{"id":98121,"date":"2026-09-29T06:23:49","date_gmt":"2026-09-29T10:23:49","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=98121"},"modified":"2026-09-29T06:23:49","modified_gmt":"2026-09-29T10:23:49","slug":"shinyhunters-dutch-arrest-amsterdam-98121","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/shinyhunters-dutch-arrest-amsterdam-98121\/","title":{"rendered":"ShinyHunters Probe Yields Dutch Arrest of Amsterdam Man, 24"},"content":{"rendered":"<p>The arrest of a 24-year-old Amsterdam man on September 15, 2026, marks a significant escalation in the international probe into the notorious cybercriminal collective ShinyHunters, a group that has redefined the landscape of data extortion and hacktivism. Dutch national police confirmed the detention, bringing a known figure from the cybersecurity underworld back into the legal spotlight just as the group claimed one of the most audacious breaches in recent memory: the compromise of the FBI\u2019s official job application portal.<\/p>\n<p>The suspect, identified by independent security journalist <a href=\"https:\/\/krebsonsecurity.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Brian Krebs<\/a> and the investigative outlet <a href=\"https:\/\/databreaches.net\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">DataBreaches.Net<\/a> as Pepijn van der Stap\u2014who operates under the alias Umbreon\u2014was taken into custody by the Politie Landelijke Opsporing en Interventies. He is scheduled to appear before the Rotterdam District Court on September 29, 2026. This arrest is not van der Stap\u2019s first encounter with the law; he was previously apprehended in 2023 for his involvement in a series of high-profile data thefts and extortion campaigns that laid the groundwork for ShinyHunters\u2019 reputation.<\/p>\n<h2>A Dual Life in Cybersecurity: From White-Hat Volunteer to Black-Hat Suspect<\/h2>\n<p>Van der Stap\u2019s profile paints a complex picture of a young professional who operated on both sides of the digital firewall. In 2023, it emerged that he held a position at the cybersecurity firm Hadrian and volunteered with the Dutch Institute for Vulnerability Disclosure (DIVD). This unique dual role\u2014working legally to secure systems while simultaneously engaging in illegal data breaches\u2014created a psychological pressure cooker. Reflecting on his mindset during that period, van der Stap told DataBreaches.Net in June 2023 that maintaining the facade of a legitimate security researcher while hiding his black-hat activities became increasingly untenable.<\/p>\n<p>\u201cWorking at Hadrian and volunteering at DIVD made me more paranoid about keeping up appearances, and I actually felt more pressure and paranoia because I was working such long hours,\u201d van der Stap stated. \u201cSo yes, I was doing more lawful work and much less illegal work but I became more paranoid about getting caught. The paranoia became so extreme that I was expecting a knock on the door at any time.\u201d That knock finally came in 2023, followed by another on September 15, 2026. Despite his past, van der Stap has since listed himself on LinkedIn as the offensive security lead at the Dutch company Neo Security, where his profile acknowledges his checkered past, stating that his journey \u201chasn\u2019t been a straight line\u201d and that he has \u201cseen security from both sides of the terminal, an experience that taught me hard lessons but ultimately gave me clarity: knowledge is for building and protecting, not breaking.\u201d<\/p>\n<h3>The FBI Breach: A Marketing Stunt or a New Chapter for ShinyHunters?<\/h3>\n<p>The arrest coincides with ShinyHunters\u2019 brazen claim of responsibility for hacking the U.S. Federal Bureau of Investigation\u2019s job application site, apply.fbijobs.gov. The group asserted it stole terabytes of <a href=\"https:\/\/overcentral.com\/en\/fortisandbox-data-exposure-flaw-80382\/\" title=\"FortiSandbox Flaw Brings Sensitive Data Exposure via HTTP Requests\" data-iacss-internal=\"1\">sensitive data<\/a>, a claim that initially sent shockwaves through the security community. However, the group\u2019s subsequent communications have framed the incident as something entirely unexpected: a marketing campaign.<\/p>\n<p>\u201cThis was all a marketing campaign to protect our business and actively combat disinformation,\u201d a ShinyHunters representative told 404 Media. \u201cIf we made this statement normally then this much attention to our words and intentions would\u2019ve never been this widespread. We\u2019d have been ignored and disregarded. However, now everyone knows what the issue is and what we are doing. Everyone is reading about it.\u201d The group doubled down on this narrative in a statement to The Hacker News, explicitly stating that the attack on the FBI\u2019s systems was not extortion and was not financially motivated.<\/p>\n<p>\u201cWe understand why many misinterpreted this as extortion and are convinced we would publish this data and\/or misuse it such as selling to third parties due to our history in past operations which has never involved a government entity of prominence,\u201d the spokesperson said. \u201cWe again want to emphasise that this is not extortion, it was never one to begin with, not a threat, not a ransom, and not financially motivated. Nothing will happen. We are way past this situation in our business operations and we confidently believe we have been successful due to seeing a recent influx of success in our operations.\u201d<\/p>\n<h3>How the FBI Breach Was Executed: A Technical Breakdown<\/h3>\n<p>ShinyHunters initially claimed to have exploited a new zero-day vulnerability in Oracle PeopleSoft to gain unauthorized access. However, subsequent analysis has revised this assessment. The group <a href=\"https:\/\/overcentral.com\/en\/claude-misuse-hacks-bioweapons-81436\/\" title=\"From Hacks to Bioweapons, Claude Misuse Is Now Everywhere\" data-iacss-internal=\"1\">is now<\/a> believed to have employed a sophisticated URL-encoding trick designed to bypass web application firewall (WAF) rules that were put in place to mitigate a known vulnerability, formally tracked as CVE-2026-35273. This technique allowed the attackers to circumvent standard security controls and siphon vast quantities of data without triggering immediate alarms. The shift in the technical narrative highlights a critical lesson for defenders: attackers are not merely finding new holes, but are developing increasingly clever methods to bypass existing patches and security layers.<\/p>\n<h2>ShinyHunters: The Evolution of a Cybercriminal Brand<\/h2>\n<p>The ShinyHunters group first gained notoriety for large-scale data breaches targeting private sector giants, selling stolen databases on underground forums. Their portfolio of victims has historically included major technology firms, e-commerce platforms, and entertainment companies. The pivot toward government targets, specifically the FBI, represents a radical escalation in both risk and ambition. The group\u2019s insistence that the FBI hack was a marketing campaign\u2014rather than a financially motivated extortion\u2014suggests an evolution in their modus operandi. They appear to be moving from a purely criminal profit model toward a hybrid model that includes attention-seeking, reputation-building, and potentially signaling their capabilities to new clients in the cybercriminal ecosystem.<\/p>\n<p>This strategic shift complicates law enforcement efforts. A financially motivated actor can often be tracked through cryptocurrency flows and ransom payments. An actor motivated by reputation or ideological goals is far harder to predict and disrupt. The arrest of van der Stap, however, signals that law enforcement is adapting. Targeting an individual suspected of being a key operator within the group can disrupt operations, sow distrust among remaining members, and provide intelligence on the group\u2019s broader structure.<\/p>\n<h3>What Is the Significance of the Dutch Arrest for Global Cybersecurity?<\/h3>\n<p>The Dutch arrest is a landmark moment for several reasons. First, it demonstrates the reach of international law enforcement cooperation. Although the primary victim in the most recent headline-grabbing attack was a U.S. federal agency, the investigation led Dutch police to act within their jurisdiction. This reinforces the message that cybercriminals cannot rely on geographic boundaries to shield them from accountability. Second, the arrest of a figure like van der Stap, who had attempted to rebrand as a legitimate security professional, serves as a deterrent to others who might consider using a white-hat career as a cover for ongoing criminal activity. It underscores that law enforcement is paying close attention to the interconnected world of cybersecurity, where the line between researcher and criminal is often thin and heavily scrutinized.<\/p>\n<h4>When Did the Arrest Occur, and What Are the Immediate Legal Steps?<\/h4>\n<p>Pepijn van der Stap was arrested on September 15, 2026, by Dutch national police. He is expected to make his first court appearance in Rotterdam on September 29, 2026. The charges are related to his alleged involvement with the ShinyHunters group. Legal experts expect the case to proceed with significant media attention, given the high-profile nature of the FBI breach and van der Stap\u2019s previous conviction. The 2023 case, which involved data theft and extortion, resulted in a conviction that placed him on probation. The current arrest likely represents a violation of those probation terms, which could lead to a significantly harsher sentence.<\/p>\n<h3>The Dual-Edged Sword of a Cybersecurity Career<\/h3>\n<p>Van der Stap\u2019s personal story offers a cautionary tale for the industry. His trajectory from a young hacker to an employee at a respected cybersecurity firm and volunteer at a vulnerability disclosure institute, all while maintaining his illegal activities, reveals the immense pressure and conflicting loyalties that can exist in the field. His own admission of paranoia highlights the psychological toll of leading a double life. For the cybersecurity community, the case raises uncomfortable questions about vetting, trust, and the ease with which an individual can weaponize legitimate security knowledge for malicious purposes. It also underscores the importance of robust background checks and ongoing monitoring for individuals in sensitive security roles.