Follow
Subscribe via Email!

Enter your email address to subscribe to this platform and receive notifications of new posts by email.

Dutch Police Arrest ShinyHunters Hacker in Murder Inquiry

Dutch police detained 24-year-old Pepijn van der Stap in Amsterdam on September 15, 2026, investigating the alleged ShinyHunters hacker for corporate extortion and two planned contract killings.
Illustration representing corporate data breaches in the ShinyHunters hacker investigation.

Dutch police and federal agents captured an alleged ShinyHunters hacker during an unannounced morning raid in Amsterdam, seizing encrypted hardware and uncovering digital records tied to international extortion campaigns. Brett Leathermann, head of the FBI Cyber Division, announced that the Dutch High Tech Crime Unit moved decisively to preserve critical forensic data across several compromised machines. While detectives initially pursued the suspect for participating in an organized extortion ring, subsequent digital analysis revealed planning materials for two contract killings abroad [1]. The Rotterdam District Court scheduled his initial formal hearing for September 29, 2026 [3].

Tactical Raid Captures Alleged ShinyHunters Hacker

The coordinated operation commenced on September 15, 2026, when tactical police units searched the Amsterdam residence that the 24-year-old suspect shared with his mother [4]. Concurrently, Dutch officers executed a high-risk entry involving flash-bang grenades at the Amsterdam offices of Neo Security, where the suspect worked as chief technology officer and offensive security lead [1]. European technology publications reported that law enforcement targeted the corporate suite to secure live server environments before remote access credentials could be altered [2]. Authorities detained the alleged ShinyHunters hacker on suspicion of participating in a criminal organization [1].

Brett Leathermann confirmed that Dutch investigators acted rapidly to safeguard vital evidence before suspects could initiate automated deletion scripts or remote cryptographic locks across their infrastructure. International prosecutors hold the ShinyHunters syndicate responsible for intrusions affecting more than 140 commercial organizations worldwide, siphoning corporate records and threatening mass publication if victims refuse extortion payments. Documented victims cited by law enforcement include Ticketmaster, adult entertainment platform Pornhub, and American telecommunications carrier AT&T [1]. Dutch police seized multiple computing devices during the coordinated premises searches [4]. The bureau characterized the Amsterdam detention as a severe disruption against syndicate command, pledging continued cooperation with European partners to pursue remaining conspirators across multiple jurisdictions [1].

Rotterdam judges ordered the suspect remanded into custody for at least 90 days. Detectives continue analyzing his confiscated workstations [1].

Handcuffs illustrating the detention of an alleged ShinyHunters hacker by Dutch law enforcement
Dutch tactical police detained an Amsterdam suspect during an international cybercrime probe. (Credit: BleepingComputer)

Seized Laptops Reveal Evidence of Contract Murders

Forensic specialists inspecting the confiscated laptop uncovered information that altered the scope of the prosecution entirely. Politie Landelijke Opsporing en Interventies reported finding detailed records pointing toward two separate contract murders intended to be executed outside the Netherlands. Dutch authorities immediately separated the violence inquiry from the primary digital extortion docket tied to the ShinyHunters hacker to expedite urgent cross-border protective measures [1].

Judicial officials declined to reveal prospective victim names or the targeted foreign nations while detectives verify encrypted operational logs. Legal representatives noted that violent criminal conspiracies remain distinct from the computer intrusion allegations leveled against the wider collective. Why did assassination plans emerge within a corporate data extortion case? Digital extortion groups rarely maintain direct connections with physical hit contracts [1].

Detectives also reviewed potential links between the detainee and an intrusion at Dutch telecommunications provider Odido [1]. Dutch police had previously broadcast an audio clip of a Dutch-speaking fraudster who called an Odido help desk employee, posed as internal technical support, and captured authentication credentials through a fraudulent login portal [4]. Law enforcement confirmed that the 24-year-old Amsterdam man faces no charges concerning the Odido breach [1]. Analysis by DataBreaches.Net and personal associates determined that the published voice recording does not match the suspect. The telephone caller sounded distinctly older [4].

Dutch police appeal video regarding telecom intrusions tied to the ShinyHunters hacker inquiry
Dutch police released an audio recording seeking public assistance to identify an Odido network intruder. (Credit: Politie Landelijke Opsporing & Interventies)

Inside the Dual Career of Pepijn van der Stap

Investigative reporter Brian Krebs of KrebsOnSecurity and DataBreaches.Net identified the arrested individual as Pepijn van der Stap, an Amsterdam resident known on underground message boards by the moniker Umbreon [3, 4]. Van der Stap previously received a four-year prison term in January 2023 after pleading guilty to hacking and extorting more than a dozen companies in the Netherlands and abroad. Judges suspended one year of that sentence, mandating three years of supervised probation. He avoided complete isolation [4].

Following his 2023 legal proceedings, Van der Stap obtained employment across respected defensive technology firms. He worked as an offensive security specialist at Hadrian and contributed volunteer technical expertise to the Dutch Institute for Vulnerability Disclosure (DIVD) before accepting his executive role at Neo Security. In a June 2023 interview with DataBreaches.Net, Van der Stap recounted experiencing severe psychological strain while maintaining an outward facade of lawful employment while running secret criminal operations. He recognized the extreme risks [3].

