{"id":98857,"date":"2026-10-03T06:29:02","date_gmt":"2026-10-03T10:29:02","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=98857"},"modified":"2026-10-03T06:29:02","modified_gmt":"2026-10-03T10:29:02","slug":"shinyhunters-hacker-arrest-fbi-breach-98857","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/shinyhunters-hacker-arrest-fbi-breach-98857\/","title":{"rendered":"Netherlands Nabs Hacker as ShinyHunters Attacks FBI"},"content":{"rendered":"<p>Dutch authorities have arrested a 24-year-old convicted cybercriminal on suspicion of aiding the prolific hacking group ShinyHunters in a series of data thefts and extortions. The arrest, which sources say occurred on or around September 16, 2026, has triggered a dramatic escalation in attacks by remaining ShinyHunters members, including the theft of highly <a href=\"https:\/\/overcentral.com\/en\/fortisandbox-data-exposure-flaw-80382\/\" title=\"FortiSandbox Flaw Brings Sensitive Data Exposure via HTTP Requests\" data-iacss-internal=\"1\">sensitive data<\/a> from the FBI and an extortion campaign against the Russian ransomware group Cl0p. The suspect, identified by three sources as Pepijn van der Stap, was previously convicted in 2023 for a string of cybercrimes that prosecutors said earned between \u20ac1.5 million and \u20ac2.7 million. Van der Stap had been released from prison in December 2025 and was working as an offensive security lead at a Dutch company when he was taken into custody again.<\/p>\n<p>Van der Stap\u2019s dual life as a cybersecurity professional and a hacker operating under the alias \u201cUmbreon\u201d has become a central theme in the investigation. At his 2023 trial, he admitted to living a Dr. Jekyll and Mr. Hyde existence: by day, he worked as a software engineer at Amsterdam-based cybersecurity startup Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research group; by night, he used the handle Umbreon to extort victims and post stolen data on hacking forums like the now-defunct RaidForums and Breached. He confessed to the activity and was sentenced to four years in prison, one of which was suspended. During his trial, he chose to remain in custody rather than at home, citing untreated PTSD from childhood trauma and a lack of adequate psychological care on the outside.<\/p>\n<p>The arrest appears to have triggered a chain reaction within the ShinyHunters collective. Just days after van der Stap was detained, the group claimed credit for a brazen breach of the FBI\u2019s job application site, apply.fbijobs.gov. According to reporting from 404 Media and Reuters, the stolen data includes Social Security numbers and personal information on more than 5,000 FBI officials, including job titles such as special agent, threat intake examiner, and members of the major cybercrimes unit. Reuters examined documents shared by ShinyHunters and found they included sensitive psychiatric and medical files <a href=\"https:\/\/overcentral.com\/en\/shinyhunters-fbi-data-breach-94942\/\" title=\"ShinyHunters Steals Data on Thousands of FBI Agents\" data-iacss-internal=\"1\">of FBI<\/a> staff. The FBI issued a brief statement confirming the hack. ShinyHunters said it gained access by exploiting a recently patched vulnerability in Oracle\u2019s PeopleSoft platform, designated CVE-2026-35273. The group reportedly began exploiting the vulnerability as a zero-day in June, and Oracle quickly issued a fix. Mandiant released web application firewall rules to mitigate the threat, but ShinyHunters later used a URL-encoding trick to bypass those rules, as reported by BleepingComputer. In a report released September 25, Mandiant and the <a href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Google<\/a> Threat Intelligence Group confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across higher education, technology, healthcare, agriculture, transportation, and government sectors.<\/p>\n<h2>Why Did ShinyHunters Escalate After the Arrest?<\/h2>\n<p>Multiple sources close to the investigation say the group\u2019s recent attacks against the FBI and Cl0p represent a major pivot from the more measured tenor of ShinyHunters\u2019 previous operations. The sudden shift came after ShinyHunters was taken over by a teenage cybercriminal from Amman, Jordan, who goes by the nickname \u201cRey.\u201d Rey operates as part of a cybercrime group called ScatteredLapsussHunters (SLSH), which experts describe as an amalgamation of three hacking groups: Scattered Spider, LAPSUS$, and ShinyHunters. Sources say Rey had an ongoing feud with van der Stap over control of the ShinyHunters brand and stolen data. The inclusion of an oversized ASCII art rendition of the Pokemon character Umbreon in the FBI jobs site defacement \u2014 the same defacement used in the group\u2019s 2020 hack of Hackforums \u2014 was likely an attempt by Rey to pin the FBI hack on the Dutchman.