
Dutch Police Arrest Previously Convicted Hacker in ShinyHunters Case
Dutch police arrested Pepijn van der Stap in connection with an investigation into ShinyHunters, a name long associated with large-scale data theft and extortion campaigns, according to a report published September 29, 2026 by SecurityWeek. Van der Stap is not a first-time offender: Dutch courts convicted him in 2023 for hacking multiple organizations, stealing their data, and extorting them for payment.
The source reporting does not specify the exact charges tied to this new arrest, what evidence links van der Stap to the ShinyHunters investigation, or whether additional suspects have been detained. What is confirmed is narrower and more concrete: a person with a documented 2023 hacking and extortion conviction in the Netherlands has been taken into custody again as part of a law enforcement inquiry that authorities are connecting to the ShinyHunters name.
Readers should treat the ShinyHunters connection as the stated basis for this arrest, not as a confirmed finding about the full scope of van der Stap's alleged conduct in this new case. Details on formal charges, court proceedings, or a plea will determine what, if anything, is ultimately proven.
Key Takeaway
A hacker convicted in the Netherlands in 2023 for data theft and extortion has been arrested again in 2026 in connection with a ShinyHunters-linked investigation. For businesses, the case is a reminder that extortion-focused threat actors operate as an ongoing ecosystem, not a single incident, and that credential theft and third-party access remain the most common entry points into that ecosystem.
What Is ShinyHunters, and Why Does This Case Matter?
ShinyHunters is a name cybersecurity researchers and law enforcement have used since 2020 to describe threat activity centered on large-scale data theft followed by extortion, where attackers demand payment to prevent the release or sale of stolen records. Security researchers have linked activity carrying the ShinyHunters name to intrusions at multiple companies over the years, frequently involving stolen login credentials, compromised third-party software connections, and cloud data platforms rather than sophisticated custom malware. The 2024 wave of breaches affecting customers of the cloud data platform Snowflake, which Snowflake itself acknowledged stemmed from compromised customer credentials rather than a flaw in its own systems, is one widely reported example researchers associated with this activity.
This pattern matters more than any single arrest. Extortion-driven groups tend to reuse the same access techniques across many victims: purchased or stolen credentials, unsecured API tokens, and accounts left without multi-factor authentication. A repeat conviction like van der Stap's fits a broader trend researchers have flagged in ransomware and extortion cases: individuals connected to one group or campaign often resurface in later investigations tied to different but overlapping criminal networks.
What remains unclear from the current reporting is whether Dutch authorities consider van der Stap a member of ShinyHunters, a facilitator, or a subject whose prior case shares infrastructure or victims with the group's activity. Readers should watch for follow-up statements from the Dutch National Police or public prosecutor's office (Openbaar Ministerie) for formal charges, which would clarify the actual legal basis for the arrest.
What This Means For Your Business
Healthcare practices, tax preparation firms, and small businesses are common targets for extortion-style attacks precisely because they hold sensitive patient, financial, or client data and often run lean IT teams. The practical defenses that blunt this style of attack have not changed, even as the individuals behind them cycle through arrests and reoffending:
Enforce multi-factor authentication everywhere. Stolen or reused passwords are the most common way extortion groups gain initial access to cloud platforms, email, and remote access tools. MFA on every account that touches patient records, tax data, or financial systems closes the most exploited gap.
Audit third-party and vendor access. Data theft tied to cloud platforms and connected apps often traces back to a vendor integration or API token nobody was actively monitoring. Review which third parties can access your systems and revoke credentials for tools you no longer use.
Assume stolen credentials are already circulating. Practices handling protected health information or federal tax data should monitor for credential exposure and rotate passwords on a regular schedule rather than only after an incident.
Have a response plan before an extortion demand arrives. If your organization is contacted with a data theft and payment demand, involve legal counsel and law enforcement, such as the FBI's Internet Crime Complaint Center (IC3), before making any decisions. Paying does not guarantee data deletion and can create its own legal and compliance complications.
Bellator Cyber Guard will continue tracking developments in this case, including any formal charges Dutch prosecutors file against van der Stap, as they become available.
People also look for
Keep exploring Security basics
Start with the fundamentals, understand the most likely risks, and choose the next improvement without getting lost in jargon.
- Common question: cybersecurity basicsBuild better cyber hygieneCover the everyday habits and controls that prevent a large share of common incidents.
- Common question: why do hackers target small businessesUnderstand why smaller organizations get targetedSee how opportunity, automation, access, and recovery pressure shape attacker decisions.
- Common question: small business cyber risk assessmentStart with a cyber risk assessmentIdentify important assets, likely threats, current safeguards, and the most useful next steps.
- Common question: cybersecurity solutions for small businessCompare business security optionsFind the right starting point by audience, threat, or compliance need.
- Common question: how hackers choose targetsLearn how attackers choose targetsUnderstand what makes an organization or person visible and attractive to automated attacks.
Learn first. Decide when you are ready.
Keep learning, or apply this to your situation
Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.



