The Pepijn van der Stap arrest was not announced by Dutch police under his name. Police said on September 28 that they had arrested a 24-year-old man in connection with an investigation into the ShinyHunters hacking group and that he would appear in a Rotterdam court the following day, Reuters reported.
Benjamin Korper, an executive at Amsterdam cybersecurity company Neo Security, identified the man to Reuters as van der Stap, the firm’s offensive security lead. That identification is from his employer, not the police statement. The reporting does not establish that van der Stap is a ShinyHunters member, that he has been charged, or that he committed an offense in the current inquiry.
ShinyHunters denied that van der Stap had any connection to the group, according to Reuters. That is a denial from the group, not an official finding.
What did Dutch police confirm about the Pepijn van der Stap arrest?
Police publicly confirmed the arrest of an unnamed 24-year-old in the ShinyHunters investigation and said the suspect was due in Rotterdam court. Reuters reported that Korper said Dutch forensic investigators visited Neo Security’s office on September 15, the night van der Stap was arrested.
Reuters did not report the outcome of the planned court appearance. An arrest and an investigation are procedural steps, not a verdict. The police statement cited by Reuters did not name van der Stap or specify a charge.
Why is van der Stap described as a reformed hacker?
Van der Stap had earlier convictions for data theft and extortion in 2023, Reuters reported. His later public rejection of cybercrime received broad attention, which is the basis for the “reformed” label in coverage of the arrest.
KrebsOnSecurity reported that van der Stap had described himself as trying to make a positive contribution after his release from prison and was working at Neo Security. The outlet also reported that he had previously used the online handle “Umbreon.” Those past convictions provide context, but they do not prove allegations tied to the current ShinyHunters inquiry.
What has Neo Security said?
Korper told Reuters that Neo Security hired an outside firm to check whether van der Stap had compromised the company or its customers. At the time of the report, Korper said investigators had found no evidence that van der Stap had acted against Neo Security or its clients.
The inquiry arrives as ShinyHunters faces scrutiny over its claimed theft of sensitive FBI personnel data. Reuters reported that the FBI was investigating the breach and communicating with people who might be affected. The FBI matter is relevant background to the group investigation, but the available reporting does not tie van der Stap to that breach.
ShinyHunters is associated in Reuters reporting with large-scale data breaches and extortion. Dutch police had also sought public help identifying the voice of a Dutch-speaking person involved in a February intrusion at telecom company Odido, KrebsOnSecurity reported. The outlet said it was unclear whether police had connected that caller to a confirmed real-world identity.
For now, the public record is narrower than the online speculation: police confirmed an unnamed suspect’s arrest, Neo Security identified that suspect as van der Stap, and the alleged relationship to ShinyHunters remains unproven.
This story draws on original reporting from Krebs on Security.