The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

Dutch police arrested 24-year-old Amsterdam resident Pepijn van der Stap in September 2026 as part of an ongoing investigation into the ShinyHunters cybercriminal group. Van der Stap, previously known online as 'Umbreon,' was already on probation from a 2023 conviction for hacking and extorting over a dozen companies worldwide. Authorities are examining potential connections between his 'Umbreon' identity and recent ShinyHunters campaigns, including alleged FBI breaches and attacks on the Clop ransomware gang's infrastructure. The arrest involved a tactical police unit search of his Amsterdam residence and seizure of electronic devices.

This incident highlights the persistent threat of repeat cybercriminals and the challenges law enforcement faces in dismantling organized hacking groups like ShinyHunters, which continue high-profile data breaches and extortion campaigns despite increased scrutiny and arrests of suspected members.

Why This Matters Now

Organized cybercriminal groups like ShinyHunters continue operating despite law enforcement pressure, demonstrating the need for enhanced monitoring of known threat actors and stronger international cooperation to disrupt persistent data breach and extortion operations targeting critical infrastructure.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Pepijn van der Stap is a 24-year-old Dutch hacker known online as 'Umbreon' who was previously convicted in 2023 for hacking and extorting companies. Authorities are investigating potential links between his online identity and the ShinyHunters cybercriminal group.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained the ShinyHunters attack against Odido by limiting lateral movement capabilities and reducing the scope of data accessible through compromised credentials. The segmented architecture would likely have contained the breach impact and reduced the overall blast radius of customer data exposure.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Identity-aware access controls would likely have limited the scope of systems accessible through the compromised credentials, constraining the attacker's initial foothold within the cloud environment

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely have constrained the ability to assume elevated IAM roles and limited token manipulation capabilities across cloud service boundaries and workload environments

Lateral Movement

Control: East-West Traffic Security

Mitigation: Workload-to-workload traffic inspection and segmentation policies would likely have constrained lateral movement paths and reduced the attacker's ability to discover and access sensitive data repositories

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Comprehensive traffic visibility and anomaly detection across cloud environments would likely have identified unauthorized communication patterns and constrained persistent command channel establishment capabilities

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies and data loss prevention mechanisms would likely have constrained large-scale data transfer capabilities and reduced the volume of customer information accessible for extraction

Impact (Mitigations)

While some customer data exposure might still occur through the initial compromise, the overall impact would likely be significantly constrained with reduced scope of accessible records and limited regulatory exposure

Impact at a Glance

Affected Business Functions

  • Law Enforcement Operations
  • Criminal Justice Processing
  • Cybersecurity Investigation
  • International Cooperation
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Investigation relates to past data breaches and extortion activities by ShinyHunters group affecting multiple organizations. Specific current data exposure limited to law enforcement investigation materials and seized electronic devices from suspect's residence.

Recommended Actions

  • • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement after initial compromise
  • • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts
  • • Establish Multicloud Visibility & Control to monitor anomalous interactions and suspicious automation patterns
  • • Enable East-West Traffic Security to inspect workload-to-workload communications and detect internal pivoting
  • • Deploy Encrypted Traffic inspection capabilities to prevent data theft through covert channels

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image