Executive Summary
Dutch police arrested 24-year-old Amsterdam resident Pepijn van der Stap in September 2026 as part of an ongoing investigation into the ShinyHunters cybercriminal group. Van der Stap, previously known online as 'Umbreon,' was already on probation from a 2023 conviction for hacking and extorting over a dozen companies worldwide. Authorities are examining potential connections between his 'Umbreon' identity and recent ShinyHunters campaigns, including alleged FBI breaches and attacks on the Clop ransomware gang's infrastructure. The arrest involved a tactical police unit search of his Amsterdam residence and seizure of electronic devices.
This incident highlights the persistent threat of repeat cybercriminals and the challenges law enforcement faces in dismantling organized hacking groups like ShinyHunters, which continue high-profile data breaches and extortion campaigns despite increased scrutiny and arrests of suspected members.
Why This Matters Now
Organized cybercriminal groups like ShinyHunters continue operating despite law enforcement pressure, demonstrating the need for enhanced monitoring of known threat actors and stronger international cooperation to disrupt persistent data breach and extortion operations targeting critical infrastructure.
Attack Path Analysis
ShinyHunters member conducted social engineering attack against Odido telecommunications company by calling help desk and impersonating IT department member to steal credentials. Attacker used stolen credentials to access internal systems and potentially escalate privileges within cloud infrastructure. With elevated access, the group likely moved laterally across cloud environments to identify valuable data repositories. Command and control was established through encrypted channels to coordinate data theft operations. Large volumes of customer data were exfiltrated from compromised systems for sale on underground forums. The breach resulted in significant data exposure and regulatory compliance violations for the telecommunications provider.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
ShinyHunters member called Odido help desk impersonating IT department staff and tricked employee into entering credentials into fake login page
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Valid Accounts: Cloud Accounts
Compromise Accounts: Email Accounts
Network Sniffing
Exfiltration Over C2 Channel
Data Encrypted for Impact
Exploit Public-Facing Application
Acquire Infrastructure: Web Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong User Authentication
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Privilege Access Management
Control ID: Identity.AM-6
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21.2(a)
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
ShinyHunters arrest highlights ongoing data breach and extortion threats requiring enhanced egress security, zero trust segmentation, and threat detection capabilities.
Law Enforcement
Dutch police investigation demonstrates law enforcement's critical role in combating cybercrime while facing sophisticated hacking groups targeting government systems.
Telecommunications
Odido hack via social engineering exposes telecom vulnerabilities to credential theft, requiring encrypted traffic protection and enhanced employee security training.
Financial Services
ShinyHunters' data breach history targeting financial institutions necessitates robust compliance frameworks, anomaly detection, and multicloud visibility controls.
Sources
- Dutch police confirm arrest in ShinyHunters hacking investigationhttps://www.bleepingcomputer.com/news/security/dutch-police-confirm-arrest-in-shinyhunters-hacking-investigation/Verified
- Dutch Police Arrest Reformed Hacker in Shiny Hunters Investigationhttps://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/Verified
- Still on probation from previous arrest for hacking and extortion, Dutch national is arrested againhttps://databreaches.net/2026/09/28/still-on-probation-from-previous-arrest-for-hacking-and-extortion-dutch-national-is-arrested-again/Verified
- Politie deelt stem van verdachte in onderzoek naar hack Odidohttps://www.politie.nl/nieuws/2026/september/7/11-politie-deelt-stem-van-verdachte-in-onderzoek-naar-hack-odido.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained the ShinyHunters attack against Odido by limiting lateral movement capabilities and reducing the scope of data accessible through compromised credentials. The segmented architecture would likely have contained the breach impact and reduced the overall blast radius of customer data exposure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Identity-aware access controls would likely have limited the scope of systems accessible through the compromised credentials, constraining the attacker's initial foothold within the cloud environment
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely have constrained the ability to assume elevated IAM roles and limited token manipulation capabilities across cloud service boundaries and workload environments
Control: East-West Traffic Security
Mitigation: Workload-to-workload traffic inspection and segmentation policies would likely have constrained lateral movement paths and reduced the attacker's ability to discover and access sensitive data repositories
Control: Multicloud Visibility & Control
Mitigation: Comprehensive traffic visibility and anomaly detection across cloud environments would likely have identified unauthorized communication patterns and constrained persistent command channel establishment capabilities
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies and data loss prevention mechanisms would likely have constrained large-scale data transfer capabilities and reduced the volume of customer information accessible for extraction
While some customer data exposure might still occur through the initial compromise, the overall impact would likely be significantly constrained with reduced scope of accessible records and limited regulatory exposure
Impact at a Glance
Affected Business Functions
- Law Enforcement Operations
- Criminal Justice Processing
- Cybersecurity Investigation
- International Cooperation
Estimated downtime: N/A
Estimated loss: N/A
Investigation relates to past data breaches and extortion activities by ShinyHunters group affecting multiple organizations. Specific current data exposure limited to law enforcement investigation materials and seized electronic devices from suspect's residence.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement after initial compromise
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts
- • Establish Multicloud Visibility & Control to monitor anomalous interactions and suspicious automation patterns
- • Enable East-West Traffic Security to inspect workload-to-workload communications and detect internal pivoting
- • Deploy Encrypted Traffic inspection capabilities to prevent data theft through covert channels



