Dutch master hacker Pepijn (24) arrested in connection with the ShinyHunters case
Hacker Pepijn van der S. has been arrested again. He is suspected of being involved with ShinyHunters, a group known for major hacks.
One of the Netherlands’ best-known young hackers is back behind bars. Pepijn van der S., 24, is suspected of being involved with ShinyHunters, the notorious hacker collective that has recently been linked to major cyberattacks on Odido and the FBI, among others.
What’s striking is that Van der S. had previously distanced himself from cybercrime and, after serving a multi-year prison sentence, had returned to work in the cybersecurity field.
The case has come as a surprise to Dutch security experts. Tech journalist Daniël Verlaan has known Van der S. for years and previously interviewed him at length. According to Verlaan, during a difficult childhood, his computer was not just a hobby but, above all, a safe haven. Later, that fascination evolved into something much more dangerous.
Van der S. was introduced to hacking at a young age. As a teenager, he ended up at the Halt agency after hacking into his high school. He was then given the opportunity to do an internship at a cybersecurity firm and seemed to be using his exceptional technical skills on the right side of the law thereafter.
He worked as a software developer in the cybersecurity field and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD). There, he helped identify vulnerabilities before criminals could exploit them.
Behind the scenes, however, something else was going on. Under the alias Umbreon, Van der S. was involved in large-scale data theft and extortion, according to his previous criminal case. In 2023, he was sentenced to four years in prison, one year of which was suspended. At the time, he confessed to his involvement in multiple cyberattacks.
According to investigative journalist Brian Krebs, prosecutors stated at the time that the cybercrimes had yielded between 1.5 million and 2.7 million euros. Van der S. was released in late 2025 and subsequently found work again in the cybersecurity sector.
That makes his latest arrest all the more striking. His employer, Neo Security, had given him a second chance despite his past. CEO Benjamin Korper told Reuters that he had carefully vetted Van der S. before hiring him. Following the arrest, the company also commissioned an external investigation to determine whether he had attacked Neo Security’s systems or those of its clients. According to Korper, no evidence of such activity had been found so far.
Verlaan had previously spoken with Van der S. for his podcast while he was still in custody for his earlier conviction. A striking picture emerged from that conversation. According to Verlaan, money did not seem to be the main motive behind the hacking.
“It was a kind of addiction,” Verlaan told RENZE, describing how Van der S. had previously characterized his own behavior. “What he really wanted wasn’t necessarily the money.”
Despite his income from cybercrime, Van der S. reportedly did not lead an extravagant lifestyle. No expensive cars or watches. According to Verlaan, it was mainly about the thrill of breaking into systems and collecting enormous amounts of information.
“That addictive feeling of being able to break into a system and steal everyone’s data,” Verlaan said.
According to Verlaan, approximately 35 terabytes of data were found during his previous arrest. He describes Van der S. as someone who had access to enormous amounts of personal information.
That picture aligns with what Van der S. himself previously told Bloomberg. In an interview with that news outlet, he described collecting and organizing stolen data as his primary obsession.
After his release, Van der S. seemed to have chosen the right path once again. He landed a job in cybersecurity and spoke publicly about his desire to use his knowledge from then on to protect organizations. According to Krebs, less than a week before his arrest, he said he wanted to turn his life around and make a positive contribution to society.
That’s precisely why the new allegations have come as a shock to the Dutch cybersecurity community. Verlaan told RENZE that many people had given Van der S. another chance.
“Actually, the entire cybersecurity community in the Netherlands is absolutely terrified,” he said. The journalist describes ShinyHunters as a group of an entirely different caliber than your average cybercriminal. “They’re kind of like the Taghi of the hacker world.”
ShinyHunters is linked worldwide to large-scale data theft and extortion. In the Netherlands, the group claimed responsibility for the attack on telecom provider Odido, in which data from more than six million people was stolen. The attackers gained access after a Dutch-speaking hacker tricked an employee using a fake login page. The police have not disclosed whether Van der S. is the person behind those phone calls.
ShinyHunters also recently claimed to have stolen data from thousands of FBI employees and job applicants. The hacker collective remained active even after Van der S. was arrested.
Exactly how significant his alleged role within ShinyHunters was remains unclear. According to Verlaan, that makes the case all the more remarkable. He himself had recently been using Van der S. as a source for information about the hacker group.
“It’s also very fascinating to me that I apparently may have spoken with someone who was already a member of that group, while I was asking questions about that group,” he said on RENZE.
ShinyHunters has made contradictory statements to Dutch media regarding Van der S. The group initially denied that he had ties to the collective. Later, according to RTL, that statement was revised to say that he had “recently” severed ties with the group.
Van der S. was arrested on September 15. His employer confirmed to Reuters that forensic investigators visited the Neo Security office that same evening. The 24-year-old is scheduled to appear before a judge in Rotterdam on Tuesday, where a decision will be made regarding his pretrial detention.