Dutch police have confirmed the arrest of a 24-year-old man from Amsterdam as part of an ongoing investigation into the ShinyHunters hacking group. The Politie Landelijke Opsporing en Interventies unit stated in a post on X that the arrest occurred this month, and said the suspect is expected to appear before the Rotterdam District Court on Tuesday, September 29, when more details will be released.
KrebsOnSecurity and DataBreaches have identified the suspect as Pepijn van der Stap, a Dutch hacker previously known online by the alias “Umbreon.” Van der Stap was arrested once before, in January 2023, for hacking and blackmailing more than a dozen companies in the Netherlands and abroad. He pleaded guilty and received a four-year sentence, with one year suspended, followed by a three-year probationary period.
According to DataBreaches, a Dutch tactical police unit raided the Amsterdam home Van der Stap shares with his mother on September 15, seizing electronic devices. Sources familiar with the case reportedly told KrebsOnSecurity that investigators are examining a possible link between Van der Stap and ShinyHunters, partly based on the “Umbreon” identity and Pokemon-themed imagery he used on BreachForums as early as 2021, the same character ShinyHunters recently used during its defacement of the Clop ransomware gang’s leak site and a breach affecting the FBI.
The connection is not conclusive. The same Umbreon character appeared in a 2020 defacement of the HackForums website, a year before Van der Stap is known to have adopted the alias, raising questions about whether the imagery originated with him or was later reused by others.
A ShinyHunters representative denied any association with the arrested suspect when contacted by BleepingComputer, stating the individual has no connection to the group.
The arrest also comes amid a separate but related Dutch investigation into the Odido breach, in which a Dutch-speaking attacker posed as an internal IT staffer to trick a help desk employee into entering credentials and a verification code on a fake login page. DataBreaches, which says it has spoken with Van der Stap on multiple occasions, along with a close friend of his, both concluded that the voice in a recording police released of the suspected Odido caller does not match Van der Stap.
What Security Teams Should Watch
- This remains a developing investigation with unconfirmed attribution to ShinyHunters.
- Organizations targeted by ShinyHunters or Clop-linked extortion campaigns should monitor for updates from the Rotterdam court proceedings.
- Help desk social engineering, as seen in the Odido case, continues to be an effective initial access vector and warrants renewed verification procedures for credential reset requests.
