📈 Markets
GSPC 7683.69 ▼ -0.77% DJI 51481.51 ▼ -0.67% GC 4155.60 ▼ -0.24% SI 60.73 ▼ -0.76% CL 94.59 ▲ 0.74% EURUSD 1.14 ▼ -0.11% GSPC 7683.69 ▼ -0.77% DJI 51481.51 ▼ -0.67% GC 4155.60 ▼ -0.24% SI 60.73 ▼ -0.76% CL 94.59 ▲ 0.74% EURUSD 1.14 ▼ -0.11%
Business

Dutch Arrest in ShinyHunters Case Highlights the Economics of Cyber Risk

The detention of a 24-year-old Amsterdam cybersecurity worker underscores how data theft has become a market problem for states, firms and insurers.

By Editorial Team — September 29, 2026 · 4 min read
Photo: Deutsche Welle

Dutch police have detained a 24-year-old Amsterdam resident as part of an investigation into the hacking group ShinyHunters, which last week claimed to have breached a database connected to FBI personnel. The arrest, announced by police on Monday, September 28, places a familiar question back at the center of the cyber economy: where the legitimate security industry ends, and the market for stolen data begins.

Police did not name the suspect or specify the exact date of the arrest, saying only that it took place in September. The suspect was due to appear before a court in Rotterdam on Tuesday, September 29. The case is being followed closely because ShinyHunters has been linked to a string of large data breaches, and because the person reportedly detained may be a previously convicted data thief who had returned to work in cybersecurity.

Benjamin Corper, a representative of Amsterdam-based cybersecurity company Neo Security, told Reuters that the arrested man was Pepijn van der Stap, who heads the company’s offensive cybersecurity practice. According to Corper, van der Stap was detained on September 15 “during a large-scale police operation involving flash-bang grenades.” Forensic officers visited Neo Security’s office the same day.

ShinyHunters said van der Stap “has nothing to do” with the group.

The denial does not resolve the broader economic significance of the case. Modern cybersecurity has developed into a labor market that actively recruits people who can think like attackers. That model can improve corporate defenses, but it also creates reputational and compliance risks when individuals with prior cybercrime convictions are given roles involving offensive security work, vulnerability research and access to sensitive client environments.

A Second-Chance Labor Market Under Stress

In 2023, van der Stap was sentenced to four years in prison, one of them suspended, after a court found him guilty of a series of data thefts and extortion. Law enforcement authorities estimated that he earned between 1.5 million and 2.7 million euros from those crimes. Investigators said the offenses occurred while he was working at Hadrian, an Amsterdam cybersecurity startup, and while volunteering for DIVD, a nonprofit research organization focused on identifying computer vulnerabilities. During his trial, he admitted guilt and expressed remorse.

Van der Stap was released early in December 2025. In an interview with Brian Krebs of the KrebsonSecurity blog shortly before the new arrest, he described himself as a hacker trying to reform, change his life for the better and contribute to society. Corper described his employment at Neo Security as a “second chance.”

That second-chance framing has become an important, and difficult, part of the cybersecurity labor market. Demand for skilled security workers remains high, while the technical expertise needed to test defenses can overlap with the expertise used to penetrate them illegally. Firms often face a trade-off: excluding reformed offenders may reduce reputational risk but also removes people with rare operational knowledge; hiring them may strengthen technical capabilities but raises questions from clients, regulators and insurers about controls, supervision and access.

The case also illustrates a structural asymmetry in cybercrime economics. A single breach can produce datasets that circulate globally at low marginal cost, while the burden of response falls repeatedly on companies, public agencies, consumers and governments. Victims must investigate, notify, repair systems, monitor identity risks and absorb legal exposure. Attackers, by contrast, can monetize stolen records through extortion, resale or reputational leverage.

From Isolated Breaches to Systemic Costs

On September 22, ShinyHunters posted a message on the dark web claiming it had breached an FBI database and stolen data belonging to many former and current bureau employees. The group said the material included information about psychiatric and medical evaluations of agents. It also claimed to have obtained access to data related to FBI Director Kash Patel. Reuters was able to partially verify the authenticity of the published data.

FBI representatives said they were “aware of claims of unauthorized activity” affecting the FBIjobs.gov applicant website and were investigating. The wording matters economically as well as legally: breaches connected to recruitment systems can expose not only employees but applicants, contractors and prospective personnel pipelines. For public agencies, such incidents may also carry national security implications and recruitment consequences beyond the immediate cost of technical remediation.

ShinyHunters has also been tied to several other major data leaks. In February 2026, after databases at Odido, the largest mobile operator in the Netherlands, were hacked, the group gained access to data on more than 6.2 million residents of the country. Other recent attacks attributed to ShinyHunters include the alleged theft of millions of corporate records from video game developer Rockstar Games, known for the Grand Theft Auto series, and a May attack on the educational platform Canvas that caused widespread disruptions in U.S. schools.

The pattern is economically important because it shows how data breaches have moved beyond discrete corporate events into infrastructure-level shocks. Telecom records, educational platforms, government employment systems and entertainment companies sit in very different sectors, but all depend on large identity datasets, cloud services and third-party integrations. When those systems fail, the losses are not confined to the hacked organization. They spread through customers, schools, employees, contractors and public agencies.

Historically, businesses treated cyber incidents as information technology failures. That view is increasingly inadequate. Large breaches now resemble operational risk events, with effects comparable to supply-chain disruption or financial fraud. They can alter insurance pricing, increase compliance spending, slow digital onboarding, trigger litigation and reduce trust in online public services. For governments, the stakes include the protection of personnel data and the credibility of digital recruitment and administrative platforms.

The Dutch arrest therefore matters beyond the identity of one suspect or one alleged hacking group. It points to an economy in which offensive cyber skills are valuable, stolen data is liquid, and institutional defenses are often tested by people moving between legitimate and illicit markets. The court process in Rotterdam may clarify the allegations against the detained man. The larger lesson is already visible: cyber risk is no longer a technical externality. It is a structural cost of the digital economy.

Continue Reading

Discussion