As reported by SecurityAffairs, Dutch police have arrested a 24-year-old Amsterdam man as part of an ongoing investigation into the ShinyHunters cybercrime group. Multiple sources, including KrebsOnSecurity, have identified the suspect as Pepijn van der Stap — a previously convicted cybercriminal who operated under the alias "Umbreon" and, remarkably, held positions at legitimate cybersecurity organizations both before and after his 2023 conviction.
This case should serve as a watershed moment for the cybersecurity industry's approach to hiring and insider risk. It exposes several uncomfortable truths that our profession has been reluctant to confront.
The Insider Threat We Created
What makes this case particularly disturbing is not just the alleged criminal activity — it's the institutional access van der Stap enjoyed. He worked as a software engineer at Hadrian, a cybersecurity startup, while simultaneously extorting victims and posting stolen data on criminal forums. He volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD). After serving a reduced sentence and being released in December 2025, he was hired as an offensive security lead at Neo Security.
Each of these roles granted him access to sensitive systems, client environments, vulnerability research, and threat intelligence — exactly the types of assets that a data theft and extortion operation like ShinyHunters would find invaluable.
The cybersecurity industry has a rehabilitation problem. We champion second chances but lack the framework to verify that rehabilitation is genuine.
What Defenders Should Be Asking
For security leaders, this case raises immediate questions about hiring practices, insider threat programs, and the due diligence applied to candidates with disclosed criminal backgrounds.
Key Concerns:
ShinyHunters: Ongoing Threat Profile
ShinyHunters has been linked to multiple high-profile breaches, typically involving large-scale data theft and extortion. Their operational model favors volume — hitting many targets and monetizing through data sales and direct extortion. The group's connection to marketplaces like BreachForums and its predecessors suggests a sophisticated understanding of the criminal data economy.
The fact that an alleged associate was operating inside legitimate security firms means ShinyHunters may have had access to pre-disclosure vulnerability information, client network architecture details, and threat intelligence that could have been used to target additional victims. The full extent of this exposure may not be known for months.
Shield53 Recommendations
- Audit historical access: Organizations that employed van der Stap or similar convicted individuals in security-adjacent roles should conduct retroactive access reviews and hunt for indicators of data exfiltration.
- Implement behavioral analytics: Deploy UEBA solutions that flag unusual data access patterns, especially for users with elevated privileges in offensive security or research roles.
- Enhance vetting protocols: For candidates with disclosed cybercrime histories, require open-source intelligence reviews covering forum handles, marketplace activity, and ongoing legal proceedings — not just court records.
- Enforce separation of duties: Offensive security teams should operate in isolated environments with no cross-visibility into client production data or vulnerability research pipelines.
- Establish disclosure frameworks: Create transparent policies for employing rehabilitated offenders — including mandatory monitoring periods, restricted access scopes, and regular risk reviews with legal counsel.
The cybersecurity community must balance compassion with pragmatism. Second chances matter, but they cannot come at the expense of the clients and organizations we are sworn to protect.