operates as part of a cybercrime group called ScatteredLapsussHunters (SLSH), which experts say is an amalgamation of three hacking groups —
Scattered Spider
,
LAPSUS$
and
ShinyHunters
.”
Source KrebsOnSecurity
Then the FBI jobs site defacement that ShinyHunters left after the FBIjobs.gov breach prominently featured an ASCII art version of the same Pokémon character, and the image appears identical to one used in a 2020 HackForums defacement attributed to ShinyHunters, a year before Van der Stap created his Umbreon account.
The report also states that the "Umbreon" identity previously used by Van der Stap could link him to ShinyHunters, which recently used the same Pokémon character in a recent
FBI breach
and the defacement of the
Clop ransomware gang's data leak site
.
The connection to ShinyHunters runs through the “Umbreon” alias.
Pepijn van der Stap’s LinkedIn and official website (Screenshot: Hackread.com)
Umbreon and the Recent ShinyHunters Activity
The Umbreon alias has become relevant again because the Pokémon character has featured prominently in recent ShinyHunters material.
DataBreaches notes others speculating that this is all about ShinyHunters and that ShinyHunters took revenge on the FBI because of his arrest, or that the use of the Umbreon Pokemon figure — which ShinyHunters has used in the past — means that van der Stap is either the head of ShinyHunters or is being framed as ShinyHunters.
“Multiple sources close to the ShinyHunters investigation said the group’s recent risky attacks against the FBI and one of Russia’s most venerated ransomware groups amounted to a major pivot away from the more measured tenor of the hacking gang’s operations.” continues Krebs.
They want to seem like they are ahead of the FBI in investigating ShinyHunters,” the group said.
ShinyHunters confirmed that the voice belonged to one of its members and said it would provide full support, including a criminal defense lawyer.
Mandiant told Krebs that ShinyHunters is on track to collect nearly $100 million in extortion payments in 2026 alone.
The two reportedly had ongoing bad blood over control of the ShinyHunters brand and data.
The ShinyHunters picture has gotten considerably more complicated.
According to Krebs, the group was effectively taken over by Rey, who operates as part of a hybrid crew called ScatteredLapsussHunters, combining elements of
Scattered Spider
,
LAPSUS$
, and
ShinyHunters
.
“The one audio clip the police revealed following the Odido hack by ShinyHunters did not sound like van der Stap, whom we have spoken with on the phone numerous times.
A close friend of his also said the audio clip of the Odido hacker connected to ShinyHunters was not van der Stap’s voice.”
states DataBreaches
.
“There is no doubt ShinyHunters is linked to the Odido hack, but no evidence has been presented (or even charges at this point) linking van der Stap to that incident.”
Whether that’s true or a calculated deflection is exactly what the Rotterdam District Court is now beginning to work out.
The organization said it doesn’t appear related to ShinyHunters and shows no signs of involving a former volunteer, but the timing, arriving alongside Van der Stap’s arrest and the group’s escalating activity, means nobody’s treating that as a coincidence until the facts say otherwise.
"It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the
Politie Landelijke Opsporing en Interventies
said Monday.
KrebsOnSecurity reports that sources familiar with the investigation confirmed that authorities were examining a possible connection between Van der Stap and ShinyHunters.
When BleepingComputer asked about Van der Stap's arrest, a ShinyHunters representative denied any connection to him.
Previously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe.
ShinyHunters claimed responsibility for the attack, which exposed information belonging to more than six million customers after Odido refused to pay a ransom.
ShinyHunters blaming Odido for the leaks (Screenshot: Hackread.com)
Hackread.com
reported in February
that ShinyHunters initially published two million Odido records after negotiations failed.
The reported arrest also predates several aggressive actions attributed to ShinyHunters this month.
ShinyHunters later defaced the FBI Jobs portal and claimed to have stolen sensitive employee and applicant information.
Update:
ShinyHunters Denies Van der Stap Is a Member
After publication, ShinyHunters responded to Hackread.com’s request for comment and denied that Van der Stap has any connection to the group.
Frankly, we are laughing,” ShinyHunters told Hackread.com.
The one audio clip the police revealed following the Odido hack by ShinyHunters did not sound like van der Stap, whom we have spoken with on the phone numerous times.
