Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
- ID
- 29757
- Status
- summarized
- Published
- 29 Sep 2026, 4:35 PM
- Fetched
- 29 Sep 2026, 7:42 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.5
- Created
- 29 Sep 2026, 7:43 PM
- Tags
- Audience
- developerssaas_founders
What happened
Dutch police (Politie Landelijke Opsporing en Interventies) confirmed the arrest of a 24-year-old Amsterdam man in the ShinyHunters investigation, with a Rotterdam District Court appearance scheduled for September 29, 2026; DataBreaches.Net reports the arrest happened September 15, 2026. Journalist Brian Krebs and DataBreaches.Net identified him as Pepijn van der Stap (aka Umbreon), previously apprehended in 2023 over data thefts and extortions, who per LinkedIn is now offensive security lead at Dutch company Neo Security and previously worked at Hadrian and volunteered at DIVD. The arrest follows ShinyHunters claiming credit for breaching the FBI job application site apply.fbijobs.gov and stealing terabytes of data, which a group representative described to 404 Media as 'a marketing campaign' to draw attention.
Why it matters
For most builders this changes nothing in their stack. The one concrete signal is the target class: ShinyHunters took terabytes from a job application site (apply.fbijobs.gov), so if you run a careers page, ATS, or any portal collecting applicant PII and resumes, that is a demonstrated high-volume target and worth treating as sensitive data rather than a marketing form. The 'marketing campaign' quote is also a reminder that public claims of a breach can be part of the pressure tactic itself, so treat attacker statements as evidence to verify, not as fact.
Discussion angle
Attackers openly calling a breach 'a marketing campaign' to get attention — does that change how you'd respond to an extortion claim against your own product, and would you verify before paying or disclosing?