Cyber Worker Allegedly Moonlighted as ShinyHunters Hacker

September 30, 2026 by

Police in the Netherlands have arrested a Dutch man on suspicion of cybercrime-related activities, according to the person’s employer and other people familiar with the matter.

Pepijn van der Stap, 24, was arrested earlier this month and charged with involvement in several cases of extortion and criminal hacking led by the group known as ShinyHunters, said the people, who requested anonymity because they weren’t authorized to speak about the matter. FBI Director Kash Patel said in a tweet Tuesday that law enforcement had arrested a Dutch man in connection with the cybercrime group’s activity.

Related: Crypto Hack Spurs $463 Million in Customer Outflows at Bitget

ShinyHunters has been active since 2019 and is among the world’s most prolific data-theft and extortion groups, according to cybersecurity firm Huntress. The group claimed responsibility last week for an alleged hack targeting the Federal Bureau of Investigation. People affiliated with ShinyHunters said they had stolen a trove of sensitive personal information about current and former FBI employees.

Van der Stap, 24, was arrested before the FBI breach. It is unclear whether authorities suspect him of involvement in that intrusion.

Dutch police said in a statement on Tuesday that the man they arrested in connection with ShinyHunters activity was also suspected of attempted incitement to commit two murders. The statement said those accusations were unconnected to his alleged role with the cybercrime gang and that evidence concerning murders had been discovered on a laptop. The police statement did not mention Van der Stap by name.

Dutch prosecutors and representatives for Van der Stap didn’t respond to requests for comment.

Related: Agentic Intelligence for Claims Dominates New Tech Launches

He hasn’t yet been tried for the alleged criminal activity.

At the time of his arrest, Van der Stap had been working as chief technology officer and offensive security lead at Amsterdam-based cybersecurity firm Neo Security. Chief Executive Officer Benjamin Korper said in a phone call Monday that police had notified him of Van der Stap’s arrest two weeks earlier, calling late one evening to ask to meet at the company’s offices. The police agency that conducted the search didn’t respond to a request for comment.

About eight police officers spent hours searching the premises and seized Neo Security servers as part of the investigation, Korper said. The company later hired an outside firm to examine its internal systems. Korper said the review had so far found no evidence that Van der Stap had tampered with Neo Security’s network or those of its customers.

ShinyHunters has claimed more than 160 victims since 2024, according to the group’s own website. It has been linked to scores of high-profile incidents, including hacks on AT&T Inc., Salesforce Inc., Jaguar Land Rover PLC, Instructure Inc. and Amazon.com Inc.-owned healthcare provider One Medical. The companies publicly addressed the incidents, but their statements did not uniformly confirm ShinyHunters’ responsibility.

Van der Stap was previously the subject of a Bloomberg Businessweek story that reported he had worked for cybersecurity companies while also engaging in cybercrime activity. In November 2023, Van der Stap was sentenced to four years in prison after a judge found him guilty of involvement in data theft, extortion and laundering at least €1.5 million ($1.7 million).

He was moved to a low-security prison in 2025 and released earlier this year. A judge took Van der Stap’s age, difficulties in his personal life and a confession into account when sentencing him.

Korper said he had wanted to give Van der Stap a second chance after his release.

Top photo: In this photo illustration a young man types on an illuminated computer keyboard typically favored by computer coders on January 25, 2021 in Berlin, Germany. (Photo by Sean Gallup/Getty Images). Bloomberg.