Press play to start listening
Pepijn van der Stap currently works as Offensive Security Lead at Dutch cybersecurity firm Neo Security.
Dutch authorities have confirmed the arrest of a 23-year-old man as part of their investigation into the February cyberattack against telecom provider Odido, an attack claimed by ShinyHunters. Multiple sources have identified the arrested man as convicted Dutch hacker and security researcher Pepijn van der Stap.
The Dutch police media desk confirmed the arrest after reports about the development appeared on Sunday. Police have not publicly named the suspect, but three sources familiar with the investigation told cybersecurity journalist Brian Krebs that the man in custody is Van der Stap. Sources cited by Krebs said he was arrested on or around September 16 and has remained in custody for questioning.
The arrest follows a months-long investigation by the Dutch National Police and Public Prosecution Service into the Odido breach. ShinyHunters claimed responsibility for the attack, which exposed information belonging to more than six million customers after Odido refused to pay a ransom.

Odido Hack Began With a Phone Call
Investigators previously established that a Dutch-speaking man called Odido customer service shortly before the breach and pretended to work in the company’s IT department. Using internal terminology, the caller convinced an employee that he needed help resolving a technical problem.
The employee was directed to a fake Odido login page, where the username and password were entered. The caller then persuaded the employee to provide the additional verification code needed to access Odido’s internal systems.
Police released a recording of the caller earlier this month and asked the public for help identifying him. Authorities described the voice as genuine, Dutch-speaking and knowledgeable about IT, but have not publicly confirmed that Van der Stap is the person heard in the recording.
ShinyHunters previously told Dutch media that the person in the recording was one of its members and said it would provide him with legal and financial support.
Hackread.com reported in February that ShinyHunters initially published two million Odido records after negotiations failed. The group claimed at the time that it had stolen considerably more data from the telecom provider.
Who is Pepijn van der Stap?
Van der Stap has a documented history in both cybersecurity and cybercrime. In 2023, an Amsterdam court sentenced him to four years in prison, with one year suspended, after he admitted involvement in hacking, data theft and extortion. Prosecutors said the criminal activity generated between €1.5 million and €2.7 million.
During that period, Van der Stap used the online name “Umbreon,” taken from the Pokémon character. A look at the alias’ activity on cybercrime and hacking forums like RaidForums and Breached revealed it was being actively used for selling stolen databases and extorting victims on hacking forums.
At the same time, he worked as a software engineer at cybersecurity company Hadrian and volunteered with the Dutch Institute for Vulnerability Disclosure (DIVD).
Van der Stap was released from prison in December 2025 and returned to cybersecurity work. Shortly before his reported arrest, he was working as offensive security lead at Dutch cybersecurity company Neo Security.
His own website presents him as a security researcher and protocol engineer. Van der Stap writes that his past taught him that security knowledge should be used for protection, and says he has submitted more than 100,000 responsible disclosure reports during his career.
Krebs interviewed Van der Stap on September 9, about a week before the reported arrest. Van der Stap described himself as having left cybercrime behind and said he was trying to contribute positively to cybersecurity while dealing with civil claims and restitution resulting from his previous crimes.
Umbreon and the Recent ShinyHunters Activity
The Umbreon alias has become relevant again because the Pokémon character has featured prominently in recent ShinyHunters material. As reported by Hackread.com, the defacement placed on the FBI Jobs portal this month contained a large ASCII representation of Umbreon. The same character has appeared in other material connected with the group.
That alone does not establish that Van der Stap participated in the FBI attack. Sources cited by Krebs described internal conflict involving another hacker known as “Rey” and suggested the use of Umbreon imagery could have been intended to associate the FBI operation with Van der Stap. Dutch authorities have not accused Van der Stap publicly of participating in the FBI breach.
The reported arrest also predates several aggressive actions attributed to ShinyHunters this month. Days after Van der Stap was reportedly detained, the group took control of Clop’s dark web leak site and demanded an eight-figure payment from the ransomware operation. ShinyHunters later defaced the FBI Jobs portal and claimed to have stolen sensitive employee and applicant information.
The confirmed arrest concerns the investigation surrounding the Odido attack, while Van der Stap’s identification as the suspect comes from sources familiar with the case. The Dutch police investigation remains active, and authorities have not publicly detailed the evidence against him or confirmed whether he is the Dutch-speaking caller whose voice was released earlier this month.
Hackread.com has reached out to ShinyHunters for comment.

