Former Convicted Hacker Arrested Again Over Massive Dutch Telecom Data Breach

Former Convicted Hacker Arrested Again Over Massive Dutch Telecom Data Breach

2026-09-29 data

The Hague, Tuesday, 29 September 2026.
Dutch authorities arrested a recently released hacker turned security consultant, investigating his links to the massive Odido telecom breach amid speculation of a rival framing attempt.

A Deep-Rooted History in Cybercrime

On September 15, 2026, the Dutch Dienst Speciale Interventies (DSI) arrested 24-year-old Pepijn van der Stap, also known online as “Umbreon”, at his mother’s home in Amsterdam [6]. The arrest, which occurred near the Amsterdam area, is tied to his suspected involvement with the notorious international hacking collective ShinyHunters and the massive cyberattack on Dutch telecom provider Odido [1][5]. Van der Stap is no stranger to law enforcement; he was previously arrested in January 2023 at the age of 20 and convicted in Amsterdam in November 2023 for a series of cybercrimes, including hacking, extortion, data fencing, and distributing “Tortilla” ransomware [1][6]. During his initial 2023 arrest, police found €46,510 in cash, and he confessed to laundering over €1.5 million in cryptocurrency [7].

From Incarceration to Corporate Security

For his 2023 offenses, the court sentenced Van der Stap to four years in prison, with one year suspended, meaning an active term of 3 years, along with a three-year probationary period [6][7]. This sentence was accompanied by special conditions, including a mandatory reporting obligation to the probation service, engaging in daytime activities, cooperating with debt counseling, and undergoing outpatient treatment [6]. Following his release from prison in December 2025, Van der Stap sought to pivot toward a legitimate career in cybersecurity [2][5][6]. He secured a role as an offensive security lead at the Dutch firm Neo Security and was also retained as a security consultant by the organization DataBreaches [1][6].

The Odido Breach and Social Engineering Tactics

The current investigation centers on the devastating cyberattack against Odido in February 2026, which exposed the personal data of over 6 million customers, including bank account numbers and government IDs [1][5]. The breach was executed using highly effective social engineering tactics [5]. A Dutch-speaking individual impersonated an IT help desk employee, tricking an Odido staff member into entering credentials and a verification code on a fraudulent login page [1][5]. Although police released an audio recording of the caller on September 8, 2026, authorities have not publicly confirmed whether the voice belongs to Van der Stap, and sources familiar with his voice have cast doubt on his involvement in the recording [1][6].

The Scale of ShinyHunters Operations

The economic ramifications of such breaches are severe, emphasizing the vulnerability of critical corporate data networks [GPT]. ShinyHunters, a group active since 2019 that has targeted an estimated 90 companies, claimed responsibility for the Odido attack after the telecom provider refused to pay a ransom demand [7]. While Dutch police have focused their investigation on Van der Stap’s potential links to this breach, no official charges confirming a connection have been publicly disclosed [6].

A Reintegration Cut Short or a Sophisticated Frame-Up?

The arrest has sparked significant debate within the cybersecurity community, with some experts hoping the situation is merely a misunderstanding of an ethical hacker’s activities [3]. On September 9, 2026, just a week before his arrest, Van der Stap gave an interview claiming he had reformed and was actively addressing civil claims and restitution from his past crimes [1][2]. However, his detention has triggered immediate legal consequences; he faces the potential revocation of his previous one-year suspended sentence due to probation violations, which he must serve before any new sentences can be imposed [6].

A Rival Faction’s Orchestration

Adding a layer of complexity to the case are allegations that Van der Stap may have been framed by rival cybercriminals [5]. Following his arrest, remaining members of ShinyHunters dramatically escalated their activities, which included hacking the FBI’s job application portal on September 22, 2026 [4][5]. The hackers used Van der Stap’s old “Umbreon” branding during the attack, which affected over 5,000 personnel [1][5]. Sources familiar with the investigation suggest that a rival faction, potentially led by a teenage hacker known as “Rey” from the Scattered Lapsus$ Hunters (SLSH) group, orchestrated the FBI hack to implicate Van der Stap amid an internal dispute over the ShinyHunters brand [1][5]. For their part, ShinyHunters denied any association with Van der Stap, claiming the Dutch police are simply targeting him to recover public favor after the embarrassment of the Odido breach [2][5].

Currently held in the Houten detention center under “complete restrictions”—meaning he is permitted to contact only his lawyer—Van der Stap’s immediate legal future hangs in the balance [6][7]. He is scheduled to appear before the chamber of the Rotterdam District Court on Tuesday, September 29, 2026, where a decision will be made regarding his continued pre-trial detention [6][7]. Dutch law enforcement confirmed the court appearance and indicated they would release more information on the following day [6].

Bronnen


cybersecurity data breach