Dutch Police Arrest ShinyHunters Suspect, 24 [2026] | #cybercrime | #infosec


Dutch police confirmed on Monday that a 24-year-old man from Amsterdam was arrested earlier this month in an investigation tied to ShinyHunters, one of the most prolific data-extortion crews operating today. The suspect was scheduled to appear before the Rotterdam District Court on Tuesday, September 29, 2026, the same day the FBI continues to sort through fallout from a breach of its own job-application portal, apply.fbijobs.gov.

Dutch authorities have not publicly named the suspect, describing him only by age and city in an official statement. Multiple outlets, including KrebsOnSecurity and Security Affairs, have reported that sources familiar with the case identified him as Pepijn van der Stap. Neither identity claim has been confirmed by police, and nothing here should be read as an established legal fact until a Dutch court says otherwise.

What Dutch Police Actually Said

The statement from Dutch police was narrow by design. Investigators said only that “it is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters.” That single sentence is the entirety of what law enforcement has put on record. No charges were listed, no evidence was described, and no alias or legal name appeared in the release.

That restraint matters. Dutch prosecutors tend to say little before a first court appearance, partly to avoid tainting a case and partly because pretrial detention hearings in the Netherlands are often closed to the public. The September 29 session in Rotterdam falls into that category, as NL Times reported. It determines whether the suspect stays in custody while the investigation continues, not whether he is guilty of anything. Readers searching for a verdict or a formal charge sheet won’t find one yet, because neither has been made public.

The gap between what police confirmed and what media outlets have layered on top of that confirmation is the real story here. This is common in fast-moving cybercrime cases, where reporters chase named sources faster than institutions release official statements. It’s worth tracking which claims sit on which side of that line, because the two categories carry very different weight.

The Neo Security Connection

The most concrete non-police detail in this case comes from a named executive at a named company. Benjamin Korper, described as the boss at Amsterdam-based security firm Neo Security, told reporters that the arrested man worked there as the company’s offensive security lead. That’s a meaningful detail on its own: it means the person under investigation had, at minimum, professional-grade penetration testing skills and access to client engagements before his arrest.

Offensive security roles sit at an uncomfortable intersection. The same red-team techniques used to legitimately probe a client’s network defenses look, on a packet capture, almost identical to a criminal intrusion. That overlap is exactly why security firms run background checks and internal audits before and during employment, and why an arrest like this one triggers immediate scrutiny of every engagement the employee touched. Korper’s public comments suggest Neo Security is now doing that review, though the company has not disclosed the scope or timeline of it.

This is not the first time a working security professional has turned out to have a parallel life on the other side of the law. It’s a recurring failure mode in the industry, and it’s one reason enterprise buyers increasingly ask vendors for continuous vetting rather than a one-time hire-day check.

ShinyHunters: A Group That Rarely Stays Quiet

ShinyHunters has built a reputation over roughly six years as a group that steals data first and negotiates second, often skipping ransomware encryption entirely in favor of straight extortion. The name surfaced publicly around 2020 tied to bulk database sales on criminal forums, and it kept resurfacing through a string of headline breaches, including the 2024 Ticketmaster incident and the wave of Snowflake-customer intrusions that hit dozens of companies through compromised cloud credentials rather than a flaw in Snowflake’s own platform.

The group’s playbook has stayed consistent: find a soft entry point, exfiltrate as much as possible before anyone notices, then threaten public release unless paid. That model doesn’t require sophisticated malware. It requires patience, social engineering, and a willingness to sit on stolen data until a deadline creates leverage. Shattered.io covered exactly that pattern earlier this month when the FBI declared a cyber incident and ShinyHunters set a seven-day deadline tied to the jobs-portal breach, and again when the bureau confirmed it was formally investigating the claim. It’s a similar approach to the one used against thousands of websites in the unrelated Brevo supply-chain hack that leaned on ClickFix-style social engineering to spread access at scale.

