Dutch authorities have arrested a 24-year-old convicted cybercriminal on suspicion of aiding the prolific hacking group ShinyHunters in a series of data thefts and extortions. The arrest, which sources say occurred on or around September 16, 2026, has triggered a dramatic escalation in attacks by remaining ShinyHunters members, including the theft of highly sensitive data from the FBI and an extortion campaign against the Russian ransomware group Cl0p. The suspect, identified by three sources as Pepijn van der Stap, was previously convicted in 2023 for a string of cybercrimes that prosecutors said earned between €1.5 million and €2.7 million. Van der Stap had been released from prison in December 2025 and was working as an offensive security lead at a Dutch company when he was taken into custody again.
Van der Stap’s dual life as a cybersecurity professional and a hacker operating under the alias “Umbreon” has become a central theme in the investigation. At his 2023 trial, he admitted to living a Dr. Jekyll and Mr. Hyde existence: by day, he worked as a software engineer at Amsterdam-based cybersecurity startup Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research group; by night, he used the handle Umbreon to extort victims and post stolen data on hacking forums like the now-defunct RaidForums and Breached. He confessed to the activity and was sentenced to four years in prison, one of which was suspended. During his trial, he chose to remain in custody rather than at home, citing untreated PTSD from childhood trauma and a lack of adequate psychological care on the outside.
ShinyHunters retaliated by breaching the FBI's job application site and stealing personal data of over 5,000 officials.
The arrest appears to have triggered a chain reaction within the ShinyHunters collective. Just days after van der Stap was detained, the group claimed credit for a brazen breach of the FBI’s job application site, apply.fbijobs.gov. According to reporting from 404 Media and Reuters, the stolen data includes Social Security numbers and personal information on more than 5,000 FBI officials, including job titles such as special agent, threat intake examiner, and members of the major cybercrimes unit. Reuters examined documents shared by ShinyHunters and found they included sensitive psychiatric and medical files of FBI staff. The FBI issued a brief statement confirming the hack. ShinyHunters said it gained access by exploiting a recently patched vulnerability in Oracle’s PeopleSoft platform, designated CVE-2026-35273. The group reportedly began exploiting the vulnerability as a zero-day in June, and Oracle quickly issued a fix. Mandiant released web application firewall rules to mitigate the threat, but ShinyHunters later used a URL-encoding trick to bypass those rules, as reported by BleepingComputer. In a report released September 25, Mandiant and the Google Threat Intelligence Group confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across higher education, technology, healthcare, agriculture, transportation, and government sectors.
Why Did ShinyHunters Escalate After the Arrest?
Multiple sources close to the investigation say the group’s recent attacks against the FBI and Cl0p represent a major pivot from the more measured tenor of ShinyHunters’ previous operations. The sudden shift came after ShinyHunters was taken over by a teenage cybercriminal from Amman, Jordan, who goes by the nickname “Rey.” Rey operates as part of a cybercrime group called ScatteredLapsussHunters (SLSH), which experts describe as an amalgamation of three hacking groups: Scattered Spider, LAPSUS$, and ShinyHunters. Sources say Rey had an ongoing feud with van der Stap over control of the ShinyHunters brand and stolen data. The inclusion of an oversized ASCII art rendition of the Pokemon character Umbreon in the FBI jobs site defacement — the same defacement used in the group’s 2020 hack of Hackforums — was likely an attempt by Rey to pin the FBI hack on the Dutchman.
Rey was first publicly identified by the cybersecurity firm KELA in March 2025. In a November 2025 profile, KrebsOnSecurity contacted Rey’s father, an employee of Royal Jordanian Airlines, to request an interview. Rey’s father forwarded the message to his son, who admitted to participating in ransomware attacks and said he was trying to extricate himself from SLSH. After the FBI hack, Rey’s now-deleted Twitter/X account taunted both Cl0p and the FBI with a meme depicting the twin towers struck by planes labeled “cl0p drama” and “fbi breach claim,” with a giant Umbreon figure in the foreground. When KrebsOnSecurity again contacted Rey’s father for comment on Rey’s apparent ascendency as the head of ShinyHunters, the teenage hacker deleted his account hours later. His father has not responded to multiple emailed requests.
The Dutch Police Investigation and Public Appeal
Authorities in the Netherlands have been asking the public for help in identifying the voice in a recorded telephone call from February 2026. In that call, a native Dutch-speaking ShinyHunters member used social engineering to breach Odido, the nation’s largest mobile telecommunications provider. The member tricked an Odido employee into logging in at a spoofed website, then used that access to steal data on more than 6.2 million Dutch people. Responding to Dutch news media, ShinyHunters confirmed that the suspect in the audio clip is a member of the collective. “Our team member has our full support – emotionally, mentally, and financially,” the hackers said in a statement shared with NL Times. “Everything has been arranged, including a criminal defense lawyer.” The group also lashed out at the Dutch police, calling them a “big joke” and “incompetent.” It remains unclear if the police have matched the Odido caller to a confirmed real-life identity.
Van der Stap’s arrest was confirmed by Dutch police in a statement on Twitter/X on September 28. The police said the man will appear on Tuesday, September 29 before the chambers of the Rotterdam District Court, and that more information will be provided the following day. Meanwhile, the Dutch news outlet RTL reported that investigators suspect van der Stap tried to orchestrate at least two murders, allegedly to be committed abroad, with indications that he gave the order for this. The FBI released a short video message from Brett Leatherman, assistant director of the FBI’s cyber division, thanking Dutch law enforcement and urging remaining ShinyHunters members to turn themselves in. “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left,” Leatherman said. “The longer you stay in this, the more we learn about you.”
Van der Stap’s Background and the ShinyHunters Evolution
Van der Stap’s criminal career predates his involvement with ShinyHunters. In an interview with Bloomberg in 2024, he said his motivation was never money but a desire to collect the world’s most complete set of stolen databases. “The hacking was very easy for me, and it wasn’t a compulsion,” he told Bloomberg. “My habit was collecting. Collecting data, organizing data, downloading data, creating folders.” After his release from prison in December 2025, he presented himself as a reformed hacker. In a September 9, 2026 interview with KrebsOnSecurity, he described trying to turn his life around and make a positive contribution to society while working as offensive security lead at Neo Security in the Netherlands. But not long after that interview, he stopped replying to messages, and efforts by others close to him failed to elicit a response for two weeks — coinciding with his arrest.
Van der Stap’s former employer, the nonprofit security research group DIVD, disclosed on LinkedIn that it was dealing with an internal cybersecurity incident involving the malicious use of artificial intelligence. A spokesperson for DIVD told KrebsOnSecurity that the incident does not appear related to ShinyHunters nor to the work of a previous volunteer. Separately, according to a Wired story this month by Andy Greenberg, ShinyHunters and SLSH members briefly partnered earlier in 2026 to monetize stolen credentials collected by TeamPCP, an upstart group that had compromised global code supply chains but had not profited much. Mandiant had infiltrated TeamPCP and was secretly feeding their stolen credentials to cloud providers like Amazon and Microsoft, causing the credentials to be invalidated. The formerly cooperating groups began blaming one another for the worthless credentials. ShinyHunters then went rogue, extorting victims with TeamPCP’s credentials without giving the supply-chain hackers their cut. Mandiant researcher Austin Larsen told KrebsOnSecurity that ShinyHunters is on track to pull in nearly $100 million in extortion payments in 2026.
What Is the Significance of the FBI and Cl0p Attacks?
The FBI breach represents a major escalation in the group’s audacity. The stolen data included not only personally identifiable information but also sensitive medical and psychiatric records of FBI staff. The attack exploited a zero-day vulnerability in Oracle PeopleSoft, which is widely used for hiring and HR management across many organizations. ShinyHunters reportedly used a URL-encoding trick to bypass Mandiant’s recommended web application firewall rules, as detailed by BleepingComputer. The group also claimed credit for extorting the Cl0p ransomware group — one of Russia’s most venerated cybercrime operations. This dual attack on U.S. federal law enforcement and a Russian ransomware gang underscores the group’s willingness to take on high-risk targets, a departure from its earlier focus on corporate and consumer data theft.
For users seeking to understand the current threat landscape, the ShinyHunters case illustrates the fluidity of hacking ecosystems, where individuals and groups merge, split, and target each other. The involvement of a teenage leader, Rey, and the conflict with van der Stap highlight the personal rivalries that can drive cybercriminal behavior. The Dutch police’s public appeal and the arrest of a previously convicted cybercriminal signal a coordinated international effort to dismantle the group. However, the group’s rapid retaliation — hacking the FBI and threatening more large-scale data thefts in the Netherlands — suggests that law enforcement actions can provoke immediate, significant consequences.
The arrest of van der Stap and the resulting surge in attacks by ShinyHunters mark a turning point in the group’s history. Whether the combined pressure from Dutch and U.S. authorities, along with internal strife, will lead to the group’s dissolution or further radicalization remains to be seen. The FBI’s warning that “arrests have a way of changing who is willing to talk” may prompt defections among ShinyHunters members, but the group’s demonstrated capacity for revenge attacks indicates that the fight is far from over. Organizations using Oracle PeopleSoft should ensure they have applied the latest patches and configured WAF rules correctly, as the vulnerability remains a vector for exploitation. The broader lesson is that cybercriminal networks, once destabilized, can become more dangerous before they collapse.
- Who was arrested by Dutch authorities?Dutch authorities arrested 24-year-old Pepijn van der Stap, a convicted cybercriminal also known as Umbreon, on suspicion of aiding ShinyHunters.
- What data did ShinyHunters steal from the FBI?ShinyHunters stole Social Security numbers and personal information of over 5,000 FBI officials, including sensitive psychiatric and medical files.
- How did ShinyHunters breach the FBI system?ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, CVE-2026-35273, using a URL-encoding trick to bypass firewall rules.