
(SeaPRwire) – By: Lucas Caldwell
A 24-year-old ‘reformed hacker’ joins a cybersecurity firm as their offensive security lead. Months later, Dutch police arrest him for allegedly leading the group that claimed to have hacked the FBI. The word ‘reformed’ needs quotes. Nobody in this industry buys the clean-break narrative. Pepijn van der Stap was convicted in 2023 for data theft and extortion. He walked out of prison in December 2025. He publicly disavowed cybercrime. He got hired at Neo Security in Amsterdam. Then he got branded as ShinyHunters’ alleged leader. This story isn’t about FBI breaches or dark web drama. It’s about a framing job so sloppy that even the accused group laughed it off.
Dutch authorities arrested Van der Stap on September 15 on suspicion of cybercrime offenses. They also suspected him of attempting to instigate at least two murders abroad. Patel called ShinyHunters a ‘global cybercrime and threat actor group.’ The FBI director linked the group to attacks across the US, the Netherlands, and the world. Neither agency named the suspect publicly. Benjamin Korper, head of Neo Security, confirmed it was his company’s offensive security lead. Van der Stap went by the alias ‘Umbreon.’ He was released from prison in December 2025 and vetted before hiring. Both US and Dutch officials said more arrests could follow.
ShinyHunters denied any connection to Van der Stap. ‘That individual has no association with us. Frankly, we are laughing,’ the group told Cybernews. They called Dutch police ‘unskilled and incompetent,’ referencing the Odido hack as Dutch embarrassment. Brian Krebs reported on a bitter dispute between Van der Stap and ‘Rey.’ ‘Rey’ leads the Scattered Lapsus$ Hunters spinoff faction. The fight is over ShinyHunters branding. Sources told Krebs the faction may have deliberately used the ‘Umbreon’ alias to implicate him. The Umbreon imagery appeared in attacks on a rival ransomware gang and the FBI. Both happened after Van der Stap’s arrest.
The FBI breach claim says something ugly about how cybercrime operates now. ShinyHunters said the theft of ‘almost all’ agents’ data was ‘not financially motivated.’ Their demand was to pull a cybersecurity advisory containing false allegations about the group. They set a one-week deadline, then dropped it, saying it was never a ‘threat’ and ‘nothing’ would happen. That’s not extortion. That’s brand warfare. The cybercrime underworld has splintered into factions fighting over turf and reputation. When a group demands an adversary retract its accusations, it means the brand matters more than the data. The data is the collateral.
The hiring pipeline problem nobody wants to discuss. Cybersecurity firms keep onboarding ex-hackers. They tell themselves the person is reformed. The person believes it. But the industry operates on a trust deficit that never fully closes. Van der Stap told people his background made him useful ‘for building and protecting, not breaking.’ Fine. But what happens when a rival faction decides your old alias is a weapon? Your reputation as a former criminal becomes your liability vector. Neo Security vetted him. That vetting is worth exactly what the industry will pay for it when things go sideways.
The cybercrime attribution game is about to get considerably more brutal as rival factions weaponize old aliases and discarded identities to silence competitors and control narratives across the dark web spaces, and the single variable that will determine whether law enforcement survives this particular mess intact is whether they can distinguish a genuine insider defection from a manufactured framing operation fast enough to prevent a sitting intelligence chief from making global public statements anchored entirely to a Pokemon character’s nickname, because once the attribution model collapses, every ex-hacker who takes a legitimate seat in a security firm becomes a potential vector for the next frame job.
Author bio: Lucas Caldwell, a tech opinion leader with millions of followers on X/Twitter, writing about cybersecurity, platform governance, and the dark side of internet infrastructure with a focus on systemic risk and attribution failures.