What makes an arrest inside a group like ShinyHunters unusual is not the crime itself. It’s the fact that an actual name, city, and workplace got attached to a group that normally operates behind aliases and encrypted chat handles. Reports say the suspect previously used the online alias “Umbreon,” a detail Dutch police have not confirmed but that has appeared consistently across coverage from outlets including Security Affairs.

The FBI Jobs-Portal Breach, Separately

The link between this arrest and the FBI breach is real but looser than some headlines suggest. ShinyHunters claimed responsibility for breaching apply.fbijobs.gov and stealing personnel data tied to job applicants and staff. Shattered.io reported on that claim when the jobs portal went dark for six days and a PeopleSoft vulnerability was cited as the likely entry point, and followed up on the broader fallout when a hacker claim put the number of exposed medical files at 60,000.

None of the available reporting establishes that the Amsterdam suspect personally took part in the FBI intrusion. He is under investigation in connection with ShinyHunters as a group, and ShinyHunters is the group that claimed the FBI breach. Those are two separate facts that a lot of casual coverage has blurred into one. Until Dutch or American investigators say otherwise, the correct framing is that this arrest touches the same criminal network, not that it closes the FBI case.

The FBI itself has not issued a statement tying the Amsterdam arrest to its own breach investigation. That silence is typical. Federal agencies rarely comment on foreign law enforcement actions involving suspects who have not been charged domestically, and cross-border cybercrime cases can take months or years to produce a formal indictment even after an arrest happens overseas. BleepingComputer’s coverage of the arrest reached the same conclusion: the two cases run on parallel tracks that have not yet been formally joined.

Timeline of the Case

DateEventSource
Early September 2026ShinyHunters claims breach of apply.fbijobs.gov, alleging theft of FBI personnel dataShinyHunters public claim
Mid-September 2026Dutch police arrest a 24-year-old Amsterdam man in a ShinyHunters-linked probe (exact date not officially confirmed)Dutch police statement
September 2026Neo Security’s Benjamin Korper confirms the arrested employee worked as the firm’s offensive security leadNeo Security statement
September 2026Media reports name the suspect as Pepijn van der Stap and cite the alias “Umbreon” (unconfirmed by police)KrebsOnSecurity, Security Affairs
Tuesday, September 29, 2026Suspect scheduled to appear before the Rotterdam District CourtDutch police statement

Confirmed Versus Unconfirmed: A Reality Check

Coverage of fast-developing hacking cases tends to flatten confirmed police statements and speculative reporting into a single narrative. It’s worth pulling those apart explicitly, because the distinction changes how seriously a claim should be taken and how it should be repeated.

ClaimStatus
24-year-old man from Amsterdam arrested this monthConfirmed by Dutch police
Suspect scheduled to appear in Rotterdam District Court September 29Confirmed by Dutch police
Arrest tied to a ShinyHunters investigationConfirmed by Dutch police
Suspect’s identity as Pepijn van der StapReported by media, not confirmed by police
Suspect worked as offensive security lead at Neo SecurityConfirmed by Neo Security’s Benjamin Korper
Suspect used the alias “Umbreon”Reported by media, not confirmed by police
Suspect personally participated in the FBI jobs-portal breachUnconfirmed
Suspect was a ShinyHunters memberUnconfirmed
Exact arrest dateUnconfirmed; police say only “this month,” some reports cite mid-September
Total scope of data taken in the FBI breachUnconfirmed

Why This Case Is Different From a Typical Cybercrime Arrest

Most ShinyHunters-linked law enforcement actions play out as sealed indictments and quiet plea deals months after the breach itself fades from headlines. This one is different because the timing overlaps almost exactly with an active, unresolved breach at a US federal agency. That overlap puts pressure on multiple institutions at once: Dutch prosecutors building a domestic case, Neo Security managing reputational exposure over a client-facing employee, and the FBI still working out how apply.fbijobs.gov was compromised in the first place.

There’s also a trust dimension that doesn’t usually attach to cybercrime arrests. Offensive security firms sell assurance. Clients pay Neo Security and companies like it specifically because they claim to test defenses more rigorously and more ethically than an attacker would. An employee under investigation for alleged ties to a criminal extortion group undercuts that pitch regardless of the outcome of the case, which is why Korper moved quickly to say an external review had so far found no evidence the suspect attacked Neo Security’s own clients.

