Back to Feed
Threat IntelligenceSep 28, 2026

Dutch police confirm arrest in ShinyHunters hacking investigation

Dutch police arrest man linked to ShinyHunters hacking group investigation.

Summary

Dutch police have confirmed the arrest of a 24-year-old Amsterdam man in connection with the ShinyHunters hacking group. The suspect, identified as Pepijn van der Stap, previously known as 'Umbreon,' has a history of hacking and blackmail charges. Authorities are investigating a potential link between Van der Stap and ShinyHunters, citing his past use of 'Umbreon' imagery, which the group has also employed. However, ShinyHunters has denied any association with Van der Stap.

Full text

Dutch police confirm arrest in ShinyHunters hacking investigation By Lawrence Abrams September 28, 2026 03:49 PM 0 Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said Monday. Police said the suspect will appear before the Rotterdam District Court on Tuesday, September 29, when further information will also be released. The suspect has been identified by KrebsOnSecurity and DataBreaches as Pepijn van der Stap, a Dutch hacker previously known online as "Umbreon." Van der Stap was previously arrested in January 2023 and charged with hacking and blackmailing more than a dozen companies in the Netherlands and worldwide. He later pleaded guilty and was sentenced to four years in prison, with one year suspended, followed by a three-year probationary period with additional conditions. According to DataBreaches, Van der Stap was arrested again this year on September 15 when a Dutch tactical police unit searched the Amsterdam home he shared with his mother and seized electronic devices. KrebsOnSecurity reports that sources familiar with the investigation confirmed that authorities were examining a possible connection between Van der Stap and ShinyHunters. The report also states that the "Umbreon" identity previously used by Van der Stap could link him to ShinyHunters, which recently used the same Pokémon character in a recent FBI breach and the defacement of the Clop ransomware gang's data leak site. Van der Stap used the "Umbreon" alias and Pokémon imagery on BreachForums as early as 2021. However, the same Umbreon character also appeared a year earlier in a 2020 defacement of the HackForums website, a year before Van der Stap created the "Umbreon" account. Dutch police previously released the voice of a Dutch-speaking man suspected of involvement in the Odido hack. Police said the man called an Odido help desk employee, posing as a member of the company's IT department, and tricked the employee into entering credentials and a verification code into a fake login page, giving the attackers access to internal systems. DataBreaches, which says it has spoken to Van der Stap on multiple occasions, noted that the voice in the recording did not sound like him. A close friend of Van der Stap reportedly reached the same conclusion. When BleepingComputer asked about Van der Stap's arrest, a ShinyHunters representative denied any connection to him. "That individual has no association with us. Frankly, we are laughing," the threat actor told BleepingComputer. This is a developing story. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: ShinyHunters hacks Clop leak site, threatens to extort ransomware gangPasskey-themed phishing attacks lead to Microsoft 365 data theftShinyHunters hackers claim breach of Florida "DAVID" DMV databaseNovocure data breach affects more than 1,400 cancer patientsClop created custom web shell for Windchill data theft attacks

Indicators of Compromise

  • malware — ShinyHunters
  • mitre_attack — T1078
  • mitre_attack — T1566

Entities

ShinyHunters (threat_actor)Umbreon (threat_actor)BreachForums (product)HackForums (product)Odido (product)