Dutch police have arrested a 24-year-old Amsterdam man on suspicion of working with ShinyHunters, the extortion crew that has spent the past year ransacking hospitals and their software vendors. He appeared before Rotterdam District Court on September 29.
Officers did not name the suspect, but Brian Krebs, working with the breach-tracking site DataBreaches.net, put a face on the case: Pepijn van der Stap, who used the handle Umbreon, served time for earlier data thefts, and later took a job in the security industry. The Dutch force confirmed the arrest followed an investigation into the group.
The FBI says the crew has breached more than 140 organizations since 2025 and pulled in at least $70M in extortion payments. Investigators have tied the group to stolen records covering federal employees, corporate help desks, and healthcare providers.
The arrest lands as health systems digest another year of ShinyHunters campaigns. The crew has repeatedly gone after connected business software rather than hospital networks directly, using voice phishing and hijacked single sign-on accounts to reach patient and workforce data held inside vendors, including a PeopleSoft-driven extortion push that swept through hospitals this month.
For security teams, the lesson is unchanged. Extortion crews are targeting the identity layer, meaning help desks, SaaS tenants, and the third parties that hold PHI. Reviewing which vendors can reach patient data, tightening MFA reset flows, and rehearsing breach communications remain the practical defenses while the group adapts.