By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Dutch Police Arrest Alleged ShinyHunters Associate

Dutch police arrested 23-year-old Pepijn van der Stap on suspicion of facilitating data thefts and extortions attributed to the hacker group ShinyHunters. The arrest, which occurred this month, was followed by a significant increase in ShinyHunters' cybercriminal activities, including breaches targeting the FBI and extortion attempts against the Russian ransomware group Cl0p. Van der Stap, identified as a convicted cybercriminal from Almere and Lelystad, Netherlands, was previously found guilty in 2023 for his involvement in data theft and extortion schemes that prosecutors estimated generated between €1.5 million and €2.7 million. During his 2023 trial, van der "Umbreon" Stap acknowledged a dual life, using the hacker alias "Umbreon" to extort victims and leak their data on platforms such as RaidForums and Breached. Concurrently, he worked as a software engineer at Hadrian, a cybersecurity startup based in Amsterdam, and volunteered with the Dutch Institute for Vulnerability Disclosure (DIVD), a non-profit organization focused on security research. Evidence presented during his trial included van der Stap's online activity as "Umbreon," specifically the sale of a database containing information on 2.3 million individuals from the Netherlands on RaidForums in September 2021. He admitted to his illicit activities and received a four-year prison sentence, with one year suspended. Van der Stap chose to remain in custody during part of his legal proceedings, citing psychological issues, including PTSD stemming from childhood trauma, and sought treatment. He was released from prison in December 2025. The escalation of ShinyHunters' attacks following van der Stap's apprehension highlights the group's operational resilience and the potential impact of apprehending key members. ShinyHunters has been a prolific threat actor, responsible for numerous high-profile data breaches affecting various organizations globally. The group's modus operandi typically involves exfiltrating sensitive customer data and then extorting the compromised companies for payment to prevent the data's public release. The FBI breach, in particular, signifies a concerning development, given the sensitive nature of the information held by law enforcement agencies. Similarly, the targeting of Cl0p, itself a notorious ransomware collective, suggests a complex and potentially retaliatory dynamic within the cybercriminal underground. The Dutch Institute for Vulnerability Disclosure (DIVD) is known for its work in identifying and reporting security vulnerabilities to organizations, aiming to improve overall cybersecurity posture. Hadrian, the cybersecurity startup where van der Stap was employed, likely focuses on providing security solutions or services to businesses. The case underscores the challenges law enforcement faces in combating sophisticated cybercrime networks and the difficulties in permanently dismantling them, especially when individuals with specialized skills are involved.
Original source — read the full reporting at the publisher:
Read on Krebs on SecurityGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.