Market and Industry Impact

The direct market impact of a single arrest is usually small, but this one lands at a moment when enterprise buyers are already nervous about vetting for offensive security contractors. Procurement teams evaluating penetration-testing vendors increasingly ask for background-check cadence, insider-threat monitoring, and incident history as standard due diligence items, not optional extras. A case like this one gives that line of questioning more weight in contract renewals happening this quarter.

For the FBI, the bigger cost isn’t this arrest. It’s the unresolved question of how much personnel data actually left apply.fbijobs.gov and what that means for anyone who applied for a federal law enforcement job in the past several years. Shattered.io tracked the operational disruption from that breach when the portal stayed offline for six days, a downtime window that itself signals how seriously the bureau treated the intrusion, independent of whatever the Dutch case ultimately proves.

Cyber insurance underwriters watching this space have been pricing in exactly this kind of scenario, where a breach claim from an extortion group can’t be independently verified for weeks. Premiums for federal contractors and firms handling sensitive personnel data have already climbed over the past two years, and cases that stay unresolved this long tend to keep that pressure elevated rather than releasing it.

How Dutch Cybercrime Prosecutions Compare Internationally

The Netherlands has built one of Europe’s more active cybercrime enforcement programs, running through its national police high-tech crime unit and the Rotterdam-based prosecution service that specializes in these cases. That’s part of why a ShinyHunters-linked arrest surfaced there rather than somewhere with less specialized capacity. Below is a general comparison of how a few jurisdictions typically structure cybercrime cases of this scale, based on standard public procedure rather than case-specific detail, since no court outcome exists yet to compare against.

JurisdictionTypical pretrial processPublic disclosure norms
NetherlandsClosed custody hearing (raadkamer-style review) before formal chargesPolice confirm arrest details narrowly, name withheld pending charges
United StatesGrand jury indictment, often unsealed after arrest or extraditionDOJ press release typically names defendant once indictment unseals
United KingdomPolice bail or remand hearing at magistrates’ courtSuspect often named once formally charged, not at arrest
FranceGarde à vue detention followed by investigating magistrate reviewNames generally withheld under strict pretrial secrecy rules

This context matters for readers trying to figure out when more concrete facts might surface. In a French-style system, secrecy could extend for months. In the Dutch system on display here, the Rotterdam hearing itself is closed, but Dutch police have shown a pattern of issuing short public updates around each procedural milestone, which is more transparency than several comparable systems offer at this stage.

Historical Context: Naming Names in Extortion Groups

Attaching a real identity to a major extortion crew is rare enough that it tends to change group behavior when it happens. Ransomware and data-extortion collectives generally organize as loose affiliate networks rather than tight-knit cells, precisely so that one member’s exposure doesn’t sink the whole operation. When a member is arrested and named, or partially named through reporting, the rest of the group typically goes quiet for a stretch, rotates infrastructure, and rebrands parts of its operation under a new name or forum handle.

ShinyHunters has already shown that kind of resilience. Despite years of law enforcement pressure and periodic arrests tied to its broader orbit, the name has stuck around since 2020 while the group’s tactics evolved from straightforward database dumps to the credential-based cloud intrusions seen in the Snowflake-linked wave of breaches. An arrest connected to the group doesn’t guarantee it stops operating. It’s more likely to prompt a temporary pause and an operational security review among whoever remains active.

What Security Teams Should Watch For

Security teams at companies that engaged Neo Security, or any offensive security vendor with employees now under scrutiny, should treat this as a prompt to review engagement logs rather than panic over an unproven allegation. That means checking whether any penetration-testing access granted to the individual in question was scoped correctly, logged completely, and revoked on schedule after each engagement ended.

