Dutch authorities have arrested cybersecurity professional and previously convicted hacker Pepijn van der Stap as part of an investigation into ShinyHunters, marking a significant law enforcement development involving the prolific hacking and extortion group.
Dutch police confirmed that a 24-year-old man from Amsterdam was arrested this month in connection with an investigation into ShinyHunters and is scheduled to appear before the Rotterdam District Court on Sept. 29.
Police did not publicly identify the suspect by name. However, Benjamin Korper, CEO of Amsterdam-based cybersecurity company Neo Security, identified the arrested employee to Reuters as Pepijn van der Stap, the company’s offensive security lead.
Korper said Van der Stap was arrested during a police raid on Sept. 15. Dutch forensic investigators also visited Neo Security’s offices that night as authorities pursued the investigation.
Van der Stap previously convicted of data theft and extortion
The arrest places Van der Stap back under criminal investigation approximately 3 years after his previous prosecution for cybercrime in the Netherlands.
Van der Stap was convicted in 2023 over his involvement in a series of corporate data theft and extortion attacks. Prosecutors accused the operation of compromising organizations, stealing large volumes of information and demanding payments from victims.
Van der Stap admitted involvement in the earlier criminal activity during those proceedings and was sentenced to 4 years in prison, with 1 year suspended.
His previous case attracted particular attention because he maintained a parallel career in legitimate cybersecurity while participating in criminal hacking activity.
At the time, Van der Stap worked as a software engineer at Amsterdam cybersecurity company Hadrian and volunteered with the Dutch Institute for Vulnerability Disclosure, a nonprofit organization that coordinates vulnerability research and responsible disclosure.
Following his arrest in that case, investigations into his legitimate cybersecurity roles found no evidence that he had abused access to Hadrian or DIVD systems for his criminal operations.
Returned to professional cybersecurity
After serving his sentence, Van der Stap returned to the cybersecurity industry and publicly presented himself as having moved away from cybercrime.
He joined Neo Security, where the company’s website identifies him as a specialist in adversary simulation and red teaming who leads red-team operations.
In a July 2026 profile published by Neo Security, Van der Stap discussed his history in cybersecurity and described having experienced security from both offensive and defensive perspectives. The company presented that background as informing his work in offensive security, penetration testing, adversary simulation and vulnerability research.
Neo Security CEO Benjamin Korper told Reuters that he had carefully vetted Van der Stap before hiring him and was shocked by the arrest.
Following the Sept. 15 raid, Neo Security commissioned an outside investigation to determine whether Van der Stap had compromised the company or any of its customers. Korper said investigators have so far found no evidence that he targeted Neo Security or its clients.
The company has not been accused of involvement in the alleged ShinyHunters activity.
Police investigating alleged ShinyHunters connection
Dutch authorities have disclosed few details about what specifically led investigators to Van der Stap or what activity they believe connects him to ShinyHunters.
Police have not publicly connected him to a specific ShinyHunters breach, extortion attempt or victim.
ShinyHunters has reportedly denied that Van der Stap is associated with the group.
The arrest therefore does not establish that Van der Stap participated in any particular operation attributed to ShinyHunters. Further details about the allegations may emerge through proceedings before the Rotterdam District Court.
Arrest came before FBIjobs.gov and Cl0p attacks
The timing of the arrest is particularly notable because ShinyHunters continued conducting high-profile operations after Van der Stap was taken into custody.
Van der Stap was arrested on Sept. 15, according to his employer. In the days that followed, ShinyHunters claimed responsibility for an intrusion affecting the FBI’s recruitment infrastructure and separately compromised the leak infrastructure operated by the Cl0p ransomware group.
On Sept. 24, BreachNews reported that the FBI was investigating unauthorized activity affecting FBIjobs.gov after ShinyHunters claimed it compromised the recruitment system and stole sensitive information involving FBI personnel and job applicants.
ShinyHunters claimed it obtained between 2 TB and 3 TB of information and gained access to additional government infrastructure. The FBI confirmed that it was investigating claims regarding unauthorized activity affecting FBIjobs.gov but has not confirmed the amount of information allegedly stolen or the broader access claimed by the group.
There is currently no public evidence establishing that Van der Stap participated in the FBIjobs.gov incident. The reported Sept. 15 arrest predates that attack becoming public.
ShinyHunters also compromised and defaced Cl0p’s ransomware leak site following Van der Stap’s arrest before threatening to extort the rival cybercrime operation.
The continued activity demonstrates that the ShinyHunters operation remained active following the arrest, regardless of what role Dutch investigators ultimately allege Van der Stap held.
PeopleSoft exploitation remains under scrutiny
The law enforcement development also comes amid scrutiny of ShinyHunters activity targeting Oracle PeopleSoft environments.
ShinyHunters claimed that its FBIjobs.gov intrusion involved a previously unknown PeopleSoft vulnerability. More recent security research has instead focused on techniques used to bypass web application firewall protections intended to mitigate CVE-2026-35273.
The group has been linked to exploitation of PeopleSoft environments across multiple sectors during 2026, including government, healthcare, education and major enterprises.
The FBI has not publicly confirmed that CVE-2026-35273, a separate zero-day or any other specific PeopleSoft vulnerability was used to compromise FBIjobs.gov.
Rotterdam court appearance expected
Van der Stap is expected to appear before the Rotterdam District Court on Sept. 29 as the Dutch investigation continues.
Authorities have not publicly disclosed the charges he may face, the evidence allegedly connecting him to ShinyHunters or whether additional arrests are expected.
The case is particularly significant because of Van der Stap’s previous conviction and subsequent return to professional cybersecurity, but his alleged role in ShinyHunters remains under investigation.
ShinyHunters, meanwhile, has continued operating despite the arrest and has denied that Van der Stap is associated with the group.












