Dutch Arrest Puts ShinyHunters Case in Corporate Cybersecurity Spotlight
The detention of an Amsterdam cybersecurity specialist raises fresh questions for companies weighing second-chance hiring against escalating data-breach risks.

Dutch police have detained a 24-year-old Amsterdam resident as part of an investigation into ShinyHunters, the hacking group that last week claimed it had breached a database connected to the U.S. Federal Bureau of Investigation and stolen data on bureau employees. The case is now drawing attention not only as a law-enforcement matter, but also as a test of corporate cybersecurity governance, hiring judgment and reputational risk management.
Police in the Netherlands announced on Monday, September 28, that a 24-year-old man from Amsterdam had been detained in connection with the investigation into ShinyHunters. The group said last week that it had breached an FBI database and taken information on agency staff. Police did not disclose the precise date of the detention in their post on X, saying only that it took place in September. The suspect was expected to appear before a court in Rotterdam on Tuesday, September 29.
Dutch authorities have not named the detained man. However, Benjamin Corper, a representative of Amsterdam-based cybersecurity company Neo Security, told Reuters that the suspect is Pepijn van der Stap, who leads offensive cybersecurity at the company. According to Corper, his employee was detained on September 15 “during a large-scale police operation using flashbang grenades.” On the same day, forensic officers visited Neo Security’s office.
ShinyHunters said van der Stap “has nothing to do with” the group.
A Second-Chance Hire Under Scrutiny
The reported identity of the suspect puts Neo Security’s management decisions under a sharp spotlight. Van der Stap was convicted in 2023 and sentenced to four years in prison, one of them suspended, after a court found him guilty of a series of data thefts and extortion. Law-enforcement authorities estimated that he earned between 1.5 million and 2.7 million euros from those crimes.
Investigators said van der Stap committed the offenses while working at Hadrian, an Amsterdam startup specializing in cybersecurity, and while volunteering at DIVD, a nonprofit research organization focused on identifying computer vulnerabilities. During the trial, he admitted guilt and expressed remorse.
Van der Stap was released early in December 2025. Shortly before the new detention, he told Brian Krebs, author of the KrebsonSecurity blog, that he considered himself a hacker who had chosen a path of rehabilitation, wanted to change his life for the better and hoped to be useful to society. Corper described his employment at Neo Security as a “second chance” for the employee.
For cybersecurity firms, the situation illustrates a difficult business dilemma. Offensive security teams often rely on people who understand attacker behavior deeply, including specialists whose skills may have been developed in ambiguous or unlawful settings. That talent can be commercially valuable as companies compete for expertise in penetration testing, vulnerability research and threat simulation. But the same hiring decisions can expose firms to legal, operational and reputational risk if governance controls are not robust and transparent.
ShinyHunters and the Competitive Cyber Risk Landscape
The latest allegations also place ShinyHunters back at the center of the global cybercrime landscape. On September 22, the group published a message on the dark web claiming it had breached an FBI database and stolen data belonging to many former and current bureau employees. The group claimed the information included psychiatric and medical examination records of agents. It also said it had obtained access to data belonging to FBI Director Kash Patel. Reuters was able to partially verify the authenticity of the published data.
FBI representatives said they were “aware of claims of unauthorized activity” affecting the FBIjobs.gov applicant website and were investigating. For public-sector agencies and companies alike, the reported target is significant because recruitment platforms can contain sensitive personal information, employment histories and medical or assessment records. Such systems are often adjacent to core operations but can still create major exposure when compromised.
ShinyHunters has also been linked to several other large data breaches. In February 2026, after a breach of databases belonging to Odido, the largest mobile operator in the Netherlands, the group gained access to data on more than 6.2 million residents of the country. Other recent attacks attributed to ShinyHunters include the alleged theft of millions of corporate records from video game developer Rockstar Games, known among other things for the Grand Theft Auto series, and a May attack on the Canvas education platform that caused widespread disruptions in U.S. schools.
For boards and executive teams, the pattern matters. ShinyHunters’ alleged targets span government hiring infrastructure, telecommunications, gaming and education technology. That breadth suggests a threat model in which data-rich organizations face sustained pressure regardless of sector. The commercial consequences can include customer churn, litigation exposure, regulatory scrutiny, operational disruption and higher security spending.
The Dutch arrest also raises broader questions about how cybersecurity companies present trust to clients. A firm that offers offensive cybersecurity services sells not just technical capability but assurance that its internal controls, staff vetting and ethical boundaries are credible. When an employee in a senior offensive role becomes connected to a high-profile criminal investigation, even without a proven link to the alleged group, the company’s risk posture can become part of the story.
At this stage, key facts remain unresolved. Dutch police have not publicly named the suspect, ShinyHunters denies van der Stap’s connection to the group, and the FBI says it is investigating the reported unauthorized activity. What is already clear is that the case sits at the intersection of cybercrime enforcement, corporate hiring strategy and the market for offensive security talent. For businesses, it is a reminder that cybersecurity risk increasingly extends beyond systems and software into management judgment, governance discipline and the competitive race for scarce expertise.