More broadly, this case is a reminder that insider-risk programs shouldn’t stop at hiring. Continuous monitoring of privileged access, especially for contractors and vendors who routinely operate inside client networks with elevated permissions, catches exactly the kind of dual-life risk this arrest represents, regardless of whether the specific allegations against this individual hold up in court. The same discipline applies to exfiltration monitoring generally, an area shattered.io examined in depth in its look at how ransomware groups are adapting by using encrypted exfiltration methods to slip stolen data past traditional detection tools.

Anyone who applied for a job through apply.fbijobs.gov in recent years should also keep an eye on credit monitoring and phishing attempts referencing that application, given ShinyHunters’ history of using stolen personal data for follow-on social engineering rather than letting it sit unused.

Predictions: Where This Case Goes Next

  • Dutch prosecutors will likely request extended pretrial detention at the September 29 hearing rather than seeking an immediate resolution, matching the pattern seen in most early-stage cybercrime custody reviews.
  • Neo Security’s internal review will probably conclude within weeks, and the company has strong incentive to publish a summary of its findings to protect its client relationships regardless of which way the results point.
  • The FBI is unlikely to comment directly on the Dutch case unless US prosecutors open a parallel domestic charge, which would only happen if evidence directly ties the suspect to the apply.fbijobs.gov intrusion specifically.
  • ShinyHunters as a brand will most likely continue operating through other members even if this individual is formally charged, consistent with how the group weathered previous law enforcement pressure since 2020.
  • Expect renewed scrutiny of offensive security vendor vetting standards across the industry in the coming months, driven less by this case alone than by its coincidence with the still-unresolved FBI breach.

The Bigger Picture

The takeaway from September 29’s Rotterdam hearing isn’t a verdict, because there isn’t one yet. It’s a snapshot of how a single arrest ripples outward: a security firm defending its reputation, a federal agency still counting the cost of a breach it hasn’t fully explained, and a hacking group that has outlasted several rounds of law enforcement pressure since it first appeared on cybercrime forums in 2020.

What happens in the Rotterdam courtroom will shape the next chapter, but the FBI breach investigation and the broader ShinyHunters problem will keep running on their own timelines regardless of this individual case’s outcome. Readers should watch for follow-up statements from Dutch police after the hearing, and for any update from the FBI on the actual scope of the apply.fbijobs.gov intrusion, which remains the more consequential open question.

Frequently Asked Questions

Who was arrested in the ShinyHunters investigation?
Dutch police confirmed the arrest of a 24-year-old man from Amsterdam in September 2026, describing him only by age and city. Media reports, not officially confirmed by police, have identified him as Pepijn van der Stap.

Is the suspect confirmed to be a member of ShinyHunters?
No. Dutch police said the arrest occurred in an investigation into the group, but membership, direct participation in any specific breach, and legal status remain unconfirmed and are subject to the ongoing case.

What is ShinyHunters?
ShinyHunters is a data-extortion group that has been active since around 2020, associated with large-scale data theft and extortion attempts against companies including Ticketmaster and multiple Snowflake customers, and more recently the claimed breach of the FBI’s job-application portal.

How is this connected to the FBI data breach?
ShinyHunters claimed responsibility for breaching apply.fbijobs.gov. The Amsterdam suspect is under investigation in connection with the group generally. No public report confirms he personally participated in the FBI breach specifically.

What happened at the September 29 Rotterdam hearing?
The suspect was scheduled to appear before the Rotterdam District Court for what Dutch procedure typically handles as a closed pretrial custody review, determining whether detention continues while the investigation proceeds, not a verdict on guilt.

Did the suspect work in cybersecurity?
Yes. Benjamin Korper, described as the boss at Amsterdam-based firm Neo Security, confirmed the arrested man worked there as the company’s offensive security lead.

Has the FBI confirmed how much data was stolen?
No. Reports describe ShinyHunters’ claims about the scope of stolen FBI personnel data, but the available reporting does not establish that those claims were independently verified by the bureau.

Will this arrest stop ShinyHunters from operating?
Unlikely on its own. Extortion groups like ShinyHunters typically function as loose networks of contributors, and past law enforcement pressure since 2020 has not ended the group’s activity, only prompted periodic pauses and rebranding.



Click Here For The Original Source.

——————————————————–

..........

.

.