
ShinyHunters Arrest: Dutch Police Detain Convicted Hacker
.webp)
Dutch national police have confirmed the arrest of a 24-year-old Amsterdam man in their investigation into ShinyHunters, the extortion crew behind several of the largest data thefts of the past two years. The force's national investigation unit acknowledged the detention on Monday, September 28. It said the man would appear before the Rotterdam District Court the following day. Officers named no victims, listed no charges, and gave no account of what the suspect is alleged to have done.
Tuesday's hearing went before the raadkamer, the chamber that reviews pretrial detention rather than guilt. Its task was narrow: decide if the man stays in custody while investigators keep working. Police promised more detail once the chamber ruled, which leaves this ShinyHunters arrest in an unusual position. The detention is on the record, the investigation's target is on the record, and almost everything joining the two rests on reporting instead.
What Police Confirmed About the ShinyHunters Arrest
The confirmed facts are thin, and worth separating from the rest. A tactical police unit searched a home in Amsterdam's Rivierenbuurt district on September 15 and seized electronic devices. The man lived at that address with his mother.
Officers then held him for questioning inside the ShinyHunters investigation, and the arrest stayed out of public view for close to two weeks. That silence is standard practice during a live inquiry, though it left the story to develop without official framing.
What police have left unsaid carries just as much weight. They have not tied the suspect to a specific intrusion, extortion demand, or victim organisation. They have not described his alleged role, and they have not confirmed his name. Dutch practice limits authorities to initials at most, so much of what the public knows about the ShinyHunters arrest comes from outside the official record.
The Name Outside the Official Record
Dutch broadcasters and independent security researchers identified the man arrested in the ShinyHunters case as Pepijn van der S., a convicted cybercriminal who operated online as "Umbreon". Three sources familiar with the investigation pointed to the same person.
His employer then confirmed it openly. Benjamin Korper runs the Amsterdam security firm Neo Security, and he said the arrested man works there as offensive security lead. Forensic investigators visited the company's office on September 15, the day of the raid.
An internal review afterwards turned up no sign that anyone had touched the firm's own systems or its client environments. Neo Security faces no accusation of wrongdoing. Korper said he believed in second chances and called the news a shock.
A Probation Period That Was Still Running
The suspect's earlier case explains why this ShinyHunters arrest carries real weight in the Netherlands. Police first arrested him in January 2023 over the hacking and blackmail of more than a dozen companies. He gave a near-full confession at trial. The court convicted him of computer intrusion, extortion, blackmail, ransomware deployment, and habitual money laundering.
His sentence came to four years with one year suspended, plus three years of probation carrying extra conditions. Prosecutors had asked for six years. The court cited his cooperation, his youth, and psychological factors as grounds for a lighter term. His lawyer argued the offences grew out of personal trauma rather than greed.
Cryptocurrency ran through the whole case. Judges established that he laundered more than €1.5 million in cryptocurrency. One victim alone paid 24.736 BTC to end an extortion attempt. He left prison around December 2025 and found paid security work again within months.
Why the Umbreon Link Falls Short of Proof
The public thread joining the arrest to ShinyHunters runs through a Pokémon character. The suspect used the Umbreon handle and matching imagery on BreachForums as early as 2021. He also sold a database on 2.3 million Dutch citizens under that name. ShinyHunters now treats the same character as its calling card, and it surfaced both in the September 19 defacement of Clop's leak site and in the group's claimed breach of the FBI jobs portal.
That overlap points somewhere, but it proves nothing on its own. The same Umbreon artwork appeared in an August 2020 defacement of HackForums, a year before the suspect registered his account. Anyone tracing the alias inherits the ambiguity investigators are working through, which explains why police have framed the ShinyHunters arrest so narrowly.
The Odido Voice Recording Does Not Match
Earlier in September, police released audio of a Dutch-speaking man suspected of involvement in the Odido breach. The caller posed as a member of the telecom's IT department. He then talked a help desk employee into entering credentials and a verification code on a fake login page.
Reporters who have spoken with the suspect by phone say the voice on that recording is not his, and a close friend reached the same conclusion. The Odido breach exposed data on roughly 6.2 million customers in February. No public evidence or charge connects the arrested man to that intrusion, even though ShinyHunters carries a firm link to it.
What One Arrest Changes for ShinyHunters
ShinyHunters dismissed the arrest outright when asked about it.
"That individual has no association with us. Frankly, we are laughing," a representative said. The group also called Dutch police incompetent.
That denial serves the group's own interests, so it settles nothing. It does sit oddly against an earlier response, though. When Dutch authorities named a different Odido suspect in early September, ShinyHunters publicly described that person as a full member.
A single ShinyHunters arrest lands against an operation that behaves less like a crew and more like a revolving collective. Estimates circulating among incident responders put the group on course for close to $100 million in extortion payments during 2026. Inside the Netherlands it carries links to the Odido theft and to the Instructure Canvas breach that hit students and staff at the VU and the University of Amsterdam.
The run beyond Dutch borders has been just as busy. It covers a claimed breach of Florida's DAVID driver database, the Clop defacement, the FBI jobs portal claim, and an Oracle PeopleSoft exploitation campaign that reached universities and corporations. Detaining one alleged contributor does not dismantle an operation moving at that pace.
What Comes Next
Attention now sits with the Rotterdam chamber's decision and the police statement that follows it. Formal charges, if prosecutors bring them, will reveal if the case rests on more than a shared alias, and the seized devices will settle much of that. Dutch investigators made an arrest they believe advances a ShinyHunters case. For now, the narrowest reading of the facts stays the safest one.
For organisations watching, the practical lesson lands elsewhere. The Odido intrusion started with one phone call to a help desk, not with a sophisticated exploit. Strict verification for anyone claiming to be internal IT stays the cheapest defence against it.
Subscribe to receive the latest blog posts to your inbox every week.