Cybersecurity

Dutch Authorities Arrest Convicted Cybercriminal Pepijn van der Stap in Connection with Massive ShinyHunters Data Theft Operations

The recent arrest of 24-year-old Dutch national Pepijn van der Stap has sent shockwaves through the global cybersecurity community, marking a significant escalation in the ongoing international investigation into the notorious hacking collective known as ShinyHunters. Van der Stap, a convicted cybercriminal previously identified by the alias "Umbreon," was taken into custody by Dutch law enforcement on or around September 16, 2026. Authorities suspect him of providing critical infrastructure and technical support for a series of high-profile data thefts and extortion campaigns that have targeted major corporations and government entities alike.

The apprehension of van der Stap follows a long and complicated history of digital transgressions. In 2023, the Dutch judiciary sentenced him to four years in prison—with one year suspended—for his role in a series of data breaches that prosecutors estimated generated between €1.5 million and €2.7 million. During his trial, van der Stap provided a candid, if chilling, assessment of his double life. By day, he functioned as a software engineer for the Amsterdam-based cybersecurity startup Hadrian and volunteered for the Dutch Institute for Vulnerability Disclosure (DIVD). By night, he operated as "Umbreon," a prolific figure on underground forums such as RaidForums and Breached, where he traded in stolen personal records and facilitated digital extortion.

A Chronology of Escalation

The arrest has acted as a catalyst for a dramatic shift in the tactics employed by the remnants of the ShinyHunters group. Following the detention of their alleged collaborator, the group pivoted toward increasingly brazen and high-risk targets. Just days after the Dutch authorities moved to detain van der Stap, ShinyHunters claimed responsibility for a sophisticated breach of the FBI’s job application portal, apply.fbijobs.gov.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

The scope of the breach was severe. Data stolen from the federal agency included Social Security numbers and detailed personal files on over 5,000 FBI officials, including individuals working in sensitive positions such as special agents and cyber threat analysts. Security researchers, including those at Mandiant and the Google Threat Intelligence Group, have since confirmed that the group utilized a zero-day exploit—CVE-2026-35273—within Oracle’s PeopleSoft platform. While Oracle moved rapidly to patch the vulnerability, evidence suggests that ShinyHunters successfully bypassed subsequent mitigation measures by employing advanced URL-encoding techniques.

The group’s aggressive posture is not limited to government agencies. In a move that surprised many industry observers, ShinyHunters also targeted the Russian ransomware group Cl0p, effectively extorting a peer in the criminal underworld. This erratic, high-stakes behavior represents a sharp departure from the group’s historical patterns, suggesting a chaotic power struggle following the arrest of key personnel.

The Rise of "Rey" and the SLSH Collective

The transition in ShinyHunters’ operational philosophy is reportedly linked to the emergence of a teenage cybercriminal from Amman, Jordan, known by the handle "Rey." Identified in 2025 by the security firm KELA, Rey is a central figure in the ScatteredLapsussHunters (SLSH) group—a coalition formed from the remnants of Scattered Spider, LAPSUS$, and ShinyHunters.

Intelligence sources suggest that the relationship between van der Stap and Rey was fraught with tension. The inclusion of the "Umbreon" mascot in the ASCII art left on the compromised FBI servers is widely interpreted by security analysts as a calculated move by Rey to frame the incarcerated Dutchman, potentially to solidify control over the group’s brand and assets. This internal friction, coupled with the group’s recent failures to monetize credentials following the collapse of the "TeamPCP" supply-chain hacking gang, has created a desperate and volatile environment for the collective.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

The Human Cost and Official Responses

While van der Stap has previously claimed that his motivations were rooted in a compulsive need to collect and organize data rather than monetary gain, the legal consequences he now faces are grave. Beyond the cybercrime charges, recent reports from the Dutch news outlet RTL indicate that investigators are probing allegations that van der Stap may have attempted to orchestrate at least two murders abroad.

The Dutch police have been meticulous in their public outreach, even releasing audio recordings of a ShinyHunters member who successfully used social engineering to infiltrate Odido, the Netherlands’ largest telecommunications provider, in February 2026. That breach resulted in the exposure of data belonging to more than 6.2 million Dutch citizens.

In a rare public statement regarding an ongoing investigation, the FBI’s assistant director of the cyber division, Brett Leatherman, issued a stern warning to the remaining members of ShinyHunters. "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left," Leatherman noted. He encouraged members to cooperate with authorities, signaling that the window for leniency is rapidly closing as federal investigators continue to map the group’s internal hierarchy.

Broader Implications for Cybersecurity

The "Umbreon" case underscores a growing trend in the cybersecurity landscape: the infiltration of the legitimate security industry by individuals with criminal intent. Van der Stap’s ability to work for security startups and research nonprofits while simultaneously orchestrating large-scale data breaches highlights a systemic vulnerability in hiring and vetting processes within the tech sector.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Furthermore, the mass exploitation of the PeopleSoft vulnerability serves as a stark reminder of the risks inherent in supply-chain software. As organizations increasingly rely on centralized human resources and payroll platforms, these systems have become "crown jewels" for threat actors. Mandiant’s report, which confirmed that ShinyHunters successfully exploited systems across the healthcare, transportation, and government sectors, emphasizes the need for rapid patch management and more robust web application firewall configurations.

As of late September 2026, the situation remains fluid. Van der Stap is expected to face further legal proceedings in the Rotterdam District Court, while global intelligence agencies continue to track the remnants of the SLSH coalition. The shift from data theft for profit to high-visibility, politically charged attacks on national security infrastructure marks a dangerous new chapter in the history of global cyber-warfare. For the victims of these breaches—ranging from federal agents to millions of mobile phone users—the consequences will be felt for years, as sensitive personal data remains in the hands of actors whose behavior is as unpredictable as it is malicious.

The case of the "Umbreon" alias serves as a cautionary tale for both the security industry and the criminal underworld. It demonstrates that while the digital world offers anonymity, the intersection of physical-world evidence, international law enforcement cooperation, and internal gang rivalries eventually brings even the most elusive actors into the light. As authorities continue to dismantle the infrastructure associated with ShinyHunters, the focus now turns to whether the collective will retreat into the shadows or continue its current path of self-destructive, high-stakes provocation.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button