📈 Markets
GSPC 7811.54 ▲ 0.60% EURUSD 1.12 ▼ -0.09% GC 4220.30 ▲ 0.43% AAPL 336.64 ▼ -1.11% MSFT 535.07 ▲ 2.38% GSPC 7811.54 ▲ 0.60% EURUSD 1.12 ▼ -0.09% GC 4220.30 ▲ 0.43% AAPL 336.64 ▼ -1.11% MSFT 535.07 ▲ 2.38%
Business

Dutch Arrest in ShinyHunters Probe Puts European Cyber Risk Back in Focus

The Amsterdam arrest comes after claims of an FBI data breach, adding pressure on European companies and investors to reassess cyber exposure.

By Editorial Team — September 29, 2026 · 4 min read
Photo: Deutsche Welle

Dutch police have detained a 24-year-old Amsterdam man as part of an investigation into ShinyHunters, the hacking group that last week claimed it had breached a database linked to FBI agents and stolen data on bureau employees.

The arrest, announced by police in the Netherlands on Monday, 28 September, places a European cyber-security case back in the frame for businesses, insurers and investors across the UK and the EU. While the alleged target was American, the suspect is based in Amsterdam, the investigation is being handled in the Netherlands, and ShinyHunters has been linked to major data incidents affecting European consumers and companies.

Dutch police did not give the exact date of the arrest in their post on X, saying only that it took place in September. The suspect was expected to appear before a court in Rotterdam on Tuesday, 29 September.

Authorities have not publicly named the detained man. However, Benjamin Corper, a representative of Amsterdam-based cyber-security company Neo Security, told Reuters that the suspect was Pepijn van der Stap, who leads offensive cyber-security at the firm. Corper said his employee was detained on 15 September “during a large-scale police operation using stun grenades”. On the same day, forensic officers visited Neo Security’s office.

ShinyHunters said van der Stap “has nothing to do” with the group.

Why the Case Matters for UK and EU Markets

For London-listed technology, telecoms and insurance groups, the case is another reminder that cyber events rarely stay within one jurisdiction. A breach allegedly affecting a US federal recruitment site can still draw in European law enforcement, European cyber firms and European defendants, while previous incidents attributed to the same group have involved data belonging to millions of EU residents.

The immediate market impact on sterling was not specified in the source material, and no direct London market reaction was reported. Even so, cases of this scale are closely watched in the City because they can influence sentiment toward cyber-security spending, operational resilience and the pricing of cyber insurance. For British companies with US exposure, the alleged FBI-linked breach also highlights the regulatory and reputational risks that follow compromised personnel data.

The pound’s sensitivity to technology risk is indirect rather than mechanical. Sterling typically moves on interest-rate expectations, growth data, fiscal policy and global risk appetite. But major cyber incidents can add to the risk premium around companies with large customer databases or public-sector contracts, including those listed in London or operating under UK and EU data-protection regimes.

Prior Conviction and a Claimed Second Chance

Van der Stap was sentenced in 2023 to four years in prison, one of them suspended, after a court found him guilty of a series of data thefts and extortion. Law enforcement estimated that he earned between €1.5 million and €2.7 million from the activity.

According to investigators, the offences took place while van der Stap was working at Hadrian, an Amsterdam cyber-security start-up, and volunteering with DIVD, a non-profit research organisation focused on finding computer vulnerabilities. During the trial, he admitted guilt and expressed remorse.

Van der Stap was released early in December 2025. In an interview shortly before the new arrest with Brian Krebs, the author of the KrebsonSecurity blog, he described himself as a hacker who had turned toward rehabilitation, wanted to improve his life and hoped to benefit society. Corper described his employment at Neo Security as a “second chance” for the employee.

That background gives the case particular significance for Europe’s cyber-security sector, where offensive security skills are often recruited from the same technical communities that can also be associated with illicit hacking. For companies in London, Amsterdam, Dublin, Berlin and elsewhere, the case underlines the commercial challenge of hiring scarce technical talent while maintaining governance, compliance and client trust.

Claims Around FBI Data

On 22 September, ShinyHunters posted a message on the dark web claiming it had breached an FBI database and stolen data belonging to many former and current bureau employees. The group alleged that the data included information on psychiatric and medical examinations of agents. It also claimed to have accessed data belonging to FBI Director Kash Patel.

Reuters was able to partially verify the authenticity of the published data. FBI representatives said they were “aware of claims of unauthorised activity” affecting the FBIjobs.gov website for applicants and were investigating.

The sensitivity of the alleged data is central to the business risk. Personnel records, medical information and recruitment data can create long-tail exposure for organisations, particularly when employees or applicants may face targeting, impersonation or blackmail. In the UK and EU, such incidents also raise questions under data-protection rules and can lead to regulatory scrutiny, legal claims and higher compliance costs.

ShinyHunters’ Wider European Footprint

ShinyHunters has also been linked to several other major data leaks. In February 2026, after a breach of databases at Odido, the largest mobile operator in the Netherlands, the group gained access to data on more than 6.2 million residents of the country.

Other recent attacks attributed to ShinyHunters include the alleged theft of millions of corporate records from Rockstar Games, the video-game developer known in part for the Grand Theft Auto series. The group has also been linked to a May attack on the Canvas education platform, which caused large-scale disruption in US schools.

For European businesses, the sequence of alleged incidents reinforces the scale of the challenge. Telecoms providers, software companies, education platforms and public-sector recruitment systems all hold large volumes of personal or operationally sensitive data. A successful intrusion can move quickly from a technical breach to a boardroom issue, affecting customer confidence, legal liabilities and market valuation.

The Rotterdam court appearance will be watched for any indication of the evidence Dutch authorities have gathered and whether prosecutors will connect the Amsterdam suspect directly to ShinyHunters’ alleged activity. For now, the case has already sharpened attention on the cyber threat facing European companies and the growing overlap between criminal investigations, corporate hiring, and market risk.

Continue Reading

Discussion