Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Dutch Police Arrest 24‑Year‑Old Hacker Tied to ShinyHunters Group

Dutch police have detained Pep Jin van der Stap, a 24‑year‑old alleged member of the ShinyHunters cybercrime group, after a raid seized his devices. The suspect’s history of data theft and extortion underscores the importance of continuous vendor‑risk monitoring and personnel‑security controls for audit readiness.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
1 recommended
📰
Source
securityaffairs.com

Dutch Police Arrest 24‑Year‑Old Hacker Tied to ShinyHunters Group

What Happened — Dutch authorities arrested a 24‑year‑old Amsterdam resident identified as Pep Jin van der Stap, an alleged member of the ShinyHunters cybercrime group. The suspect, previously convicted for large‑scale data theft and extortion, was seized together with several electronic devices during a raid on his home.

Why It Matters for Trust & Control Assurance

  • The case highlights the risk of insider threats when individuals with advanced offensive skills are employed by security‑focused firms.
  • Continuous vendor‑risk monitoring and robust personnel‑security controls are essential to detect and mitigate such hidden affiliations.
  • Demonstrable evidence of due‑diligence (background checks, ongoing monitoring) provides a defensible audit trail for governance frameworks.

Who Is Affected – Technology and security‑services firms, especially those hiring offensive security talent; downstream customers that rely on those firms for protection.

Recommended Actions

  • Review and tighten background‑screening procedures for security‑team hires, including periodic re‑validation of affiliations.
  • Integrate third‑party risk data feeds into a continuous monitoring platform to flag emerging criminal ties.
  • Document all due‑diligence activities to support audit readiness under governance frameworks (e.g., NIST CSF 2.0).

Technical Notes – The suspect’s alleged activities involved credential harvesting, data exfiltration, and extortion of multiple companies worldwide. No new breach was disclosed in this arrest, but the historical pattern underscores the need for strong personnel and vendor oversight. Source: SecurityAffairs

📰 Original Source
https://securityaffairs.com/199979/cyber-crime/24-year-old-arrested-in-dutch-investigation-into-shinyhunters.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →