Cybersecurity and Privacy

Dutch Authorities Arrest Convicted Cybercriminal Pepijn van der Stap in Connection with Massive ShinyHunters Data Thefts and Extortions

Law enforcement authorities in the Netherlands have taken 24-year-old convicted cybercriminal Pepijn van der Stap into custody on suspicion of providing crucial technical and logistical support to the notorious, prolific threat group known as ShinyHunters. The arrest, executed mid-September, has sent shockwaves through the international cybersecurity landscape, triggering a high-stakes sequence of events that includes aggressive retaliatory cyberattacks against the Federal Bureau of Investigation (FBI), extortion targeting the Russian ransomware syndicate Cl0p, and new allegations involving international murder-for-hire plots.

The detention of van der Stap—who previously operated under the hacker alias “Umbreon”—marks a significant milestone for European law enforcement agencies working in coordination with international partners to dismantle modern data extortion rings. However, rather than neutralizing the threat, the arrest appears to have destabilized the internal hierarchy of ShinyHunters, accelerating a chaotic leadership transition and provoking a wave of unprecedented, high-profile retaliatory strikes against global law enforcement and critical infrastructure.

The Double Life of Pepijn van der Stap

According to multiple familiar sources, Dutch authorities detained van der Stap on or around September 16, 2026, following a thorough investigation into sophisticated cyber intrusions. A resident of Almere and Lelystad, van der Stap is no stranger to the justice system. In late 2023, he was convicted for his involvement in an extensive campaign of data thefts and corporate extortions that prosecutors estimated netted between €1.5 million and €2.7 million.

During his 2023 trial, van der Stap candidly admitted to maintaining a stark "Dr. Jekyll and Mr. Hyde" lifestyle. By night, he deployed his technical capabilities under the handle “Umbreon,” systematically extorting corporate victims and auctioning stolen databases on English-language cybercrime forums such as RaidForums and Breached. By day, he maintained a respectable professional profile, working as a software engineer for Hadrian, an Amsterdam-based cybersecurity startup, while simultaneously volunteering for the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit research group dedicated to identifying security flaws.

Despite confessing to his crimes, van der Stap was sentenced to four years in prison, with one year suspended. Citing ongoing psychological challenges, including post-traumatic stress disorder stemming from childhood trauma, he initially chose to remain in custody rather than serve his pre-trial detention at home. Following his eventual release in December 2025, van der Stap sought to cast himself as a reformed individual. In a September 9, 2026 interview, he maintained that he was attempting to rebuild his life, make positive contributions to society, and fulfill civil restitution obligations. At the time of his recent arrest, he was employed as an offensive security lead at Neo Security.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Chronology of the Escalation: From Odido to the FBI

The trajectory of the investigation accelerated significantly in early 2026. Dutch police launched a public appeal to identify a native Dutch speaker heard on a recorded telephone call from February 2026. During the call, a ShinyHunters operative used advanced social engineering techniques to compromise Odido, the Netherlands’ largest mobile telecommunications provider. By tricking an employee into authenticating through a spoofed web portal, the threat actors exfiltrated sensitive records belonging to more than 6.2 million Dutch citizens.

When local media covered the police appeal, ShinyHunters aggressively confirmed that the voice belonged to one of their core members. In a defiant public statement, the syndicate mocked Dutch law enforcement as incompetent and promised comprehensive emotional, mental, and financial support—including legal defense—for their detained operative.

Shortly after van der Stap’s arrest in September 2026, ShinyHunters executed a dramatic pivot in its operational strategy, launching a series of high-risk attacks that defied its traditional modus operandi. Most notably, the group claimed responsibility for a brazen breach of the FBI’s job application portal, apply.fbijobs.gov.

According to reports from digital security publications and mainstream media outlets, the breach compromised personally identifiable information (PII) belonging to more than 5,000 individuals. The stolen records included Social Security numbers, job titles, and operational unit assignments—such as special agents, threat intake examiners, and personnel assigned to major cybercrime and foreign state-backed threat units. Furthermore, analysis of the leaked documents by independent investigators revealed sensitive psychological and medical files concerning FBI personnel.

Exploitation of Oracle PeopleSoft and the WAF Bypass

The breach of the FBI portal and dozens of other corporate systems across sectors like healthcare, technology, agriculture, transportation, and higher education was facilitated by the mass exploitation of a security vulnerability (CVE-2026-35273) affecting Oracle PeopleSoft, a widely used human resources and payroll platform.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Although Oracle rapidly issued patches after discovering the flaw was being actively exploited as a zero-day in June, and security firms like Mandiant subsequently released web application firewall (WAF) mitigation rules, ShinyHunters adapted quickly. Security researchers from Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that the threat group deployed URL-encoding evasion techniques to bypass the WAF rules, enabling continued mass extraction of corporate data.

Throughout the FBI portal defacement, the group left a distinct calling card: an ASCII art rendering of the Pokémon character Umbreon, accompanied by the text, "This site has been seized by ShinyHunters. rooting your systems since ’19 ;)." This overt reference to van der Stap’s historic online moniker suggested a deliberate attempt by remaining faction leaders to frame the Dutch national for the attack.

Internal Power Struggles and the Rise of "Rey"

Intelligence sources tracking the cybercrime underground indicate that the recent escalation stems from a fundamental shift in leadership. Control of the ShinyHunters brand reportedly transitioned to a teenage cybercriminal from Amman, Jordan, known by the handle “Rey.” Rey operates as a core figure within ScatteredLapsussHunters (SLSH), a hybrid syndicate formed from the remnants of Scattered Spider, LAPSUS$, and ShinyHunters.

Investigators suggest that Rey harbored significant friction with van der Stap over control of operational assets and the ShinyHunters brand. The inclusion of the oversized Umbreon imagery in the FBI portal defacement was allegedly a calculated move by Rey to direct law enforcement scrutiny toward the imprisoned Dutch hacker.

Rey’s aggressive posture extended beyond domestic law enforcement and the FBI; the syndicate also claimed to have extorted Cl0p, a prominent Russian-speaking ransomware gang, signaling an unprecedented willingness to target even peer criminal enterprises. However, international law enforcement pressure is closing in. Following the deletion of Rey’s primary social media accounts and ongoing inquiries directed at his family, the operational stability of the group is facing severe strain.

Official Responses and Broader Implications

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

The arrest of van der Stap and the subsequent dismantling of infrastructure have drawn high-level responses from international security agencies. Brett Leatherman, Assistant Director of the FBI’s Cyber Division, released a video statement commending Dutch law enforcement for their decisive action and issuing a direct warning to remaining ShinyHunters members.

"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left," Leatherman stated. "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out to us while the choice is still yours."

As the legal proceedings unfold, Dutch prosecutors have introduced even more alarming allegations into the case. Reports from Dutch news outlet RTL indicate that investigators are examining whether van der Stap attempted to orchestrate at least two contract murders to be carried out abroad. Meanwhile, van der Stap is scheduled to appear before the Rotterdam District Court to face formal charges, while local authorities continue to investigate the full extent of the syndicate’s domestic and international crimes.

The developments highlight a critical turning point in the global fight against organized cybercrime, demonstrating that while international cooperation can successfully apprehend high-value targets, it often triggers chaotic, retaliatory spasms from decentralized threat groups operating across jurisdictional boundaries.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Device Kick
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.