Skip to main content
Threat IntelligenceEmerging Threats

Dutch Police Apprehend ShinyHunters Hacker in Amsterdam

Dutch police officer stands near courthouse with detained 24-year-old man.

"It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies wrote on X, signaling a concrete law-enforcement step in a case that has rippled across security circles and federal agencies.

Dutch police confirmation and next legal step

Dutch authorities confirmed the arrest and said the individual is expected to appear before the Rotterdam District Court on September 29, 2026. Police did not disclose additional details in their public message beyond the age, city of residence and forthcoming court appearance. Independent reporting identified a specific arrest date of September 15, 2026.

Independent reporting identifies the suspect as Pepijn van der Stap (aka "Umbreon")

Independent security journalist Brian Krebs and DataBreaches.Net identified the arrested man as Pepijn van der Stap, also known by the handle "Umbreon." Reporting notes that van der Stap was previously apprehended in 2023 for his alleged role in a series of data thefts and extortions. DataBreaches.Net reported the September 15, 2026 arrest.

Prior reporting from 2023 is part of the public record about the individual’s background: in that year it emerged that he worked at the cybersecurity company Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD). In a June 2023 interview with DataBreaches.Net he said, "Working at Hadrian and volunteering at DIVD made me more paranoid about keeping up appearances, and I actually felt more pressure and paranoia because I was working such long hours," adding that he had been "expecting a knock on the door at any time."

According to LinkedIn, he is presently employed as the offensive security lead at Neo Security. His profile acknowledges a checkered path: he wrote that his journey "hasn't been a straight line" and that "I've seen security from both sides of the terminal, an experience that taught me hard lessons but ultimately gave me clarity: knowledge is for building and protecting, not breaking."

ShinyHunters claims and public statements about the FBI breach

The arrest comes amid ShinyHunters’ public claims of responsibility for a high-profile intrusion of the U.S. Federal Bureau of Investigation's job application site, apply.fbijobs.gov, an incident the group says involved the theft of terabytes of sensitive data. A ShinyHunters representative told 404 Media: "This was all a marketing campaign to protect our business and actively combat disinformation." The group argued that the publicity was intentional: "If we made this statement normally then this much attention to our words and intentions would’ve never been this widespread," the representative said.

In a statement shared with The Hacker News, ShinyHunters reiterated that the attack on the FBI's systems was not extortion and "not financially motivated." The group said, "We understand why many misinterpreted this as extortion and are convinced we would publish this data and/or misuse it such as selling to third parties due to our history in past operations which has never involved a government entity of prominence." They added, "We again want to emphasise that this is not extortion, it was never one to begin with, not a threat, not a ransom, and not financially motivated."

Technical detail: zero‑day claim and an assessed WAF bypass

ShinyHunters claimed to have exploited a new zero-day flaw in Oracle PeopleSoft to gain unauthorized access and siphon the data. It is now assessed that ShinyHunters employed a URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate CVE-2026-35273. The juxtaposition of a claimed zero-day and a reported URL-encoding WAF bypass will be a central technical point in any subsequent forensic and legal review.

What this means for technologists, law enforcement, and employers

  • Technologists and security teams: the matter touches on WAF rule effectiveness and CVE-2026-35273 specifically; the reported use of a URL-encoding trick to circumvent WAF protections highlights the need to reassess rules and detection for encoded inputs and similar bypass techniques.
  • Law enforcement and the courts: the arrested individual is scheduled to appear before the Rotterdam District Court on September 29, 2026, and Dutch police have framed the arrest as part of an ongoing investigation into the ShinyHunters group.
  • Employers and professional peers (Hadrian, DIVD, Neo Security): media reporting linked the arrested individual to prior roles at Hadrian and DIVD and to a current role at Neo Security; those connections are now publicly noted and likely to prompt internal review and external scrutiny.

The case brings together competing public claims—an arrest announced by Dutch police, independent identification of the suspect, ShinyHunters’ own statements about motive and method, and an assessed technical bypass of WAF rules intended to mitigate CVE-2026-35273. The Rotterdam court appearance on September 29, 2026, will be the first public legal step after the arrest; beyond that date, how courts and investigators reconcile the technical assessments, the group's public messaging, and prior allegations from 2023 will determine the next chapter of this investigation.

Source: The Hacker News — Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation