Odido's headquarters building in The Hague. Undated- Credit: Odido / Supplied - License: All Rights Reserved

Dutch authorities arrest suspected ShinyHunters member in Odido hack probe

A 23-year-old has been arrested by Dutch authorities in connection with the investigation into the Odido hack. Police are investigating Pepijn van der S. over suspected involvement with ShinyHunters, the hacking group that claimed responsibility for the February 2026 attack on the telecom provider, RTL reported.

According to reporting by cybersecurity journalist Brian Krebs, sources familiar with the investigation say he was arrested around September 16 and has since been held for questioning. The report identifies him as Pepijn van der Stap from Almere.

The ShinyHunters group stole data relating to more than 6 million Odido customers. Police say the attackers obtained access after a Dutch-speaking man called Odido's customer service pretending to be an IT employee. He convinced an employee to enter login credentials and subsequently a verification code on a fake Odido login page. This gave the hackers access to internal systems.

ShinyHunters subsequently demanded a ransom. Odido refused to pay, after which the stolen information was published on the dark web. According to Krebs' sources, ShinyHunters significantly escalated its activities after Van der S. was detained. The group claimed responsibility for an attack on the FBI's job application website, with stolen information reportedly involving more than 5,000 FBI personnel. The FBI confirmed that the website had been compromised.

Police released an audio recording of the Dutch-speaking man who called the Odido helpdesk in September because they wanted the public to identify him. The caller had convinced the employee that he was an Odido IT colleague by using convincing internal terminology.

ShinyHunters subsequently told Dutch media that the man in the recording was a member of their group and said that the group would provide him with financial and legal support if necessary. However, police have not publicly confirmed that Van der S. is the man heard in the recording.

Van der S. is not a newcomer to cybercrime. He was previously convicted in Amsterdam in November 2023 following a major investigation into hacking, data theft and extortion. He was sentenced to four years in prison, one of which was suspended. He had admitted to hacking and extorting companies.

The previous case attracted attention because Van der S. simultaneously had a legitimate career in cybersecurity. While secretly involved in cybercrime, he worked as a software engineer at cybersecurity company Hadrian and volunteered for the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organization that helps companies discover and fix security vulnerabilities.

After his release from prison, he reportedly attempted to rebuild his career in cybersecurity. Krebs reported that during his arrest, he was working as an offensive security lead at Dutch cybersecurity company Neo Security.

In an interview with Krebs on September 9, shortly before his reported arrest, Van der S. presented himself as someone who had changed his life after his conviction. He said he was trying to contribute positively to cybersecurity and was dealing with the consequences of his previous crimes, including civil claims and restitution.

He has previously explained his motivation for hacking as being less about money than about collecting stolen databases. In a 2024 interview with Bloomberg, he described the activity as a form of collecting and organizing data.

Krebs reports that people familiar with the ShinyHunters investigation believe the group has undergone a significant internal change, with a teenage hacker known online as Rey taking a leading role. He is associated with ScatteredLapsussHunters (SLSH), a combination of the names Scattered Spider, LAPSUS$, and ShinyHunters.