Dutch Arrest in ShinyHunters Probe Raises Startup Cybersecurity Questions
A 24-year-old Amsterdam cybersecurity worker was detained in an investigation tied to alleged FBI data theft claims by ShinyHunters.

Dutch police have detained a 24-year-old Amsterdam resident as part of an investigation into ShinyHunters, the hacker group that last week claimed it had breached a database connected to the U.S. Federal Bureau of Investigation and stolen data on bureau employees. The case is drawing particular attention across the cybersecurity startup ecosystem because the suspect is believed to be a technology worker with a prior conviction for data theft and extortion.
Police in the Netherlands announced on Monday, September 28, that a 24-year-old man from Amsterdam had been arrested in connection with the investigation into ShinyHunters. The precise date of the arrest was not disclosed in the police statement on X; authorities said only that it took place in September. The suspect is expected to appear before a court in Rotterdam on Tuesday, September 29.
Dutch police did not name the detained man. However, Benjamin Corper, a representative of Amsterdam-based cybersecurity company Neo Security, told Reuters that the person detained was Pepijn van der Stap, who leads the company’s offensive cybersecurity practice. According to Corper, his employee was arrested on September 15 “during a large-scale police operation involving flash-bang grenades.” On the same day, forensic officers also visited Neo Security’s office.
ShinyHunters said van der Stap “has nothing to do” with the group.
Cyber Talent, Second Chances and Investor Risk
For venture-backed cybersecurity startups, the arrest lands in a sensitive area: the industry’s dependence on elite offensive-security talent, including people with deep knowledge of how attackers operate. Startups in this market often sell credibility based on their ability to think like adversaries, test defenses and identify vulnerabilities before criminals do. That model can create obvious value for customers, but it also places extra weight on hiring controls, compliance, board oversight and reputational risk management.
Van der Stap had already been convicted in 2023 and sentenced to four years in prison, one year of which was suspended, after a court found him guilty of a series of data thefts and extortion. Law enforcement estimated that he earned between €1.5 million and €2.7 million from those crimes. During the trial, he admitted guilt and expressed remorse.
Investigators said the offenses were committed while van der Stap was working at Hadrian, an Amsterdam cybersecurity startup, and volunteering at DIVD, a nonprofit research organization focused on discovering computer vulnerabilities. That history has direct relevance for the innovation ecosystem: it involves the overlap between startup employment, vulnerability research and the trust placed in highly technical employees with access to sensitive systems or methods.
Van der Stap was released early in December 2025. Shortly before the new arrest, he told Brian Krebs, author of the KrebsonSecurity blog, that he considered himself a hacker who had taken the path of reform, wanted to change his life for the better and sought to benefit society. Corper described his employment at Neo Security as a “second chance” for the employee.
That framing is likely to resonate across cybersecurity founders, investors and acquirers. The sector has long wrestled with whether and how to reintegrate talented hackers after convictions, particularly when their skills are commercially valuable. The Neo Security case may sharpen due-diligence questions for venture capital firms backing security startups, as well as for enterprise buyers considering acquisitions of companies built around offensive-security teams.
Alleged FBI Breach Adds Geopolitical Weight
On September 22, ShinyHunters published a message on the dark web claiming it had breached an FBI database and stolen information belonging to numerous former and current bureau employees. The group claimed the stolen material included information on psychiatric and medical evaluations of agents. The hackers also said they had obtained access to data related to FBI Director Kash Patel. Reuters was able to partially verify the authenticity of the published data.
FBI representatives said they were “aware of claims of unauthorized activity” affecting FBIjobs.gov, the bureau’s employment website, and were investigating.
If the claims are substantiated more fully, the incident would expand concern around the exposure of sensitive personnel data, including information that could create counterintelligence, blackmail or physical-security risks. For companies serving government, defense, law enforcement or critical infrastructure customers, the case is also a reminder that security failures can quickly move from commercial breach response into national-security territory.
ShinyHunters has been linked to several other major data leaks. In February 2026, after a breach of databases belonging to Odido, the largest mobile operator in the Netherlands, the group obtained access to data on more than 6.2 million residents of the country. Other recent attacks attributed to ShinyHunters include the alleged theft of millions of corporate records from video game developer Rockstar Games, known in part for the Grand Theft Auto franchise, and a May attack on the education platform Canvas that caused major disruptions in U.S. schools.
For the venture market, those incidents underline the scale of demand for cybersecurity products while also exposing the fragility of the sector’s own trust architecture. Security startups are expected to protect customers from exactly the kind of data theft and extortion campaigns that groups such as ShinyHunters are accused of conducting. When employees or former startup workers become tied to investigations, even without formal public charges being detailed, founders and investors face harder questions about governance, hiring standards and the boundaries of offensive research.
The Dutch investigation is still developing, and authorities have not disclosed the suspect’s name in their own announcement. Neo Security’s account, ShinyHunters’ denial of van der Stap’s connection to the group and the expected Rotterdam court appearance now place the matter at the intersection of law enforcement, cybercrime, startup culture and the commercial market for offensive cybersecurity expertise.



