As reported by Krebs on Security, Dutch police have arrested Pepijn van der Stap—a 23-year-old convicted cybercriminal who previously operated under the alias "Umbreon"—on suspicion of aiding the prolific ShinyHunters group in data thefts and extortion campaigns. What makes this case particularly instructive is not the arrest itself, but the pattern it reveals: a convicted cybercriminal who received a reduced sentence, secured employment in the cybersecurity industry, and allegedly returned to criminal activity within months of release.
The 'Reformed Hacker' Fallacy
The cybersecurity industry has a long and troubled history of romanticizing the path from blackhat to whitehat. The narrative is seductive: a talented individual makes mistakes, pays their debt to society, and returns to contribute meaningfully. While genuine reform does occur, van der Stap's case demonstrates that the assumption of rehabilitation is a risk management decision—not a certainty.
Van der Stap received a four-year sentence (one year suspended) for crimes that generated between €1.5 and €2.7 million. He was released in December 2025. By September 2026, he was employed as offensive security lead at Neo Security, positioned to access sensitive client environments, and allegedly re-engaged with ShinyHunters. The timeline alone should give any CISO pause.
The issue isn't whether second chances are possible—they are. The issue is that organizations treat hiring convicted cybercriminals as a PR opportunity rather than the serious risk decision it genuinely represents.
Why This Matters for Defenders
Three dimensions of this case demand attention from security leaders:
Beyond Background Checks: A Maturity Problem
Standard background checks would have surfaced van der Stap's conviction. The fact that he secured offensive security roles suggests either inadequate vetting processes or deliberate decisions to overlook his history. Neither is acceptable for positions with privileged access to client environments.
The deeper problem is structural. The cybersecurity industry suffers a persistent talent shortage, creating pressure to hire anyone with demonstrable technical skill—regardless of provenance. Offensive security roles, in particular, require exactly the skill set that active or former criminals possess. This creates a perverse incentive structure where criminal history can actually accelerate hiring rather than trigger additional scrutiny.
Shield53 Recommendations
For organizations—particularly security firms, MSSPs, and any entity granting offensive security personnel access to client environments:
- Implement enhanced vetting for privileged roles. Standard background checks are insufficient for positions with access to client systems. Require full disclosure of criminal history, verify references independently, and conduct periodic re-vetting for employees with elevated access.
- Adopt zero-trust for internal actors. No employee—regardless of role or tenure—should have unmonitored access to client environments. Implement just-in-time access, session recording, and behavioral analytics for all privileged users.
- Establish criminal history review protocols. If your organization decides to hire individuals with cybercrime convictions, require executive-level sign-off, documented risk acceptance, enhanced monitoring, and restriction from roles with unsupervised access to client data or security tooling.
- Brief clients on insider risk posture. Security providers should transparently disclose their hiring practices regarding convicted cybercriminals. Clients deserve to make informed decisions about who accesses their environments.
- Monitor for retaliation targeting. If an employee or contractor is arrested or investigated, immediately assess whether your organization could be a target for retaliatory attacks by their associates. Van der Stap's arrest triggered ShinyHunters escalation—any organization connected to him or his employers was potentially in the blast radius.
This case isn't about denying second chances. It's about recognizing that trust is earned through demonstrated behavior over time—not conferred by a job title. The cybersecurity industry must mature its approach to insider risk, or it will continue to provide safe harbor for exactly the threat actors it exists to defend against.