Full Report
Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p. According to three sources familiar with the matter, the Dutch man arrested by authorities this month is Pepijn van der Stap, a convicted cybercriminal from Almere and Lelystad in the Netherlands. Van der Stap was previously convicted in 2023 in connection with a string of data thefts and extortions that prosecutors said earned between €1.5 million and €2.7 million. At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle “Umbreon” to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached. By day, however, van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian, while volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research group.
Analysis Summary
# Incident Report: Arrest of Pepijn van der Stap & Subsequent ShinyHunters Escalation
## Executive Summary
Dutch authorities arrested 24-year-old Pepijn van der Stap (aka "Umbreon") on suspicion of aiding the ShinyHunters hacking collective. Following his arrest, the group retaliated by breaching the FBI’s recruitment portal and extorting the Cl0p ransomware group. The incident highlights the "insider threat" risk posed by cybercriminals operating within legitimate security organizations.
## Incident Details
- **Discovery Date:** September 16, 2026 (Approximate date of arrest)
- **Incident Date:** February 2026 (Odido hack); September 2026 (FBI/Cl0p escalation)
- **Affected Organization:** Odido (Netherlands), FBI (USA), Cl0p Ransomware Group
- **Sector:** Telecommunications, Government, Cybercrime
- **Geography:** Netherlands, United States
## Timeline of Events
### Initial Access
- **Date/Time:** February 2026
- **Vector:** Social Engineering / Phishing
- **Details:** A ShinyHunters member (suspected to be Van der Stap) used a spoofed website to trick an Odido employee into providing login credentials.
### Lateral Movement
- **Details:** Using the stolen credentials, the attackers gained access to Odido’s internal customer databases.
### Data Exfiltration/Impact
- **Odido:** Theft of personal data belonging to 6.2 million Dutch citizens.
- **FBI:** Post-arrest retaliation led to the theft of Social Security numbers and personal data of 5,000+ officials via `apply.fbijobs.gov`.
- **Cl0p:** Extortion of the rival ransomware group.
### Detection & Response
- **Discovery:** Dutch police identified a voice recording of the Odido social engineering call.
- **Response Actions:** Surveillance and eventual arrest of Van der Stap at his residence; seizure of electronic equipment.
## Attack Methodology
- **Initial Access:** Vishing (voice phishing) and credential harvesting via spoofed websites.
- **Persistence:** Not explicitly detailed, though the suspect maintained a dual life as a security professional.
- **Defense Evasion:** Using legitimate employment at cybersecurity firms (Hadrian, Neo Security) and volunteer positions at DIVD to mask criminal activity.
- **Collection:** Targeting centralized databases (telecom customer data, government job applications).
- **Exfiltration:** Posting data on illicit forums (RaidForums, Breached).
- **Impact:** Massive data theft and retaliatory extortion.
## Impact Assessment
- **Financial:** Van der Stap’s prior activities earned €1.5M–€2.7M; subsequent impacts include potential regulatory fines for Odido.
- **Data Breach:** Exposure of sensitive PII (SSNs, job titles, phone numbers) for over 6.2 million civilians and 5,000 FBI officials.
- **Operational:** Disruption of FBI recruitment services and Odido security operations.
- **Reputational:** Significant damage to the Dutch cybersecurity firms and non-profits (DIVD) that unknowingly employed the suspect.
## Indicators of Compromise
- **Network Indicators:** Spoofed login portals (e.g., `odido-login.[redacted].nl`).
- **Behavioral Indicators:** Dual-use of professional security tools for illicit data exfiltration; voice patterns matching suspect in vishing calls.
## Response Actions
- **Containment:** Arrest of the primary suspect and seizure of infrastructure.
- **Eradication:** Law enforcement efforts to identify remaining ShinyHunters members.
- **Recovery:** FBI and Odido ongoing forensic audits of affected web applications.
## Lessons Learned
- **The "Reformed" Hacker Risk:** Background checks and continuous monitoring are essential for hires with prior criminal records, even those claiming rehabilitation.
- **Social Engineering Resilience:** The Odido breach emphasizes that technical controls are easily bypassed by convincing vishing/phishing campaigns.
- **Retaliatory Cycles:** High-profile arrests of group members can trigger immediate "reflexive" attacks from remaining cells to project strength.
## Recommendations
- **Zero Trust Architecture:** Implement strict MFA (preferably hardware-based) to mitigate credential harvesting via spoofed sites.
- **Enhanced Vetting:** Security startups and research groups (like DIVD) should implement more rigorous oversight for volunteers with access to sensitive disclosures.
- **Vishing Training:** Employee awareness programs should specifically include simulations of voice-based social engineering.