As reported by The Hacker News, Dutch authorities have arrested a 24-year-old Amsterdam man—identified by security journalists as Pepijn van der Stap (aka "Umbreon")—in connection with the ShinyHunters threat group. The arrest, made on September 15, 2026, comes amid escalating ShinyHunters activity, including the group's recent claim of compromising the FBI's job application portal.

Key Takeaway: As reported by The Hacker News, Dutch authorities have arrested a 24-year-old Amsterdam man—identified by security journalists as Pepijn van der Stap (aka "Umbreon")—in connection with the ShinyHunters threat group.

The most striking element of this story isn't the arrest itself—it's the profile. Van der Stap held positions at a cybersecurity firm (Hadrian), volunteered at a vulnerability disclosure organization (DIVD), and most recently served as an offensive security lead at Neo Security. He was previously arrested in 2023 for data theft and extortion, yet continued working in privileged security roles. This is not a peripheral actor; this is someone embedded in the defensive ecosystem with deep access to tooling, methodology, and potentially sensitive client environments.

Why This Matters Beyond the Headlines

This case exposes a structural weakness that the cybersecurity industry continues to underweight: the insider trust gap. We obsess over zero-day vulnerabilities and nation-state APTs, but we hand administrative credentials, internal network access, and threat intelligence to individuals whose vetting often extends no further than a job interview and a criminal record check. A prior arrest in 2023 did not prevent re-entry into the offensive security community. That is a systemic failure, not an individual one.

The issue isn't that cybersecurity employs former criminals—many rehabilitation pathways exist and can be valuable. The issue is when organizations lack the governance frameworks to manage that risk intelligently.

ShinyHunters' denial of any connection to van der Stap is itself noteworthy. Threat groups routinely disassociate from arrested individuals to preserve operational security and morale. The group's statement framing the arrest as Dutch police "chasing attention" after the Odido breach embarrassment is consistent with their pattern of using media narratives to control perception. This public-relations-as-tactic approach has been central to their recent FBI jobs portal breach framing, which they described to 404 Media as a "marketing campaign."

Broader Industry Implications

Broader Industry Implications
Insider risk is underestimated in security firms. Organizations providing penetration testing, red teaming, or managed detection services grant employees access to client networks and sensitive data. A single compromised or dual-role individual creates cascade risk across every client engagement.
Prior arrests don't automatically trigger industry-wide exclusion. Without cross-organizational information sharing or regulatory requirements for disclosure, individuals can move between security employers without prior incidents surfacing.
Threat actors are normalizing PR-driven breach disclosure. ShinyHunters' self-described "marketing" approach to the FBI jobs portal hack signals an evolution in how threat groups weaponize media attention for recruitment and reputation.

What You Should Do: Shield53 Recommendations

  • Implement continuous insider risk monitoring for all personnel with privileged access to client systems, threat intelligence, or offensive tooling. Look for anomalous data staging, off-hours access, and unauthorized external communications.
  • Adopt a structured re-entry framework for individuals with prior cybercrime history. If your organization chooses to employ someone with a criminal cybersecurity background, require supervised access, restricted scope on client engagements, and documented risk acceptance at the executive level.
  • Enforce least-privilege on offensive security teams. Red teamers and pentesters should not retain persistent access to client environments beyond engagement windows. Time-box credentials, log everything, and revoke access automatically.
  • Establish cross-employer information sharing through legal frameworks like sharing agreements under counsel, or industry ISACs, so that prior incidents follow individuals with appropriate privacy safeguards.
  • Treat ShinyHunters as an active, evolving threat. Their FBI portal claim and "marketing" posture indicate continued operational capability and willingness to target government infrastructure. Ensure your threat intel feeds track their TTPs and claimed victim lists.

The cybersecurity industry cannot afford to treat insider risk as a secondary concern. When the people building your defenses may also be the ones probing them from the other side, governance—not just talent—becomes the controlling variable.