AI Weekly Malaysia

Back to items Summaries

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

ID
29757
Status
summarized
Published
29 Sep 2026, 4:35 PM
Fetched
29 Sep 2026, 7:42 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
2.5
Created
29 Sep 2026, 7:43 PM
Tags
Audience
developerssaas_founders

What happened

Dutch police (Politie Landelijke Opsporing en Interventies) confirmed the arrest of a 24-year-old Amsterdam man in the ShinyHunters investigation, with a Rotterdam District Court appearance scheduled for September 29, 2026; DataBreaches.Net reports the arrest happened September 15, 2026. Journalist Brian Krebs and DataBreaches.Net identified him as Pepijn van der Stap (aka Umbreon), previously apprehended in 2023 over data thefts and extortions, who per LinkedIn is now offensive security lead at Dutch company Neo Security and previously worked at Hadrian and volunteered at DIVD. The arrest follows ShinyHunters claiming credit for breaching the FBI job application site apply.fbijobs.gov and stealing terabytes of data, which a group representative described to 404 Media as 'a marketing campaign' to draw attention.

Why it matters

For most builders this changes nothing in their stack. The one concrete signal is the target class: ShinyHunters took terabytes from a job application site (apply.fbijobs.gov), so if you run a careers page, ATS, or any portal collecting applicant PII and resumes, that is a demonstrated high-volume target and worth treating as sensitive data rather than a marketing form. The 'marketing campaign' quote is also a reminder that public claims of a breach can be part of the pressure tactic itself, so treat attacker statements as evidence to verify, not as fact.

Discussion angle

Attackers openly calling a breach 'a marketing campaign' to get attention — does that change how you'd respond to an extortion claim against your own product, and would you verify before paying or disclosing?

Top