Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Dutch Police Arrest Reformed Hacker Linked to ShinyHunters Data Theft and Extortion Campaigns

Dutch authorities detained Pepijn van der Stap, a convicted cybercriminal tied to ShinyHunters. The group’s subsequent attacks stole FBI data and targeted ransomware group Cl0p, underscoring the importance of continuous third‑party risk monitoring for audit readiness.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 krebsonsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
krebsonsecurity.com

Dutch Police Arrest Reformed Hacker Linked to ShinyHunters Data Theft and Extortion Campaigns

What Happened — Dutch authorities detained 24‑year‑old Pepijn van der Stap, a convicted cybercriminal who operated under the alias “Umbreon” and was identified as an active participant in the ShinyHunters data‑theft and extortion operations. Within days of his arrest, remaining ShinyHunters members escalated attacks, exfiltrating sensitive FBI data and attempting to extort the ransomware group Cl0p.

Why It Matters for Trust & Control Assurance

  • The incident illustrates the risk of insiders or “reformed” actors who retain privileged knowledge and can re‑engage in illicit activity, underscoring the need for continuous third‑party risk monitoring and evidence of due‑diligence.
  • A robust vendor‑risk program provides a defensible audit trail that demonstrates you have vetted, monitored, and can quickly isolate personnel with access to sensitive data or systems.
  • Continuous control‑assurance tooling (e.g., Verisq’s Third‑Party Risk Management) helps surface anomalous behavior and maintains compliance posture across frameworks that map to the same control objective.

Who Is Affected

  • Government agencies (e.g., FBI) whose data was exfiltrated.
  • Organizations that employ or contract with individuals who have a history of cybercrime, especially in the security‑services sector.

Recommended Actions

  • Review all current third‑party and contractor relationships for prior cyber‑crime convictions or suspicious activity.
  • Implement continuous monitoring of privileged accounts and conduct periodic re‑certification of access rights.
  • Document oversight activities to satisfy audit‑readiness for frameworks that reference third‑party risk (e.g., NIST CSF 2.0).

Technical Notes – ShinyHunters typically harvest credentials from previously breached databases, then use automated scripts to scrape, aggregate, and sell data on underground forums. The group’s recent extortion of Cl0p involved threatening to release internal ransomware tooling. Source: Krebs on Security

📰 Original Source
https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →