ShinyHunters Probe Yields Dutch Arrest of Amsterdam Man, 24

A 24-year-old Amsterdam man arrested in connection with the ShinyHunters cybercriminal collective, linked to the FBI job portal breach.

By Central
The suspect, Pepijn van der Stap, also known as Umbreon, was previously arrested in 2023 for data thefts.
Highlights
  • The suspect worked at cybersecurity firm Hadrian and volunteered with DIVD while engaging in illegal breaches.
  • ShinyHunters claimed responsibility for hacking the FBI's job application portal using a URL-encoding trick.
  • The arrest occurred on September 15, 2026, and the suspect faces court on September 29, 2026.

The arrest of a 24-year-old Amsterdam man on September 15, 2026, marks a significant escalation in the international probe into the notorious cybercriminal collective ShinyHunters, a group that has redefined the landscape of data extortion and hacktivism. Dutch national police confirmed the detention, bringing a known figure from the cybersecurity underworld back into the legal spotlight just as the group claimed one of the most audacious breaches in recent memory: the compromise of the FBI’s official job application portal.

The suspect, identified by independent security journalist Brian Krebs and the investigative outlet DataBreaches.Net as Pepijn van der Stap—who operates under the alias Umbreon—was taken into custody by the Politie Landelijke Opsporing en Interventies. He is scheduled to appear before the Rotterdam District Court on September 29, 2026. This arrest is not van der Stap’s first encounter with the law; he was previously apprehended in 2023 for his involvement in a series of high-profile data thefts and extortion campaigns that laid the groundwork for ShinyHunters’ reputation.

The paranoia became so extreme that I was expecting a knock on the door at any time.

A Dual Life in Cybersecurity: From White-Hat Volunteer to Black-Hat Suspect

Van der Stap’s profile paints a complex picture of a young professional who operated on both sides of the digital firewall. In 2023, it emerged that he held a position at the cybersecurity firm Hadrian and volunteered with the Dutch Institute for Vulnerability Disclosure (DIVD). This unique dual role—working legally to secure systems while simultaneously engaging in illegal data breaches—created a psychological pressure cooker. Reflecting on his mindset during that period, van der Stap told DataBreaches.Net in June 2023 that maintaining the facade of a legitimate security researcher while hiding his black-hat activities became increasingly untenable.

“Working at Hadrian and volunteering at DIVD made me more paranoid about keeping up appearances, and I actually felt more pressure and paranoia because I was working such long hours,” van der Stap stated. “So yes, I was doing more lawful work and much less illegal work but I became more paranoid about getting caught. The paranoia became so extreme that I was expecting a knock on the door at any time.” That knock finally came in 2023, followed by another on September 15, 2026. Despite his past, van der Stap has since listed himself on LinkedIn as the offensive security lead at the Dutch company Neo Security, where his profile acknowledges his checkered past, stating that his journey “hasn’t been a straight line” and that he has “seen security from both sides of the terminal, an experience that taught me hard lessons but ultimately gave me clarity: knowledge is for building and protecting, not breaking.”

The FBI Breach: A Marketing Stunt or a New Chapter for ShinyHunters?

The arrest coincides with ShinyHunters’ brazen claim of responsibility for hacking the U.S. Federal Bureau of Investigation’s job application site, apply.fbijobs.gov. The group asserted it stole terabytes of sensitive data, a claim that initially sent shockwaves through the security community. However, the group’s subsequent communications have framed the incident as something entirely unexpected: a marketing campaign.

“This was all a marketing campaign to protect our business and actively combat disinformation,” a ShinyHunters representative told 404 Media. “If we made this statement normally then this much attention to our words and intentions would’ve never been this widespread. We’d have been ignored and disregarded. However, now everyone knows what the issue is and what we are doing. Everyone is reading about it.” The group doubled down on this narrative in a statement to The Hacker News, explicitly stating that the attack on the FBI’s systems was not extortion and was not financially motivated.

“We understand why many misinterpreted this as extortion and are convinced we would publish this data and/or misuse it such as selling to third parties due to our history in past operations which has never involved a government entity of prominence,” the spokesperson said. “We again want to emphasise that this is not extortion, it was never one to begin with, not a threat, not a ransom, and not financially motivated. Nothing will happen. We are way past this situation in our business operations and we confidently believe we have been successful due to seeing a recent influx of success in our operations.”

How the FBI Breach Was Executed: A Technical Breakdown

ShinyHunters initially claimed to have exploited a new zero-day vulnerability in Oracle PeopleSoft to gain unauthorized access. However, subsequent analysis has revised this assessment. The group is now believed to have employed a sophisticated URL-encoding trick designed to bypass web application firewall (WAF) rules that were put in place to mitigate a known vulnerability, formally tracked as CVE-2026-35273. This technique allowed the attackers to circumvent standard security controls and siphon vast quantities of data without triggering immediate alarms. The shift in the technical narrative highlights a critical lesson for defenders: attackers are not merely finding new holes, but are developing increasingly clever methods to bypass existing patches and security layers.

ShinyHunters: The Evolution of a Cybercriminal Brand

The ShinyHunters group first gained notoriety for large-scale data breaches targeting private sector giants, selling stolen databases on underground forums. Their portfolio of victims has historically included major technology firms, e-commerce platforms, and entertainment companies. The pivot toward government targets, specifically the FBI, represents a radical escalation in both risk and ambition. The group’s insistence that the FBI hack was a marketing campaign—rather than a financially motivated extortion—suggests an evolution in their modus operandi. They appear to be moving from a purely criminal profit model toward a hybrid model that includes attention-seeking, reputation-building, and potentially signaling their capabilities to new clients in the cybercriminal ecosystem.