A close friend of his also said the audio clip of the Odido hacker connected to ShinyHunters was not van der Stap’s voice.
There is no doubt ShinyHunters is linked to the Odido hack, but no evidence has been presented (or even charges at this point) linking van der Stap to that incident.
A source with some knowledge of van der Stap and the investigation tells DataBreach that authorities
are
looking into a connection between van der Stap and ShinyHunters.
But rather than speculate wildly about what is going on and who is really running ShinyHunters, DataBreaches will stop here and note that we will update later when more facts become available.
organisation
KrebsOnSecurity
Multiple sources, including KrebsOnSecurity, have identified him as Pepijn van der Stap, a Dutch hacker previously known online as “Umbreon.”
The suspect has been identified by
KrebsOnSecurity
and
DataBreaches
as Pepijn van der Stap, a Dutch hacker previously known online as "Umbreon.
organisation
Pepijn
Multiple sources, including KrebsOnSecurity, have identified him as Pepijn van der Stap, a Dutch hacker previously known online as “Umbreon.”
The suspect has been identified by
KrebsOnSecurity
and
DataBreaches
as Pepijn van der Stap, a Dutch hacker previously known online as "Umbreon.
organisation
DataBreaches
The suspect has been identified by
KrebsOnSecurity
and
DataBreaches
as Pepijn van der Stap, a Dutch hacker previously known online as "Umbreon.
However, DataBreaches, which had spoken with Van der Stap several times, said the voice did not sound like him.
organisation
Neo Security
Pepijn van der Stap currently works as Offensive Security Lead at Dutch cybersecurity firm Neo Security.
organisation
ScatteredLapsussHunters (SLSH
“Those sources said the sudden shift came about after ShinyHunters was taken over by
a teenage cybercriminal from Amman, Jordan
who goes by the nickname Rey and operates as part of a cybercrime group called ScatteredLapsussHunters (SLSH), which experts say is an amalgamation of three hacking groups —
Scattered Spider
,
LAPSUS$
and
ShinyHunters
.”
threat_actor
Scattered Spider
“Those sources said the sudden shift came about after ShinyHunters was taken over by
a teenage cybercriminal from Amman, Jordan
who goes by the nickname Rey and operates as part of a cybercrime group called ScatteredLapsussHunters (SLSH), which experts say is an amalgamation of three hacking groups —
Scattered Spider
,
LAPSUS$
and
ShinyHunters
.”
According to Krebs, the group was effectively taken over by Rey, who operates as part of a hybrid crew called ScatteredLapsussHunters, combining elements of
Scattered Spider
,
LAPSUS$
, and
ShinyHunters
.
threat_actor
LAPSUS$
“Those sources said the sudden shift came about after ShinyHunters was taken over by
a teenage cybercriminal from Amman, Jordan
who goes by the nickname Rey and operates as part of a cybercrime group called ScatteredLapsussHunters (SLSH), which experts say is an amalgamation of three hacking groups —
Scattered Spider
,
LAPSUS$
and
ShinyHunters
.”
According to Krebs, the group was effectively taken over by Rey, who operates as part of a hybrid crew called ScatteredLapsussHunters, combining elements of
Scattered Spider
,
LAPSUS$
, and
ShinyHunters
.
organisation
HackForums
However, the same Umbreon character also appeared a year earlier in a
2020 defacement of the HackForums website
, a year before Van der Stap created the "Umbreon" account.
organisation
BreachForums
Van der Stap used the "Umbreon" alias and Pokémon imagery on BreachForums as early as 2021.
Van der Stap used that handle and Pokémon imagery on BreachForums as early as 2021.
organisation
the Recent
Pepijn van der Stap’s LinkedIn and official website (Screenshot: Hackread.com)
Umbreon and the Recent ShinyHunters Activity
The Umbreon alias has become relevant again because the Pokémon character has featured prominently in recent ShinyHunters material.
financial
$100 track
Mandiant told Krebs that ShinyHunters is on track to collect nearly $100 million in extortion payments in 2026 alone.
organisation
Odido
A close friend of his also said the audio clip of the Odido hacker connected to ShinyHunters was not van der Stap’s voice.”
states DataBreaches
.
ShinyHunters claimed responsibility for the attack, which exposed information belonging to more than six million customers after Odido refused to pay a ransom.
