Dutch Police Detain Amsterdam Cybersecurity Worker in ShinyHunters Probe
The arrest adds to market scrutiny of cyber-risk exposure after ShinyHunters claimed breaches involving FBI data, telecom records and major platforms.

Dutch police have detained a 24-year-old Amsterdam resident as part of an investigation into the hacking group ShinyHunters, a case now drawing attention well beyond law enforcement because of the group’s claimed links to breaches involving government, telecom, gaming and education data. The detention was announced by Dutch police on Monday, September 28, following ShinyHunters’ claim last week that it had breached a database connected to the U.S. Federal Bureau of Investigation and stolen employee data.
For market participants, the case lands in a risk category that has become increasingly difficult to treat as isolated from valuation, compliance and operational continuity. ShinyHunters has been associated with several large data leaks, including a February 2026 breach of databases at Odido, the largest mobile operator in the Netherlands, that gave the group access to data on more than 6.2 million residents of the country. The group has also been linked to the alleged theft of millions of corporate records from Rockstar Games, the video-game developer known for the Grand Theft Auto series, and to a May attack on the Canvas education platform that caused widespread disruption in U.S. schools.
Cyber-Risk Watch Intensifies Across Sectors
Dutch police did not name the suspect and did not state the exact date of the arrest in their post on X, saying only that it took place in September. The suspect was expected to appear before a court in Rotterdam on Tuesday, September 29.
Benjamin Korper, a representative of the Amsterdam cybersecurity company Neo Security, told Reuters that the detained man was Pepijn van der Stap, who leads the company’s offensive cybersecurity practice. According to Korper, his employee was arrested on September 15 “during a large-scale police operation involving flashbang grenades.” On the same day, forensic officers visited Neo Security’s office.
ShinyHunters said van der Stap “has nothing to do” with the group.
“He has nothing to do with ShinyHunters,” the group said, according to the source account of the case.
The matter is particularly sensitive for cybersecurity firms and their clients because the suspect identified by Neo Security has a prior criminal conviction tied to data theft and extortion. In 2023, van der Stap was sentenced to four years in prison, one year of which was suspended, after a court found him guilty of a series of data thefts and extortion. Law enforcement estimated that he earned between 1.5 million euros and 2.7 million euros from those crimes.
According to investigators in that earlier case, van der Stap committed the offenses while working at Hadrian, an Amsterdam startup specializing in cybersecurity, and while volunteering at DIVD, a nonprofit research organization focused on finding computer vulnerabilities. During the trial, he admitted guilt and expressed remorse.
Van der Stap was released early in December 2025. In an interview with Brian Krebs, author of the KrebsonSecurity blog, shortly before the new detention, he described himself as a hacker who had turned toward rehabilitation, was seeking to change his life for the better and wanted to benefit society. Korper described his employment at Neo Security as a “second chance” for his employee.
FBI Claim Raises Operational and Compliance Questions
On September 22, ShinyHunters published a message on the dark web claiming it had breached an FBI database and stolen data belonging to numerous current and former bureau employees. The group claimed the information included psychiatric and medical examination records of agents. It also said it had obtained access to data belonging to FBI Director Kash Patel. Reuters was able to partially verify the authenticity of the published data.
FBI representatives said they were “aware of claims of unauthorized activity” affecting the FBIjobs.gov applicant website and were investigating.
For investors and corporate security teams, the immediate issue is not only whether the FBI-related claims are fully substantiated. The broader signal is that threat actors continue to target systems that sit near recruitment, employee vetting, customer records and third-party platforms. Those systems often contain data that is not directly tied to trading desks or revenue generation but can trigger reputational damage, regulatory scrutiny and costly incident response.
The ShinyHunters case also reinforces the cross-sector pattern of cyber incidents. Telecom operators face exposure through mass customer databases. Gaming companies hold valuable corporate and user records. Education technology platforms can become single points of failure for schools. Government recruitment and personnel systems can contain sensitive individual information. That breadth matters for markets because cyber events can move from technical incident to material disclosure, legal liability or vendor-risk review with little warning.
The Odido case remains one of the largest claims associated with the group in the Netherlands. In February 2026, after breaching databases at the country’s largest mobile operator, ShinyHunters obtained access to data on more than 6.2 million residents, according to the source account. The group’s alleged reach into Rockstar Games and Canvas adds to a profile of attacks spanning consumer, enterprise and public-facing systems.
The Dutch detention may therefore become a key reference point for assessing law-enforcement pressure on high-profile hacking groups. Yet the conflicting claims around the suspect’s identity, role and alleged links to ShinyHunters leave important facts unresolved. Dutch police have not publicly identified the man they detained. Neo Security has identified him as van der Stap. ShinyHunters denies that he is connected to the group. The court appearance in Rotterdam is expected to provide the next procedural marker in a case that markets will watch through the lens of cyber exposure, liability and operational resilience.



