Odido: Previously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe

Odido: Previously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe

Dutch Authorities Arrest Suspected ShinyHunters Affiliate in Odido Cyberattack

Dutch police have arrested a 23-year-old man in connection with the February cyberattack on telecom provider Odido, an incident claimed by the hacking group ShinyHunters. Multiple sources, including cybersecurity journalist Brian Krebs, identify the suspect as Pepijn van der Stap, a convicted hacker and former security researcher.

Van der Stap was taken into custody on or around September 16 and remains in police custody for questioning. The arrest follows a months-long investigation by the Dutch National Police and Public Prosecution Service into the breach, which exposed data belonging to over six million Odido customers after the company refused to pay a ransom.

Investigators allege the attack began with a social engineering call to Odido’s customer service. A Dutch-speaking man, posing as an IT employee, convinced a staff member to enter credentials on a fake login page and provide a multi-factor authentication code, granting access to internal systems. Police released a recording of the call earlier this month, though they have not publicly confirmed whether Van der Stap is the speaker.

ShinyHunters initially leaked two million Odido records in February, claiming to have stolen far more data. The group later stated it would provide the arrested individual with legal and financial support, though it has since denied any association with Van der Stap, calling the arrest a publicity stunt by Dutch authorities.

Van der Stap has a history of cybercrime, including a 2023 conviction for hacking, data theft, and extortion, which prosecutors said generated €1.5–2.7 million. Operating under the alias "Umbreon" (a Pokémon character), he sold stolen databases on forums like RaidForums and Breached. Despite his criminal past, he also worked as a software engineer at Hadrian, volunteered with the Dutch Institute for Vulnerability Disclosure (DIVD), and later served as Offensive Security Lead at Neo Security.

His online presence includes claims of submitting over 100,000 responsible disclosure reports, though his recent arrest raises questions about his alleged shift away from cybercrime. In a September 9 interview with Krebs, Van der Stap stated he had left illicit activities behind but was still dealing with civil claims from his past offenses.

The "Umbreon" alias has resurfaced in recent ShinyHunters activity, including an ASCII art depiction in the group’s defacement of the FBI Jobs portal this month. However, sources cited by Krebs suggest internal conflicts within the group, with another hacker known as "Rey" potentially using the imagery to implicate Van der Stap. Dutch authorities have not publicly linked him to the FBI breach.

The investigation remains active, with police yet to disclose the evidence against Van der Stap or confirm his role in the Odido attack. ShinyHunters has dismissed the arrest as an attempt by Dutch authorities to regain credibility after the high-profile breach.

Source: https://hackread.com/convicted-dutch-hacker-arrest-shinyhunters-odido-probe/

Odido Nederland cybersecurity rating report: https://www.rankiteo.com/company/odidonederland

"id": "ODI1790634436",
"linkid": "odidonederland",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Over six million',
                        'industry': 'Telecommunications',
                        'location': 'Netherlands',
                        'name': 'Odido',
                        'type': 'Telecom Provider'}],
 'attack_vector': 'Social Engineering',
 'data_breach': {'data_exfiltration': 'Yes',
                 'number_of_records_exposed': 'Over six million',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'Personally Identifiable Information '
                                        '(PII)',
                 'type_of_data_compromised': 'Customer records'},
 'date_detected': '2024-02-01',
 'date_publicly_disclosed': '2024-09-16',
 'description': 'Dutch police have arrested a 23-year-old man in connection '
                'with the February cyberattack on telecom provider Odido, an '
                'incident claimed by the hacking group ShinyHunters. The '
                'suspect, identified as Pepijn van der Stap, was taken into '
                'custody on or around September 16 and remains in police '
                'custody for questioning. The attack exposed data belonging to '
                'over six million Odido customers after the company refused to '
                'pay a ransom.',
 'impact': {'brand_reputation_impact': 'High',
            'data_compromised': 'Over six million customer records',
            'identity_theft_risk': 'High',
            'systems_affected': 'Internal systems of Odido'},
 'initial_access_broker': {'entry_point': 'Social engineering call to customer '
                                          'service'},
 'investigation_status': 'Active',
 'motivation': 'Extortion, Data Theft',
 'post_incident_analysis': {'root_causes': 'Social engineering, credential '
                                           'theft, MFA bypass'},
 'ransomware': {'data_exfiltration': 'Yes',
                'ransom_demanded': 'Yes (amount not disclosed)',
                'ransom_paid': 'No'},
 'references': [{'source': 'Brian Krebs'}, {'source': 'Dutch National Police'}],
 'regulatory_compliance': {'legal_actions': 'Arrest of suspect (Pepijn van der '
                                            'Stap)'},
 'response': {'law_enforcement_notified': 'Yes (Dutch National Police and '
                                          'Public Prosecution Service)'},
 'threat_actor': 'ShinyHunters (alleged affiliate: Pepijn van der Stap)',
 'title': 'Dutch Authorities Arrest Suspected ShinyHunters Affiliate in Odido '
          'Cyberattack',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Credential Theft via Fake Login Page and MFA '
                            'Bypass'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.