Dutch authorities have arrested a 24-year-old cybersecurity professional as part of an investigation into ShinyHunters, the hacking and data-extortion operation linked to a series of major breaches.
Police confirmed that a man from Amsterdam was detained earlier in September and was scheduled to appear before the Rotterdam District Court on September 29. Authorities have not officially released his name or provided detailed allegations concerning his suspected role in ShinyHunters.
Multiple reports have identified the arrested man as Pepijn van der Stap, a security researcher who had previously been convicted of cybercrime before publicly presenting himself as reformed. His employer, Amsterdam-based cybersecurity company Neo Security, separately confirmed his identity.
Van der Stap worked as Neo Security’s offensive security lead. Company CEO Benjamin Korper said forensic investigators visited the firm’s offices on September 15, the same night Van der Stap was arrested.
His detention has attracted additional attention because of his criminal history. In 2023, Van der Stap was convicted of hacking, data theft, and extortion offenses. He later publicly distanced himself from cybercrime and moved into professional cybersecurity work.
Neo Security has commissioned an independent investigation to determine whether its own infrastructure or customers were affected by any unauthorized activity. According to Korper, investigators have so far found no evidence that Van der Stap targeted the company or its clients.
The arrest comes as Dutch authorities investigate major breaches attributed to ShinyHunters. One of the most significant involved telecom provider Odido, where attackers obtained information belonging to more than six million customers.
Dutch police previously disclosed that the Odido intrusion began with social engineering. A Dutch-speaking attacker impersonated an IT employee during a call with customer service and directed an employee to a fake login page. The attacker obtained both login credentials and a verification code, providing access to internal systems.
ShinyHunters has denied that Van der Stap has any connection to the group. That denial has not been independently established, while Dutch authorities have so far released few details about the evidence behind the arrest.
The timing also overlaps with intense scrutiny of ShinyHunters following its claimed compromise of the FBI’s recruitment environment and alleged theft of sensitive personnel information. However, authorities have not publicly established that Van der Stap personally participated in the FBI incident.