Van der Stap described the intense dread of detection that accompanied his dual professional life. ‘Working at Hadrian and volunteering at DIVD made me more paranoid about keeping up appearances, and I actually felt more pressure and paranoia because I was working such long hours,’ Van der Stap stated. He acknowledged that paranoia eventually consumed his daily routine: ‘So yes, I was doing more lawful work and much less illegal work but I became more paranoid about getting caught. The paranoia became so extreme that I was expecting a knock on the door at any time.’ On LinkedIn, he wrote that ‘knowledge is for building and protecting, not breaking [3].’

Cybersecurity concept graphic depicting systems compromised by a ShinyHunters hacker syndicate
Investigators traced multiple corporate network intrusions linked to the international extortion syndicate. (Credit: The Hacker News)

Syndicate Denies Ties Following the ShinyHunters Arrest

Representatives speaking for the criminal collective dismissed Dutch police statements shortly after news of the detention surfaced. ‘That individual has no association with us. Frankly, we are laughing,’ a syndicate spokesperson stated in written remarks to The Hacker News and BleepingComputer [3, 4]. The organization alleged that Dutch investigators fabricated links to the gang to restore institutional prestige after encountering public embarrassment over the unresolved Odido investigation. They rejected every police claim [3].

Digital identity breadcrumbs uncovered by independent analysts nevertheless link the suspect’s moniker to past group campaigns. Van der Stap utilized the Umbreon screen name and related Pokémon imagery on BreachForums as early as 2021. However, archival forum records show that an identical Umbreon character appeared in a 2020 defacement targeting HackForums, a full calendar year before Van der Stap registered his BreachForums profile. More recently, threat actors deployed that same Pokémon visual branding during a breach of FBI portals and the retaliatory defacement of data leak servers operated by the Clop ransomware cartel [4].

The syndicate contended that European law enforcement constructed a false association to manufacture international success. ‘Dutch police are chasing attention and public favour after the massive embarrassment in result of the Odido hack,’ the spokesperson told The Hacker News. ‘They want to seem like they are ahead of the FBI in investigating ShinyHunters [3].’ Dutch authorities maintained that technical telemetry recovered from seized hardware directly substantiates their criminal organization charges, linking the alleged ShinyHunters hacker directly to syndicate operations [1].

Enterprise infrastructure monitoring graphic associated with the ShinyHunters hacker investigation
Law enforcement operations targeted digital infrastructure tied to widespread extortion campaigns. (Credit: The Register)

Federal Fallout Over Compromised Government Networks

The Amsterdam arrest occurred amidst escalating fallout regarding an aggressive breach of United States federal infrastructure [1]. ShinyHunters claimed responsibility for infiltrating the Federal Bureau of Investigation job application portal at apply.fbijobs.gov, exfiltrating terabytes of personnel data belonging to applicants and special agents [3]. In an analytical overview, our newsroom documented the federal investigation into the FBI breach claims after administrators discovered widespread database compromises [1]. Cross-border investigators connected this campaign to wider global cybercrime syndicate operations targeting corporate infrastructure [3]. The Bureau faced serious embarrassment [1].

Internal communications alerted FBI employees that full names, residential addresses, job titles, and Social Security numbers were exposed during the unauthorized network access. Sifted samples containing approximately 5,000 personnel files revealed even more intrusive disclosures, including psychiatric evaluations as well as mandatory blood and urine test results. Counterintelligence specialists warned that foreign intelligence services possessing such sensitive medical records could exert coercive pressure on federal undercover operatives abroad. The stolen data posed severe risks [1].

Speaking to 404 Media, syndicate members characterized the federal intrusion as a publicity campaign to counter government disinformation rather than a financial extortion scheme. ‘We proved our points on several occasions,’ a spokesperson declared to 404 Media, insisting the crew will not publish the government data [1, 3]. Although intruders claimed they leveraged an unpatched zero-day flaw in Oracle PeopleSoft, technical assessments revealed they used URL-encoding methods to bypass web application firewall (WAF) mitigations for CVE-2026-35273 [3]. The FBI Cyber Division reaffirmed that prosecutors will pursue every syndicate affiliate across international borders as Dutch authorities assemble their trial dossier [1].

Sources
  1. ONLINE NEWS Whittaker, Z. (2026, September 29). Dutch police arrest ShinyHunters hacker accused of planning two murders. TechCrunch. [Article Link]
  2. ONLINE NEWS Jones, C. (2026, September 29). Dutch police arrest ‘security pro’ in ShinyHunters probe. The Register. [Article Link]
  3. ONLINE NEWS The Hacker News. (2026, September 29). Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation. The Hacker News. [Article Link]
  4. ONLINE NEWS Abrams, L. (2026, September 28). Dutch police confirm arrest in ShinyHunters hacking investigation. BleepingComputer. [Article Link]

Leave a Comment

Related Posts
Total
0
Share