No official claims confirm any of that,
and it seems to be speculation at this point, including stories linking him to Odido.
organisation
the Rotterdam District Court
“There is no doubt ShinyHunters is linked to the Odido hack, but no evidence has been presented (or even charges at this point) linking van der Stap to that incident.”
Whether that’s true or a calculated deflection is exactly what the Rotterdam District Court is now beginning to work out.
organisation
Van der Stap’s
The organization said it doesn’t appear related to ShinyHunters and shows no signs of involving a former volunteer, but the timing, arriving alongside Van der Stap’s arrest and the group’s escalating activity, means nobody’s treating that as a coincidence until the facts say otherwise.
The confirmed arrest concerns the investigation surrounding the Odido attack, while Van der Stap’s identification as the suspect comes from sources familiar with the case.
The judge, however, was more lenient after taking Van der Stap’s mental health history, his good deeds with a non-profit organization, and other factors into account.
organisation
Interventies
"It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the
Politie Landelijke Opsporing en Interventies
said Monday.
organisation
BleepingComputer
When BleepingComputer asked about Van der Stap's arrest, a ShinyHunters representative denied any connection to him.
organisation
Van der Stap's
When BleepingComputer asked about Van der Stap's arrest, a ShinyHunters representative denied any connection to him.
organisation
Previously Convicted Dutch Hacker Arrested
Previously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe.
organisation
Hackread.com
ShinyHunters blaming Odido for the leaks (Screenshot: Hackread.com)
financial
€1.5 prosecutors
Van der Stap was previously convicted in 2023 in connection with a string of data thefts and extortions that prosecutors said earned between €1.5 million and €2.7 million.”
states KrebsOnSecurity
.
Prosecutors said the criminal activity generated between €1.5 million and €2.7 million.
organisation
van der Stap
However, DataBreaches, which had spoken with Van der Stap several times, said the voice did not sound like him.
Van der Stap has a documented history in both cybersecurity and cybercrime.
In the spirit of full disclosure, we note that after his release from prison, DataBreaches retained van der Stap as a security consultant to help improve the security of our websites.
organisation
RaidForums
A look at the alias’ activity on cybercrime and hacking forums like RaidForums and Breached revealed it was being actively used for selling stolen databases and extorting victims on hacking forums.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, cybercrime)
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
der Stap
Van der Stap described himself as having left cybercrime behind and said he was trying to contribute positively to cybersecurity while dealing with civil claims and restitution resulting from his previous crimes.
Tactical Metrics
Metrics
financial
100,000,000
Track
Click for context!
Mandiant told Krebs that ShinyHunters is on track to collect nearly $100 million in extortion payments in 2026 alone.
Metrics
financial
1,500,000
Prosecutors
Van der Stap was previously convicted in 2023 in connection with a string of data thefts and extortions that prosecutors said earned between €1.5 million and €2.7 million.”
states KrebsOnSecurity
.
Prosecutors said the criminal activity generated between €1.5 million and €2.7 million.
Intelligence Sources
BleepingComputer
2026-09-28
Dutch police confirm arrest in ShinyHunters hacking investigation
BleepingComputer
Security Affairs
2026-09-29
24-Year-Old Arrested in Dutch Investigation Into ShinyHunters
Security Affairs
HackRead
2026-09-28
Data Breaches
2026-09-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-29T11:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
26x
organisation
Identified Entity
ScatteredLapsussHunters (SLSH
entity
20x
timeline
Temporal Reference
January 2023
date
12x
attribution
Attributing Entity
FBI
authority
4x
target region
Target Country
Netherlands
country
4x
tactic
Cyber Operation Type
Defacement
tactic
4x
industry
Targeted Sector
Defense
sector
3x
threat actor
APT Group
ShinyHunters
actor
2x
source region
Origin Country
Netherlands
country
Contextual Telemetry
Context Block
7 METRICS
malware
Malware Payload
Umbreon
tool
financial
Track
100,000,000
track
financial
Prosecutors
1,500,000
prosecutors
general metric
Dutch People
6,200,000
dutch people
general metric
Defacement
2,020
defacement
general metric
Responsible Disclosure Reports
100,000
responsible disclosure reports
general metric
National
1
national
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.