The short version
- Dutch police confirmed the arrest of a 24-year-old Amsterdam man as part of an investigation into the ShinyHunters hacking group.
- The suspect has previously been convicted in a separate hacking and blackmail case and later worked in offensive security.
- Authorities have not publicly established that he was part of ShinyHunters and the group has denied an association.
Amsterdam has become the centre of a new development in the investigation surrounding ShinyHunters after Dutch police confirmed that a 24-year-old man was arrested in connection with the group. The suspect is due to appear before a Rotterdam court as authorities continue examining the possible relationship between the individual and the cybercrime operation.
A previous hacking conviction is part of the background
The suspect has been publicly identified by security reporting as Pepijn van der Stap, who previously used the online alias Umbreon. He was arrested in an earlier case and later convicted over hacking and blackmail offences involving companies in the Netherlands and abroad. After serving part of his sentence, he moved into legitimate security work.
That history is one reason the latest arrest has attracted attention across the security community. A previous criminal record can establish technical experience, but it does not by itself prove involvement in a later intrusion. Dutch authorities have not publicly laid out evidence showing that the suspect operated as part of ShinyHunters.
The investigation is also examining online identities and infrastructure associated with the hacking group. Researchers have pointed to the repeated use of Pokémon imagery and the Umbreon identity as one possible connection. That clue remains circumstantial because the same alias and imagery can be copied by other actors.
The attribution question remains open
BleepingComputer reported that authorities were examining a possible connection between the suspect and ShinyHunters while the group itself denied that he was associated with it. That leaves an important distinction between an arrest connected to an investigation and a confirmed attribution.
Dutch police have previously investigated social-engineering activity involving corporate help desks. In one case described in security reporting, an attacker posed as an IT employee and persuaded a help-desk worker to enter credentials and a verification code into a fraudulent login page. The technique illustrates why identity abuse and human manipulation remain central to modern intrusions even when a campaign later becomes technically sophisticated.
The arrest adds a person to the investigation. It does not by itself establish the person’s role in the wider ShinyHunters operation.
The next stage will depend on evidence gathered from seized devices, communications, financial records and infrastructure. Investigators will also have to separate material directly tied to an intrusion from older online identities that may have been reused by unrelated actors.
For defenders, the case is another reminder that cybercrime investigations often move through several layers at once. The same operation can involve social engineering, stolen credentials, access brokers, data theft and extortion while the people behind each stage remain difficult to identify.
The latest police development is being tracked alongside reporting from BleepingComputer and other security researchers. Until Dutch investigators publish further evidence, the connection between the arrested man and ShinyHunters remains an allegation under investigation rather than an established fact.
The case is expected to develop through the Dutch court process and further investigative disclosures.