Skip to main content
Threat IntelligenceEmerging Threats

Dutch Hacker Arrest Sparks ShinyHunters Escalation

Courthouse exterior with stone facade, tall windows, and flags in daylight.

“Our team member has our full support – emotionally, mentally, and financially,” ShinyHunters wrote in response to Dutch reporting about a suspected member, adding that “Everything has been arranged, including a criminal defense lawyer.”

The arrest: Pepijn van der Stap detained in mid‑September

Dutch authorities arrested a 24‑year‑old man this month in connection with the long‑running ShinyHunters investigation; three sources named him to reporters as Pepijn van der Stap of Almere and Lelystad. According to those sources, he was taken into custody on or around September 16 and has been held for questioning. The Dutch police later confirmed the arrest and said the man will appear on Tuesday, September 29 before the chambers of the Rotterdam District Court.

Van der Stap is a convicted cybercriminal who admitted during a 2023 trial that he had operated under the hacker handle “Umbreon.” Prosecutors at that time said the string of thefts and extortions he was linked to earned between €1.5 million and €2.7 million; he was sentenced to four years in prison, with one year suspended, and he was released in December 2025. At trial he told the court he lived a “Dr. Jekyll and Mr. Hyde existence.”

ShinyHunters escalates: FBI breach, extortion of Cl0p, and PeopleSoft exploitation (CVE‑2026‑35273)

Sources say the group dramatically escalated operations in the days after van der Stap’s detention. ShinyHunters claimed credit for a breach of the FBI job application site apply.fbijobs.gov; 404 Media and Reuters reported the data stolen from the FBI site included Social Security numbers and personal information on more than 5,000 officials, and Reuters said shared documents included sensitive psychiatric and medical files of FBI staff. The FBI issued a brief confirmation of the hack.

ShinyHunters told reporters it exploited a recently patched PeopleSoft vulnerability identified as CVE‑2026‑35273. Oracle issued a fix for the PeopleSoft flaw, and Mandiant released web application firewall (WAF) rules for organizations that could not immediately patch. BleepingComputer later reported ShinyHunters used a URL‑encoding trick to bypass those WAF rules. On Sept. 25, security teams at Mandiant and the Google Threat Intelligence Group (GTIG) published a report confirming mass exploitation of the PeopleSoft vulnerability and data thefts from dozens of systems across higher education, technology, healthcare, agriculture, transportation and government.

Imagery, handles and intra‑group strife: Umbreon and the rise of “Rey”

The Umbreon persona linked to van der Stap has appeared in several places tied to ShinyHunters activity. KELA and reporting show an Umbreon avatar selling a database on RaidForums in September 2021, and the defacement image left on the FBI jobs site included an ASCII art Umbreon identical to images used by ShinyHunters in earlier hacks. Multiple investigative sources told reporters that an Amman‑based teenager known as Rey — publicly identified by KELA in March 2025 — has moved to take operational control of ShinyHunters as part of an amalgamated group nicknamed SLSH (ScatteredLapsussHunters), which merges elements of Scattered Spider, LAPSUS$ and ShinyHunters. Those sources allege Rey and the Dutch hacker had an ongoing dispute over control and branding, and that Rey may have deliberately included Umbreon imagery to pin recent attacks on van der Stap.

Rey briefly taunted both the FBI and the Cl0p ransomware group on social media with a meme that prominently featured Umbreon; within hours of outreach from reporters, Rey deleted a longtime account.

Odido call, Dutch investigation, and DIVD incident

Dutch police have publicly asked the population for help identifying the voice in a recorded February 2026 telephone call in which a native Dutch speaker social‑engineered an Odido employee and set up a spoofed login that led to the theft of data on more than 6.2 million Dutch people. ShinyHunters confirmed that the suspect in the audio clip is a member of the collective, and the group’s public statement attacked Dutch law enforcement as “incompetent” and warned the police to “catch him before we carry out another large‑scale data theft in the Netherlands.” It remains unclear whether investigators have matched the voice to a confirmed identity.

Separately, the Dutch nonprofit security research group DIVD disclosed an internal cybersecurity incident involving apparent malicious use of artificial intelligence; a DIVD spokesperson told reporters the incident does not appear related to ShinyHunters nor to any previous volunteer.

Responses from defenders, law enforcement, and extortion economics

Oracle issued a PeopleSoft patch after the vulnerability was identified, and Mandiant published temporary WAF rules for defenders; ShinyHunters’ reported use of URL encoding to evade those rules was reported by BleepingComputer. Mandiant researcher Austin Larsen told reporters that ShinyHunters has been on track to collect nearly $100 million in extortion payments in 2026, and Wired reporting traced recent friction between groups to a failed partnership with TeamPCP, whose stolen credentials were allegedly invalidated after Mandiant fed them to major cloud providers. Wired’s reporting quoted Mandiant researcher actions as a factor that led to ShinyHunters and partner groups accusing one another of sabotaging the credentials’ value.

What this means for the FBI, Odido, and Neo Security

  • FBI: The agency confirmed a breach of its jobs site; reporting shows personal and highly sensitive files on more than 5,000 officials were among the stolen records, a breach with direct personnel‑security and privacy consequences.
  • Odido and Dutch telecoms: Dutch police are seeking public help to identify the caller in the February social‑engineering incident that exposed data on 6.2 million customers; the public appeal signals an investigatory focus on voice attribution in large‑scale telecom intrusions.
  • Neo Security and previous employers: Reporting notes van der Stap was working as offensive security lead at Neo Security and previously as a software engineer at Hadrian; Neo Security did not respond to requests for comment and employers tied to individuals under investigation face reputational and legal questions that reporters say are active in this case.

The arrest ties a named individual with a known alias, a history of conviction and release, and a circle of violent public taunting between rival cybercriminal factions. Dutch authorities have signalled they will present more information at the Rotterdam hearing on September 29; meanwhile ShinyHunters’ public attacks and the confirmed PeopleSoft mass exploit leave a trail of breached organizations, a contested chain of custody for stolen credentials, and fresh questions about attribution when intra‑group rivalries weaponize familiar handles and imagery.

Source: KrebsOnSecurity — Dutch Police Arrest ‘Reformed’ Hacker in ShinyHunters Investigation