Key Takeaways
- Pepijn van der Stap faces investigation over alleged assistance to ShinyHunters data theft and extortion operations.
- His former role at Neo Security raises questions about privileged access, personnel risk, and oversight of offensive-security specialists.
- The case highlights how impersonation, stolen credentials, and session access can bypass otherwise mature security programs.
Dutch authorities have arrested 24-year-old Pepijn van der Stap, a convicted cybercriminal and former offensive-security lead at Neo Security, as part of an investigation into alleged assistance provided to ShinyHunters.
Dutch police said van der Stap was scheduled to appear before Rotterdam District Court on September 29, 2026. The current allegations remain subject to judicial proceedings, and an arrest does not establish guilt.
Reporting by Krebs on Security identified van der Stap and connected the investigation to data theft and extortion activity attributed to ShinyHunters. Reuters also reported on the arrest and van der Stap's cybersecurity background.
That background makes the case particularly relevant for business and technology leaders. Van der Stap was convicted in 2023 in connection with earlier data theft and extortion activity that prosecutors said generated between €1.5 million and €2.7 million. He later worked in offensive security at Neo Security, where such roles can involve knowledge of intrusion techniques, identity systems, cloud environments, and defensive blind spots.
Offensive-security expertise is valuable precisely because it resembles an attacker's skill set. Companies hire specialists to test controls, expose weaknesses, and improve detection. The risk emerges when access governance, monitoring, or personnel controls do not reflect the sensitivity of that work.
The investigation also puts renewed attention on ShinyHunters. The name has been associated with the theft, sale, and attempted extortion of data obtained from corporate systems. Unlike traditional ransomware operations, which often depend on encrypting infrastructure, data-extortion campaigns can create leverage simply by copying sensitive information and threatening to publish or sell it.
A ShinyHunters-linked incident reportedly affected data belonging to more than 6 million Odido customers. Attackers allegedly impersonated an IT employee during a customer-service call, illustrating how a convincing conversation can become an entry point into a larger technical environment.
No exotic exploit is required in that scenario. A caller may seek a password reset, multifactor authentication change, account recovery action, or session access. If customer-service personnel accept the story, technical safeguards can be weakened through legitimate administrative processes.
Coverage from CBC News further underscores why the distinction between a former offender and a security professional deserves careful handling. A prior conviction does not mean someone will reoffend. At the same time, sensitive positions often call for documented risk assessments, narrowly scoped privileges, separation of duties, and detailed access logging.
Privileged access can be temporary and task-specific rather than standing indefinitely. Administrative actions can require additional approval, while logs should record who accessed sensitive systems, what changed, and whether large volumes of data were queried or exported. Alerts tied to unusual session creation, authentication changes, and data movement can also shorten investigation time.
NIST Cybersecurity Framework 2.0 places governance alongside identification, protection, detection, response, and recovery. Applied here, that means defining ownership of personnel risk, identity controls, third-party access, and incident escalation before suspicious behavior appears. ISO/IEC 27001:2022 similarly supports controls covering access management, logging, incident handling, and employment-related security.
Social engineering deserves equal weight. Phishing accounted for 60% of observed initial intrusions against EU organisations in ENISA's 2025 threat landscape, while info-stealers continued to support credential theft, session hijacking, and access brokering. Help-desk verification should therefore account for adversaries who already possess personal details and can sound entirely credible.
The van der Stap proceedings will determine the legal merits of the allegations. For Neo Security, Odido, and other companies watching the case, the immediate lesson is narrower: trusted access works better when it is limited, observable, and difficult for any single person or persuasive caller to misuse.
⬇️