Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Dutch Police Arrest Suspect Tied to ShinyHunters Hacker Group Amid Ongoing Credential‑Harvesting Campaign

Dutch police detained Pepijn van der Stap, a figure tied to the ShinyHunters group, after a raid seized his devices. The investigation underscores how voice‑phishing can bypass technical safeguards, making continuous identity‑access monitoring and security‑awareness training essential for audit readiness.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

Dutch Police Arrest Suspect Tied to ShinyHunters Hacker Group Amid Ongoing Credential‑Harvesting Campaign

What Happened — Dutch police confirmed the arrest of 24‑year‑old Pepijn van der Stap, alleged to be linked to the ShinyHunters hacking group. Van der Stap, previously convicted for hacking and blackmailing dozens of companies, was detained after a tactical raid seized his electronic devices. Authorities are investigating his possible role in recent ShinyHunters operations, including a voice‑phishing call that tricked an Odido help‑desk employee into revealing credentials.

Why It Matters for Trust & Control Assurance —

  • The case exemplifies how credential‑harvesting groups exploit social engineering to bypass technical controls, underscoring the need for continuous identity‑access monitoring.
  • Demonstrates the importance of documented security‑awareness programs that can provide audit‑ready evidence of employee training and phishing‑simulation results.
  • Highlights the requirement for a defensible incident‑response trail when suspected actors are identified, supporting governance under frameworks such as NIST CSF 2.0.

Who Is Affected — Technology‑SaaS providers, telecom operators, and any organization that relies on help‑desk or remote‑support functions.

Recommended Actions —

  • Verify that multi‑factor authentication (MFA) is enforced for all privileged and remote‑access accounts.
  • Conduct targeted phishing simulations and refresh security‑awareness training focused on voice‑phishing (vishing) tactics.
  • Review and tighten logging of credential‑use events; integrate alerts into a continuous monitoring platform.

Source: BleepingComputer

Technical Notes — The suspect used the “Umbreon” alias on breach forums and is linked to ShinyHunters’ recent use of Pokémon imagery in credential‑stealing campaigns. The Odido incident involved a voice‑phishing call that harvested a username, password, and verification code via a fake login page. No specific CVE or software flaw was disclosed. Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/dutch-police-confirm-arrest-in-shinyhunters-hacking-investigation/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →