Recent developments in the field of cybersecurity in the Netherlands have caused a huge stir, with the confirmation from Dutch authorities and the Federal Bureau of Investigation (FBI) in the United States that a 24-year-old Dutch man, Pepijn van der Stap, also known by his online alias Umbreon, who is a director of a local cybersecurity company, has been arrested in a dramatic police raid.
Van der Stap is not only accused of being one of the notorious core leaders of the international hacker group ShinyHunters, but authorities also found evidence on his computer suggesting his involvement in planning two overseas murder-for-hire cases.
The international attention on this arrest is primarily due to ShinyHunters’ recent aggressive attack on the US FBI’s recruitment portal (apply.fbijobs.gov), where the hackers claimed to have stolen terabytes of sensitive data, including social security numbers, medical records, intelligence missions, and family information of over 5,000 FBI employees. An internal FBI memorandum indicated that authorities are currently operating under the assumption that “all employee data has been compromised” and are taking necessary measures to address the situation.
In response to the multinational arrest that took place on September 15, FBI Director Kash Patel officially announced on social media platform X on Tuesday, September 29, that one of the core leaders of ShinyHunters had been successfully apprehended in a joint operation with the Dutch National Police, emphasizing the group’s involvement in several major cyberattacks in the US and Europe.
Patel stressed that the FBI team is collaborating with international partners and using this arrest as a breakthrough to uncover more leads on a global scale. Assistant Director of the FBI’s Cyber Division, Brett Leatherman, made an unusual public video statement on Tuesday warning hackers like van der Stap, “You know how to find us, and we know how to find you. I suggest you reach out to us while you still have a choice.”
Prior to his arrest, van der Stap was a well-known figure in the cybersecurity community. Back in 2023, he was convicted by a Dutch court and sentenced to four years (later reduced and paroled) for crimes such as hacking into the systems of several large companies under the alias “Umbreon,” conducting ransom schemes, and money laundering. He publicly swore to turn away from cybercrime, stating on his personal website that his past experiences led him to realize that “knowledge should be used to build and protect, not destroy.”
With his exceptional technical abilities, he successfully reintegrated into mainstream society. Before his arrest, van der Stap held the position of Offensive Security Lead at the cybersecurity company Neo Security in Amsterdam, where he was responsible for red team exercises and penetration testing. The company’s founder, Benjamin Korper, confirmed to Reuters that the police conducted a dramatic raid using flashbangs at van der Stap’s residence on the evening of September 15 and subsequently seized his belongings for investigation.
Korper expressed deep regret, having thoroughly vetted van der Stap before hiring him, believing in giving the young man a second chance, only to be met with “immense shock and betrayal.”
Aside from hacker extortion, Dutch authorities found detailed information on van der Stap’s laptops and other storage devices indicating his alleged involvement in planning two murders abroad. The police later released a statement clarifying that “evidence suggests the suspect ordered these murders, thereby also being charged with soliciting others to commit the crimes.”
It was emphasized that the murder-for-hire charges are a separate case from the ShinyHunters cybercrime case. Van der Stap is currently in custody and under full restrictions.
According to reports from Dutch media outlets like NL Times, faced with the strong crackdown from law enforcement, the ShinyHunters organization released a statement through channels vehemently denying any connection with van der Stap, claiming they have “no affiliation with this individual.” The group softened their previous demand for the FBI to retract an alert notice, stating their earlier statements were “just a marketing ploy” and they have no intention of disclosing data.
However, joint investigators from the Netherlands and the United States are continuing to probe van der Stap’s criminal activities linked to the organization, including the recent FBI case, and he is strongly suspected of masterminding the attack on the Dutch telecom operator Odido in February 2026, resulting in the theft of a large amount of customer sensitive data.
The legal proceedings are set to take place in Rotterdam, and as the criminal investigation progresses, more details of this multinational case involving cyber extortion, identity fraud, and dark web schemes are expected to come to light.
