As reported by BleepingComputer, Dutch police have confirmed the September 15 arrest of a 24-year-old Amsterdam man, identified by KrebsOnSecurity and DataBreaches as Pepijn van der Stap β a previously convicted hacker who operated under the alias "Umbreon." Authorities are investigating his possible connection to the ShinyHunters threat group, though attribution remains unconfirmed and ShinyHunters itself has denied any link.
Why This Matters Beyond the Headline
The arrest is notable not because it definitively dismantles ShinyHunters β it does not β but because it illustrates the persistent challenges of linking online personas to physical actors, especially when threat groups deliberately cultivate ambiguity. Van der Stap's prior 2023 conviction for hacking and extortion across more than a dozen companies should have been a career-ending event. Yet here we are, with authorities examining whether the same individual (or his associates) continued operating under overlapping identities.
What makes the attribution thread particularly tangled is the reuse of the "Umbreon" PokΓ©mon character. Van der Stap reportedly used that alias on BreachForums as early as 2021, but the same character appeared in a 2020 HackForums defacement β a year before his known account was created. ShinyHunters also recently used Umbreon imagery during an FBI breach and the defacement of Clop's leak site. Whether this represents a shared aesthetic, a purchased account, a collective identity, or deliberate misdirection is exactly the kind of ambiguity that makes forum-based attribution unreliable as a single data point.
The Social Engineering Angle
Police also released a voice recording of a suspect in the Odido telecom breach who called a help desk impersonating IT staff and tricked an employee into entering credentials and a verification code into a fake portal. Reports indicate the voice did not match van der Stap. This is a critical detail: it suggests either a co-conspirator or that investigators are still working through multiple suspects. For defenders, it reinforces that these crews operate withεε·₯ and that neutralizing one actor does not neutralize the operational capability.
The ShinyHunters representative's denial to BleepingComputer β "That individual has no association with us. Frankly, we are laughing" β is exactly the kind of counter-narrative threat actors deploy to seed doubt and protect operational infrastructure. It should carry zero evidentiary weight in a serious investigation.
Who Is Affected
Shield53 Recommendations
Regardless of whether this arrest meaningfully disrupts ShinyHunters' capabilities, defenders should treat the group as still operational and apply the following:
- Hardens help desk authentication workflows: Implement callback verification for any password reset or credential-related request. Train staff to recognize and escalate vishing attempts. Disable the ability to bypass MFA via social engineering by requiring in-band verification through an authenticated portal.
- Audit and rotate developer credentials: Assume any GitHub/GitLab tokens, cloud API keys, or storage credentials exposed in prior breaches are compromised. Rotate secrets, enforce least-privilege scopes, and enable anomaly detection on token usage.
- Monitor for data exfiltration indicators: ShinyHunters campaigns often involve bulk download from cloud storage and databases. Deploy egress monitoring and alerting on anomalous data transfer volumes.
- Strengthen insider and third-party risk monitoring: Convicted hackers with remaining network access or associate relationships can continue to pose risk. Review access for any personnel with prior offenses and ensure separation agreements include credential revocation.
- Do not rely on forum-based attribution for defensive decisions: Alias overlap is useful for investigation but should not drive your incident response scope. Assume the threat persists until your own telemetry confirms disruption.
The Dutch court appearance on September 29 may yield additional clarity. Until then, treat this as an intelligence signal β not a takedown confirmation. ShinyHunters has demonstrated resilience, and the gap between an arrest and operational disruption is measured in months, not headlines.