This strategic shift complicates law enforcement efforts. A financially motivated actor can often be tracked through cryptocurrency flows and ransom payments. An actor motivated by reputation or ideological goals is far harder to predict and disrupt. The arrest of van der Stap, however, signals that law enforcement is adapting. Targeting an individual suspected of being a key operator within the group can disrupt operations, sow distrust among remaining members, and provide intelligence on the group’s broader structure.

What Is the Significance of the Dutch Arrest for Global Cybersecurity?

The Dutch arrest is a landmark moment for several reasons. First, it demonstrates the reach of international law enforcement cooperation. Although the primary victim in the most recent headline-grabbing attack was a U.S. federal agency, the investigation led Dutch police to act within their jurisdiction. This reinforces the message that cybercriminals cannot rely on geographic boundaries to shield them from accountability. Second, the arrest of a figure like van der Stap, who had attempted to rebrand as a legitimate security professional, serves as a deterrent to others who might consider using a white-hat career as a cover for ongoing criminal activity. It underscores that law enforcement is paying close attention to the interconnected world of cybersecurity, where the line between researcher and criminal is often thin and heavily scrutinized.

When Did the Arrest Occur, and What Are the Immediate Legal Steps?

Pepijn van der Stap was arrested on September 15, 2026, by Dutch national police. He is expected to make his first court appearance in Rotterdam on September 29, 2026. The charges are related to his alleged involvement with the ShinyHunters group. Legal experts expect the case to proceed with significant media attention, given the high-profile nature of the FBI breach and van der Stap’s previous conviction. The 2023 case, which involved data theft and extortion, resulted in a conviction that placed him on probation. The current arrest likely represents a violation of those probation terms, which could lead to a significantly harsher sentence.

The Dual-Edged Sword of a Cybersecurity Career

Van der Stap’s personal story offers a cautionary tale for the industry. His trajectory from a young hacker to an employee at a respected cybersecurity firm and volunteer at a vulnerability disclosure institute, all while maintaining his illegal activities, reveals the immense pressure and conflicting loyalties that can exist in the field. His own admission of paranoia highlights the psychological toll of leading a double life. For the cybersecurity community, the case raises uncomfortable questions about vetting, trust, and the ease with which an individual can weaponize legitimate security knowledge for malicious purposes. It also underscores the importance of robust background checks and ongoing monitoring for individuals in sensitive security roles.

The narrative presented by van der Stap’s LinkedIn profile—that he has reformed and now uses his knowledge purely for defense—is directly contradicted by the allegations leading to his second arrest. This disconnect will likely be a central theme in his upcoming trial, as prosecutors argue that his actions reveal a pattern of recidivism rather than genuine rehabilitation. The outcome of this case will be closely watched by cybersecurity professionals and legal experts alike, as it may set a precedent for how courts handle individuals who oscillate between legitimate security research and cybercrime.

Why Did ShinyHunters Target the FBI?

The ShinyHunters group has provided a clear, albeit unconventional, answer to this question. They state the operation was not about financial gain or extortion but about marketing and combating disinformation. By targeting the FBI, the group ensured global media attention, thereby amplifying whatever message they intended to convey. This tactic is a departure from traditional cybercriminal behavior, which tends to avoid unnecessary attention from the world’s most powerful law enforcement agencies. It suggests that the individuals currently running ShinyHunters may be motivated by a mix of ego, ideological conviction, and a desire to establish a reputation that transcends the typical underground forum. The group’s claim that they have experienced “an influx of success in our operations” following the FBI breach suggests that, from their perspective, the risk paid off.

Implications for Oracle PeopleSoft and Web Application Firewalls

The technical method used in the FBI breach—the URL-encoding trick to bypass WAF rules targeting CVE-2026-35273—has immediate implications for enterprise security teams. Organizations running Oracle PeopleSoft must verify that they have applied the relevant patches for CVE-2026-35273. However, patching alone is no longer sufficient. Security teams must also carefully review their WAF configurations to ensure that URL-encoding tricks and other obfuscation techniques cannot bypass rule sets. This incident serves as a powerful reminder that WAFs are not a silver bullet; they require constant tuning and testing against known adversary techniques. The breach also highlights the critical importance of monitoring for abnormal data exfiltration patterns, regardless of whether an initial alert is triggered.

The ShinyHunters saga, now punctuated by a major arrest and an unprecedented breach of a federal system, is far from over. The coming months will reveal whether the arrest of van der Stap cripples the group’s operations or merely forces them to adapt. The group’s public statements, which oscillate between defensive justification and aggressive marketing, suggest a volatile and unpredictable adversary. For governments and corporations alike, the events of September 2026 serve as a stark reminder that the threat landscape is constantly shifting, and yesterday’s patch may not protect against today’s cleverly disguised attack. The most effective defense now requires a combination of robust technology, vigilant human oversight, and an intelligence-driven understanding of the motivations that drive the most daring cybercriminals.

Questions answered
  • Who was arrested in the ShinyHunters probe?A 24-year-old Amsterdam man identified as Pepijn van der Stap, who operates under the alias Umbreon.
  • What breach did ShinyHunters claim responsibility for?They claimed responsibility for hacking the FBI's official job application portal.
  • What was the suspect's dual role in cybersecurity?He worked at the cybersecurity firm Hadrian and volunteered with the Dutch Institute for Vulnerability Disclosure while engaging in illegal data breaches.
Share This Article