<\/p>\n<p>The narrative presented by van der Stap\u2019s LinkedIn profile\u2014that he has reformed and now uses his knowledge purely for defense\u2014is directly contradicted by the allegations leading to his second arrest. This disconnect will likely be a central theme in his upcoming trial, as prosecutors argue that his actions reveal a pattern of recidivism rather than genuine rehabilitation. The outcome of this case will be closely watched by cybersecurity professionals and legal experts alike, as it may set a precedent for how courts handle individuals who oscillate between legitimate security research and cybercrime.<\/p>\n<h3>Why Did ShinyHunters Target the FBI?<\/h3>\n<p>The ShinyHunters group has provided a clear, albeit unconventional, answer to this question. They state the operation was not about financial gain or extortion but about marketing and combating disinformation. By targeting the FBI, the group ensured global media attention, thereby amplifying whatever message they intended to convey. This tactic is a departure from traditional cybercriminal behavior, which tends to avoid unnecessary attention from the world\u2019s most powerful law enforcement agencies. It suggests that the individuals currently running ShinyHunters may be motivated by a mix of ego, ideological conviction, and a desire to establish a reputation that transcends the typical underground forum. The group\u2019s claim that they have experienced \u201can influx of success in our operations\u201d following the FBI breach suggests that, from their perspective, the risk paid off.<\/p>\n<h2>Implications for Oracle PeopleSoft and Web Application Firewalls<\/h2>\n<p>The technical method used in the FBI breach\u2014the URL-encoding trick to bypass WAF rules targeting CVE-2026-35273\u2014has immediate implications for enterprise security teams. Organizations running Oracle PeopleSoft must verify that they have applied the relevant patches for CVE-2026-35273. However, patching alone is no longer sufficient. Security teams must also carefully review their WAF configurations to ensure that URL-encoding tricks and other obfuscation techniques cannot bypass rule sets. This incident serves as a powerful reminder that WAFs are not a silver bullet; they require constant tuning and testing against known adversary techniques. The breach also highlights the critical importance of monitoring for abnormal data exfiltration patterns, regardless of whether an initial alert is triggered.<\/p>\n<p>The ShinyHunters saga, now punctuated by a major arrest and an unprecedented breach of a federal system, is far from over. The coming months will reveal whether the arrest of van der Stap cripples the group\u2019s operations or merely forces them to adapt. The group\u2019s public statements, which oscillate between defensive justification and aggressive marketing, suggest a volatile and unpredictable adversary. For governments and corporations alike, the events of <a href=\"https:\/\/overcentral.com\/en\/mech-arena-codes-september-2026-80470\/\" title=\"Mech Arena Drops New Codes for September 2026\" data-iacss-internal=\"1\">September 2026<\/a> serve as a stark reminder that the threat landscape is constantly shifting, and yesterday\u2019s patch may not protect against today\u2019s cleverly disguised attack. The most effective defense now requires a combination of robust technology, vigilant human oversight, and an intelligence-driven understanding of the motivations that drive the most daring cybercriminals.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The arrest of a 24-year-old Amsterdam man on September 15, 2026, marks a significant escalation in the international probe into the notorious cybercriminal collective ShinyHunters, a group that has redefined the landscape of data extortion and hacktivism. Dutch national police confirmed the detention, bringing a known figure from the cybersecurity underworld back into the legal [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":98124,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/98121.png","fifu_image_alt":"ShinyHunters Probe Yields Dutch Arrest of Amsterdam Man, 24","footnotes":""},"categories":[40668],"tags":[],"class_list":["post-98121","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/98121.png","fifu_image_alt":"ShinyHunters Probe Yields Dutch Arrest of Amsterdam Man, 24","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/98121","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=98121"}],"version-history":[{"count":2,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/98121\/revisions"}],"predecessor-version":[{"id":98123,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/98121\/revisions\/98123"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/98124"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=98121"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=98121"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=98121"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}