Dutch authorities have arrested 24-year-old Pepijn van der Stap on suspicion of assisting the hacking group ShinyHunters, according to reporting cited by local media and KrebsonSecurity. Van der Stap, who previously operated online under the name “Umbreon,” was detained on September 16 and is expected in Rotterdam District Court on September 29.

The arrest has drawn added attention because van der Stap is already a convicted cybercriminal. He had earlier been found guilty over data theft and extortion, received a four-year suspended sentence, and was released in December 2025.

A known figure in Dutch cybercrime cases

Van der Stap has been publicly associated with hacking and extortion activity under the alias Umbreon. Despite that history, he had also held roles in the cybersecurity field, including work at startup Hadrian and volunteer work with the Dutch Institute for Vulnerability Disclosure.

At the time of the new arrest, he was serving as offensive security lead at Neo Security. He had reportedly described himself to journalists as a reformed offender before being taken into custody for questioning and later formally arrested in connection with the ShinyHunters probe.

Why investigators are looking at ShinyHunters links

The current case centers on suspected assistance to ShinyHunters, a group tied to multiple high-profile breaches. The source report says local media also indicated that US authorities are involved in the matter, though the precise nature of that involvement was not detailed.

Six days after van der Stap’s arrest, ShinyHunters claimed responsibility for an intrusion involving the data of 5,000 FBI agents. In that same incident, the FBI’s jobs page was reportedly altered to show an image of Umbreon, placing van der Stap’s online identity directly into the public narrative around the hack.

Questions around motive and attribution

According to sources cited in the report, ShinyHunters is led by a teenager in Amman, Jordan known as “Rey.” The same reporting says the group had reportedly merged with Scattered Spider and LAPSUS$ under the name ScatteredLapsussHunters.

Those sources also claimed Rey had an ongoing dispute with van der Stap. If accurate, the appearance of Umbreon’s image in the FBI-related attack may have been intended to redirect suspicion toward him rather than serve as proof of his role. The reporting does not present that as confirmed fact, and the allegation remains part of an active investigation.

Broader backdrop and next step

ShinyHunters has also been linked to the February hack of Dutch telecom provider Odido. In that breach, personal information including bank account and passport numbers of six million customers was reportedly leaked, making the group a significant focus for Dutch investigators.

For now, the confirmed next step is van der Stap’s court appearance in Rotterdam on September 29. The case remains at the suspicion stage, and the available reporting does not establish whether prosecutors believe he directly participated in any specific ShinyHunters breach.

Source: protos.com