Dutch man arrested in ShinyHunters investigation
RTL reports the arrest of a 23-year-old man, but police and the Public Prosecution Service have not yet confirmed the information.
A 23-year-old Dutch national has been arrested on suspicion of involvement with hacking group ShinyHunters, RTL Nieuws reports. The group has been linked to major data thefts, including the breach at telecoms company Odido.
RTL Nieuws reported the arrest late on Monday afternoon; several Dutch media outlets picked up the report. According to those reports, the man had previously been convicted of hacking and extorting companies. We are leaving the suspect’s identity out of consideration; he is considered a suspect, not a perpetrator.
Police previously confirmed that data belonging to more than six million customers fell into criminal hands in the attack on Odido. According to the police appeal, the attackers gained access by contacting customer services by telephone and posing as an employee of the IT department. Police made a voice recording public and asked the public for information.
The new arrest has so far not been linked to a public police report, press release from the Public Prosecution Service or statement from the police. It is therefore unclear exactly what the man is suspected of, where he was arrested and whether he will be brought before a judge. It is also not known whether he is suspected of the Odido attack itself or of other activities attributed to ShinyHunters.
ShinyHunters is a loose association of cybercriminals involved in data theft and extortion. In recent weeks, the group has also claimed to have gained access to systems belonging to the US FBI. Malwarebytes described that claim, but stressed that it was an assertion by the group and not an independently established breach.
The case shows how difficult it is to attribute digital attacks to individual people. Groups use shared infrastructure, pseudonyms and intermediaries. A suspect may therefore have played a role without this establishing which attack they carried out or which data they themselves stole.
For companies, the immediate lesson mainly concerns access security and checking telephone requests for passwords or customer data. For Odido customers, the arrest in itself changes nothing about the risk that data were previously stolen. As long as police and prosecutors provide no further information, the scope of the suspicion remains uncertain.
One story, several perspectives
What is established
- The arrest was reported by RTL Nieuws, but has not yet been publicly confirmed by the police or Public Prosecution Service.
- Police confirm that data belonging to more than six million customers were stolen in the Odido attack.
- ShinyHunters has also claimed other hacks; such claims are not automatically evidence.
Left
Arguments The emphasis is on protecting citizens from data misuse and on the responsibility of companies that store personal data. Victims should receive clarity and support quickly, as well as better opportunities for compensation.
Values Privacy, digital fundamental rights and protection for people who have little influence over the security of their data.
Consequences Stricter security requirements and oversight may prove more costly for companies, but should limit the social harm caused by data breaches.
Centre
Arguments The investigation must be conducted carefully, with international cooperation and full respect for the rule of law. At the same time, companies must demonstrably invest in access controls and incident response.
Values A balance between privacy, effective law enforcement, legal protection and practical feasibility.
Consequences The emphasis is on better procedures, transparent communication and proportionate sanctions once the facts have been established.
Right
Arguments Digital extortion calls for visible enforcement and tough sentences. Companies and citizens must also take more responsibility for their own digital resilience.
Values Security, accountability and deterrence.
Consequences More powers and higher sentences may act as a deterrent, but also increase the risk of hasty conclusions while the evidence is not yet public.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved with corrections · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The official information about the Odido attack is strongly substantiated. The arrest and previous conviction are still based on reporting without a public police or Public Prosecution Service document.
- uncertain A 23-year-old Dutch national has been arrested in an investigation into ShinyHunters. — Reported by RTL Nieuws and repeated by 112Nederland; no public confirmation from the police or Public Prosecution Service was found. source
- confirmed Data belonging to more than six million customers fell into criminal hands in the Odido attack. — Confirmed in the official police appeal. source
- confirmed The attackers posed by telephone as an Odido IT employee. — Described by police in the police appeal. source
- confirmed ShinyHunters claimed to have gained access to FBI systems. — The claim was described by Malwarebytes as an assertion by the group; the breach itself was not presented as established fact. source
1 correction(s) applied
- Was: Dutch hacker (24) arrestedNow: Dutch national (23) arrested on suspicion of involvement (The public reporting gives his age as 23, and the suspicion has not yet been officially explained by the police or Public Prosecution Service.)
Editor's note
The arrest was reported by RTL Nieuws via a secondary source, but at the time of publication no public confirmation from the police or Public Prosecution Service had been found. The Odido data-breach details have been officially confirmed.Sources
- Nederlander opgepakt om vermeende banden met ShinyHunters — 112Nederland
- Datadiefstal Odido. Herkent u de stem? — Politie
- ShinyHunters beweert dat de FBI-inbreuk een wraakactie was — Malwarebytes
More on this in Dutch media
- NOS — „shinyhunters cybercrime”
- Het Parool — „shinyhunters cybercrime”
- NRC — „shinyhunters cybercrime”