📈 Markets
GSPC 7683.69 ▼ -0.77% DJI 51481.51 ▼ -0.67% IXIC 26820.38 ▼ -0.92% EURUSD 1.14 ▼ -0.06% GC 4175.30 ▲ 0.23% CL 93.91 ▲ 0.01% GSPC 7683.69 ▼ -0.77% DJI 51481.51 ▼ -0.67% IXIC 26820.38 ▼ -0.92% EURUSD 1.14 ▼ -0.06% GC 4175.30 ▲ 0.23% CL 93.91 ▲ 0.01%
Business

Dutch Arrest in ShinyHunters Case Highlights Rising Economic Cost of Cyber Risk

The detention of a 24-year-old Amsterdam cybersecurity worker underscores how data breaches are becoming a strategic policy and economic issue.

By Editorial Team — September 29, 2026 · 4 min read
Photo: Deutsche Welle

Dutch police have detained a 24-year-old Amsterdam resident as part of an investigation into ShinyHunters, the hacking group that last week claimed to have breached a database linked to the U.S. Federal Bureau of Investigation and stolen data on bureau personnel. The case, still unfolding across law enforcement, cybersecurity and corporate circles, points to a broader macroeconomic concern: cyber incidents are no longer isolated technology failures, but recurring shocks to institutional trust, labor markets, insurance pricing and public-sector resilience.

Police in the Netherlands announced on Monday, September 28, that they had arrested a 24-year-old man from Amsterdam in connection with an inquiry into ShinyHunters. The exact date of the arrest was not specified in the police statement on X, which said only that it occurred in September. The suspect is due to appear before a court in Rotterdam on Tuesday, September 29.

Authorities did not disclose the man’s name. However, Benjamin Corper, a representative of Amsterdam-based cybersecurity company Neo Security, told Reuters that the detainee is Pepijn van der Stap, who heads the company’s offensive cybersecurity division. Corper said his employee was arrested on September 15 “in a large-scale police operation using flashbangs.” On the same day, forensic officers visited Neo Security’s office.

ShinyHunters said van der Stap “has nothing to do” with the group.

The allegations arrive at a sensitive moment for governments and companies trying to expand cyber defenses while managing the risks of employing highly skilled security specialists with complex histories. In 2023, van der Stap was sentenced to four years in prison, one of them suspended, after a court found him guilty in a series of data theft and extortion cases. Law enforcement estimated that he earned between 1.5 million and 2.7 million euros from those crimes.

According to investigators, van der Stap committed the offenses while working at Hadrian, an Amsterdam cybersecurity startup, and while volunteering at DIVD, a nonprofit research organization focused on identifying computer vulnerabilities. During the trial, he admitted guilt and expressed remorse. He was released early in December 2025.

Shortly before the new arrest, van der Stap told Brian Krebs, author of the KrebsOnSecurity blog, that he saw himself as a hacker who had chosen a path of reform, wanted to improve his life and hoped to benefit society. Corper described Neo Security’s decision to employ him as a “second chance” for his employee.

Cybersecurity Becomes a Governance and Productivity Risk

For senior decision-makers, the case highlights a policy dilemma with economic consequences. Digital economies require offensive cybersecurity expertise to test systems before criminals exploit them. At the same time, governments, insurers, investors and corporate boards are increasingly asking how firms manage insider risk, third-party access and employee vetting in sensitive roles. The challenge is especially acute in Europe, where cybersecurity capacity is in high demand and where cross-border enforcement often intersects with U.S. agencies and global platforms.

The claimed FBI-related breach also underscores how cyberattacks can affect public-sector credibility. On September 22, ShinyHunters published a message on the dark web claiming it had breached an FBI database and stolen information on many former and current bureau employees. The data allegedly included information about psychiatric and medical evaluations of agents. The group also claimed to have gained access to data on FBI Director Kash Patel. Reuters was able to partially verify the authenticity of the published data.

FBI representatives said they were “aware of claims of unauthorized activity” affecting the FBIjobs.gov applicant website and were conducting an investigation. Even where investigations remain incomplete, the economic implications can begin immediately: affected agencies may face higher remediation costs, slower recruitment processes, more expensive vendor oversight and added pressure to modernize legacy systems.

Those pressures are not confined to the United States. ShinyHunters has also been linked to several other major data leaks. In February 2026, after databases belonging to Odido, the largest mobile operator in the Netherlands, were breached, the group gained access to data on more than 6.2 million residents of the country. Other recent attacks attributed to ShinyHunters include the alleged theft of millions of corporate records from Rockstar Games, the video game developer known in part for the Grand Theft Auto series, and a May attack on the Canvas education platform that caused widespread disruption in U.S. schools.

Long-Term Costs Extend Beyond Immediate Breach Response

The repeated targeting of telecoms, education platforms, entertainment companies and government-related systems illustrates why cyber risk has become a structural economic issue. Large breaches can raise compliance spending, divert management attention, increase litigation exposure and impose hidden costs on households whose personal information circulates in illicit markets. In sectors such as telecommunications and education, where platforms underpin daily economic and social activity, disruption can also reduce productivity and weaken confidence in digital services.

For policymakers, the Dutch arrest adds urgency to debates over cyber labor pipelines, rehabilitation of convicted hackers, public-private information sharing and international coordination. A shortage of skilled cybersecurity workers has made second-chance employment a practical question rather than a purely ethical one. Yet cases involving alleged repeat links to cybercrime may prompt stricter supervisory expectations for companies operating in offensive security, vulnerability research and penetration testing.

The legal process in Rotterdam will determine the immediate direction of this specific case. Its wider significance is already visible: cybercrime investigations now touch the balance between labor market reintegration and national security, between innovation and control, and between corporate cyber capability and public trust. For economies that depend on digital infrastructure, those trade-offs will only become more consequential.

Continue Reading

Discussion