<\/p>\n<p>Rey was first publicly identified by the cybersecurity firm KELA in March 2025. In a November 2025 profile, KrebsOnSecurity contacted Rey\u2019s father, an employee of Royal Jordanian Airlines, to request an interview. Rey\u2019s father forwarded the message to his son, who admitted to participating in ransomware attacks and said he was trying to extricate himself from SLSH. After the FBI hack, Rey\u2019s now-deleted Twitter\/X account taunted both Cl0p and the FBI with a meme depicting the twin towers struck by planes labeled \u201ccl0p drama\u201d and \u201cfbi breach claim,\u201d with a giant Umbreon figure in the foreground. When KrebsOnSecurity again contacted Rey\u2019s father for comment on Rey\u2019s apparent ascendency as the head of ShinyHunters, the teenage hacker deleted his account hours later. His father has not responded to multiple emailed requests.<\/p>\n<h2>The Dutch Police Investigation and Public Appeal<\/h2>\n<p>Authorities in the Netherlands have been asking the public for help in identifying the voice in a recorded telephone call from February 2026. In that call, a native Dutch-speaking ShinyHunters member used social engineering to breach Odido, the nation\u2019s largest mobile telecommunications provider. The member tricked an Odido employee into logging in at a spoofed website, then used that access to steal data on more than 6.2 million Dutch people. Responding to Dutch news media, ShinyHunters confirmed that the suspect in the audio clip is a member of the collective. \u201cOur team member has our full support \u2013 emotionally, mentally, and financially,\u201d the hackers said in a statement shared with NL Times. \u201cEverything has been arranged, including a criminal defense lawyer.\u201d The group also lashed out at the Dutch police, calling them a \u201cbig joke\u201d and \u201cincompetent.\u201d It remains unclear if the police have matched the Odido caller to a confirmed real-life identity.<\/p>\n<p>Van der Stap\u2019s arrest was confirmed by Dutch police in a statement on Twitter\/X on September 28. The police said the man will appear on Tuesday, September 29 before the chambers of the Rotterdam District Court, and that more information will be provided the following day. Meanwhile, the Dutch news outlet RTL reported that investigators suspect van der Stap tried to orchestrate at least two murders, allegedly to be committed abroad, with indications that he gave the order for this. The FBI released a short video message from Brett Leatherman, assistant director of the FBI\u2019s cyber division, thanking Dutch law enforcement and urging remaining ShinyHunters members to turn themselves in. \u201cArrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who\u2019s left,\u201d Leatherman said. \u201cThe longer you stay in this, the more we learn about you.\u201d<\/p>\n<h2>Van der Stap\u2019s Background and the ShinyHunters Evolution<\/h2>\n<p>Van der Stap\u2019s criminal career predates his involvement with ShinyHunters. In an interview with Bloomberg in 2024, he said his motivation was never money but a desire to collect the world\u2019s most <a href=\"https:\/\/overcentral.com\/en\/control-resonant-complete-set-quest-guide-97361\/\" title=\"Control Resonant: Complete Set Quest Guide \u2013 All Speakers\" data-iacss-internal=\"1\">complete set<\/a> of stolen databases. \u201cThe hacking was very easy for me, and it wasn\u2019t a compulsion,\u201d he told Bloomberg. \u201cMy habit was collecting. Collecting data, organizing data, downloading data, creating folders.\u201d After his release from prison in December 2025, he presented himself as a reformed hacker. In a September 9, 2026 interview with KrebsOnSecurity, he described trying to turn his life around and make a positive contribution to society while working as offensive security lead at Neo Security in the Netherlands. But not long after that interview, he stopped replying to messages, and efforts by others close to him failed to elicit a response for two weeks \u2014 coinciding with his arrest.<\/p>\n<p>Van der Stap\u2019s former employer, the nonprofit security research group DIVD, disclosed on LinkedIn that it was dealing with an internal cybersecurity incident involving the malicious use of artificial intelligence. A spokesperson for DIVD told KrebsOnSecurity that the incident does not appear related to ShinyHunters nor to the work of a previous volunteer. Separately, according to a Wired story this month by Andy Greenberg, ShinyHunters and SLSH members briefly partnered earlier in 2026 to monetize stolen credentials collected by TeamPCP, an upstart group that had compromised global code supply chains but had not profited much. Mandiant had infiltrated TeamPCP and was secretly feeding their stolen credentials to cloud providers like Amazon and <a href=\"https:\/\/www.microsoft.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Microsoft<\/a>, causing the credentials to be invalidated. The formerly cooperating groups began blaming one another for the worthless credentials. ShinyHunters then went rogue, extorting victims with TeamPCP\u2019s credentials without giving the supply-chain hackers their cut. Mandiant researcher Austin Larsen told KrebsOnSecurity that ShinyHunters is on track to pull in nearly $100 million in extortion payments in 2026.<\/p>\n<h2>What Is the Significance of the FBI and Cl0p Attacks?<\/h2>\n<p>The FBI breach represents a major escalation in the group\u2019s audacity. The stolen data included not only personally identifiable information but also sensitive medical and psychiatric records of FBI staff. The attack exploited a zero-day vulnerability in Oracle PeopleSoft, which is widely used for hiring and HR management across many organizations. ShinyHunters reportedly used a URL-encoding trick to bypass Mandiant\u2019s recommended web application firewall rules, as detailed by BleepingComputer. The group also claimed credit for extorting the Cl0p ransomware group \u2014 one of Russia\u2019s most venerated cybercrime operations. This dual attack on U.S. federal law enforcement and a Russian ransomware gang underscores the group\u2019s willingness to take on high-risk targets, a departure from its earlier focus on corporate and consumer data theft.<\/p>\n<p>For users seeking to understand the current threat landscape, the ShinyHunters case illustrates the fluidity of hacking ecosystems, where individuals and groups merge, split, and target each other. The involvement of a teenage leader, Rey, and the conflict with van der Stap highlight the personal rivalries that can drive cybercriminal behavior. The Dutch police\u2019s public appeal and the arrest of a previously convicted cybercriminal signal a coordinated international effort to dismantle the group. However, the group\u2019s rapid retaliation \u2014 hacking the FBI and threatening more large-scale data thefts in the Netherlands \u2014 suggests that law enforcement actions can provoke immediate, significant consequences.<\/p>\n<p>The arrest of van der Stap and the resulting surge in attacks by ShinyHunters mark a turning point in the group\u2019s history. Whether the combined pressure from Dutch and U.S. authorities, along with internal strife, will lead to the group\u2019s dissolution or further radicalization remains to be seen. The FBI\u2019s warning that \u201carrests have a way of changing who is willing to talk\u201d may prompt defections among ShinyHunters members, but the group\u2019s demonstrated capacity for revenge attacks indicates that the fight is far from over. Organizations using Oracle PeopleSoft should ensure they have applied the latest patches and configured WAF rules correctly, as the vulnerability remains a vector for exploitation. The broader lesson is that cybercriminal networks, once destabilized, can become more dangerous before they collapse.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dutch authorities have arrested a 24-year-old convicted cybercriminal on suspicion of aiding the prolific hacking group ShinyHunters in a series of data thefts and extortions. The arrest, which sources say occurred on or around September 16, 2026, has triggered a dramatic escalation in attacks by remaining ShinyHunters members, including the theft of highly sensitive data [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":98860,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/98857.png","fifu_image_alt":"Netherlands Nabs Hacker as ShinyHunters Attacks FBI","footnotes":""},"categories":[40668],"tags":[],"class_list":["post-98857","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/98857.png","fifu_image_alt":"Netherlands Nabs Hacker as ShinyHunters Attacks FBI","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/98857","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=98857"}],"version-history":[{"count":2,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/98857\/revisions"}],"predecessor-version":[{"id":98859,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/98857\/revisions\/98859"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/98860"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=98857"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=98857"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=98857"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}