Dutch authorities arrested Pepijn van der Stap on September 16 on suspicion of aiding the hacking collective ShinyHunters, according to Protos, which cited KrebsOnSecurity. He was detained in the Netherlands for questioning, and police said he is due to appear in Rotterdam District Court on September 29.

Local news reports cited in the article said the United States is also involved in the case.
Van der Stap, 24, had previously carried out multiple acts of data theft and extortion under the alias “Umbreon” more than three years ago. He was later arrested, convicted, and handed a four-year suspended sentence. He was released in December 2025.
The report also described him as a previously convicted hacker who had publicly portrayed himself as reformed after leaving prison in 2025. Dutch police are investigating his possible connection to ShinyHunters activity.
While engaged in those criminal activities, van der Stap worked at cybersecurity startup Hadrian and volunteered for the nonprofit Dutch Institute for Vulnerability Disclosure. He is currently the offensive security lead at Neo Security and had described himself to KrebsOnSecurity as a reformed convict.
FBI breach claim surfaced six days after the arrest
Six days after van der Stap’s arrest, ShinyHunters claimed responsibility for hacking and stealing data belonging to 5,000 FBI agents. The attack also altered the FBI’s job page to display an image of the Pokémon Umbreon.
KrebsOnSecurity said the operation looked different from ShinyHunters’ usual attacks. At the time, the group was reportedly led by a teenager based in Amman, Jordan, who uses the nickname “Rey.”
According to the same report, Rey merged ShinyHunters with Scattered Spider and LAPSUS$ into a group called ScatteredLapsussHunters.
Sources said the Umbreon reference may have been meant to redirect blame
Sources close to the ShinyHunters investigation told KrebsOnSecurity that Rey had “ongoing beef” with van der Stap. The report said the appearance of Umbreon in the FBI page hack may have been an attempt to shift blame toward van der Stap.
ShinyHunters has also been linked to the hacking of Dutch telecom provider Odido last February. In that incident, personal data from 6 million Odido customers was leaked, including bank account and passport numbers.

