Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and high-stakes extortions orchestrated by the prolific hacker collective known as ShinyHunters. The arrest, which took place in mid-September, sent immediate shockwaves through the underground cybercrime ecosystem. In the days immediately following the suspect’s detention, remaining members of ShinyHunters dramatically escalated their global operations, carrying out an unprecedented breach that compromised sensitive data belonging to the Federal Bureau of Investigation (FBI) and brazenly extorting the notorious Russian ransomware syndicate Cl0p.
According to three sources familiar with the ongoing international investigation, the Dutch man taken into custody by local law enforcement is Pepijn van der Stap, a convicted cybercriminal who splits his time between Almere and Lelystad in the Netherlands. Van der Stap previously drew international attention during a 2023 criminal trial connected to a massive string of data thefts and digital extortions. Dutch prosecutors at the time estimated that his illicit operations had generated between €1.5 million and €2.7 million in illegal proceeds.
During his late 2023 trial, van der Stap candidly admitted to living a modern-day Dr. Jekyll and Mr. Hyde existence. By night, he secretly operated under the hacker handle "Umbreon," using the alias to extort corporate victims and dump stolen company databases onto English-language cybercrime forums, including the now-defunct RaidForums and Breached. By day, however, van der Stap maintained a respectable professional facade as a software engineer working for Hadrian, an Amsterdam-based cybersecurity startup. He even volunteered his technical skills at the Dutch Institute for Vulnerability Disclosure (DIVD), a well-known nonprofit security research organization dedicated to finding and patching software flaws.
Van der Stap fully confessed to his extensive data theft and extortion activities during the proceedings, ultimately receiving a four-year prison sentence, with one year suspended. Bizarrely, during his legal proceedings, van der Stap chose to remain in custody rather than return home under house arrest, telling the court that he could not find adequate medical or psychological treatment on the outside for his ongoing mental health struggles. He claimed these issues included post-traumatic stress disorder stemming from childhood trauma. He was subsequently released from prison in December 2025.
In an interview with KrebsOnSecurity on September 9, 2026, van der Stap cast himself as a thoroughly reformed individual striving to turn his life around and contribute positively to society. At the time of the interview, he was employed as an offensive security lead at Neo Security, a Dutch cybersecurity firm that has since declined to respond to media requests for comment regarding his arrest.
During the interview, van der Stap noted that he was still navigating complex civil lawsuits and restitution payments related to his past cybercrime offenses, insisting he was doing everything in his power to make amends. However, shortly after that conversation, the Dutch hacker abruptly ceased responding to messages. Efforts by acquaintances and colleagues to reach him over a two-week period also went entirely unanswered.
According to two sources with direct knowledge of the situation, Dutch authorities arrested van der Stap on or around September 16, holding him in custody for intensive questioning. One source reported that a colleague personally witnessed law enforcement officers carting various items and electronic equipment out of van der Stap’s residence.

Law enforcement in the Netherlands had already been intensifying pressure on the cybercrime ring. Earlier in September, Dutch police made a public appeal for help identifying the voice in a recorded telephone call from February 2026. In that call, a native Dutch-speaking ShinyHunters member used sophisticated social engineering techniques to trick an employee of Odido, the nation’s largest mobile telecommunications provider, into logging into a spoofed website. The intruders subsequently used that compromised access to steal sensitive personal data belonging to more than 6.2 million Dutch citizens.
Responding directly to Dutch news media reports, ShinyHunters publicly confirmed that the individual heard in the audio clip was indeed an active member of their hacking collective.
"Our team member has our full support – emotionally, mentally, and financially," the hackers declared in a statement shared with the NL Times. "Everything has been arranged, including a criminal defense lawyer. We do not look down on our staff and members; we take excellent care of them."
It remains unclear whether Dutch police have successfully matched the voice from the Odido intrusion to a confirmed real-world identity. The specialized police unit handling the Odido investigation declined to comment on the ongoing probe. Meanwhile, ShinyHunters lashed out aggressively at Dutch law enforcement in their statement, mocking their investigative capabilities.
"The Dutch police will need all the luck in the world – and everyone’s prayers – if they want to catch him before we carry out another large-scale data theft in the Netherlands," the statement read. "Frankly, the Dutch police are a big joke; they are incapable of doing anything. Incompetent. Irrelevant. Unimportant. Useless."
FBI and CL0P Hacks
Just days after sources confirmed van der Stap was detained by Dutch authorities, ShinyHunters claimed responsibility for a remarkably brazen and high-profile breach targeting the FBI’s official job application portal, apply.fbijobs.gov. According to reporting from 404 Media, the stolen data extracted from the federal recruitment site included Social Security numbers and deeply personal background information concerning more than 5,000 federal officials and applicants.
Reporting from both 404 Media and Reuters revealed that the compromised FBI records contained specific job titles and operational team assignments. These included sensitive positions such as special agents, threat intake examiners, personnel within major cybercrimes units, and staff actively investigating foreign state-backed cyber threats. Furthermore, Reuters examined documents shared directly by the hackers and confirmed they included confidential psychiatric and medical files belonging to FBI personnel. The bureau subsequently issued a brief public statement confirming the compromise of the portal.
ShinyHunters asserted that they gained initial access to the FBI application site and numerous other corporate victims by exploiting a recently patched vulnerability, tracked as CVE-2026-35273, affecting PeopleSoft. PeopleSoft is a widely used software-as-a-service platform developed by enterprise technology giant Oracle, utilized extensively across global organizations for human resources, recruitment, payroll, and benefits management. Oracle moved quickly to issue a software patch after discovering that ShinyHunters had been weaponizing the flaw as a zero-day exploit since June. At the time, Mandiant released targeted web application firewall (WAF) rules to assist organizations unable to immediately apply the security update.

However, security researchers at BleepingComputer reported that ShinyHunters managed to bypass Mandiant’s mitigation rules by employing a clever URL-encoding trick. In a comprehensive threat report released on September 25, security experts at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that the hacker group had engaged in a widespread, mass-exploitation campaign targeting the PeopleSoft vulnerability. The attacks compromised dozens of systems across diverse industry sectors, including higher education, technology, healthcare, agriculture, transportation, and government agencies.
Intriguingly, van der Stap’s former hacker alias, Umbreon, was hidden in plain sight within the digital imagery used by ShinyHunters to publicize the FBI breach. The defacement message left behind by the hackers on the compromised FBI jobs portal featured an ASCII art design depicting the Pokémon character Umbreon. A banner at the top read, "This site has been seized by ShinyHunters. rooting your systems since ’19 ;)." Security analysts noted that this graphic was virtually identical to a defacement banner deployed by ShinyHunters during their 2020 breach of Hackforums, an English-language cybercrime community.
Sources close to the international investigation into ShinyHunters suggested that the group’s recent high-risk attacks against U.S. federal law enforcement and a prominent Russian ransomware syndicate marked a sharp departure from the gang’s traditionally more calculated operational tenor. Investigators indicated that this sudden tactical shift followed a leadership change within the collective, resulting from a takeover by a teenage cybercriminal from Amman, Jordan. Operating under the alias "Rey," this individual is a key figure in a loose federation known as ScatteredLapsussHunters (SLSH), which security researchers describe as an amalgamation of three notorious hacking factions: Scattered Spider, LAPSUS$, and ShinyHunters.
According to these sources, Rey had harbored an ongoing dispute with the Dutch hacker regarding control over the ShinyHunters brand and its vast repositories of stolen data. The prominent inclusion of the Umbreon Pokémon imagery in the FBI site defacement was widely viewed as a deliberate attempt by Rey to frame the incarcerated Dutchman for the attack.
Rey was first unmasked publicly by cybersecurity firm KELA in March 2025. Ahead of a detailed profile published by KrebsOnSecurity in November 2025, reporters contacted Rey’s father to request an interview with the teenager. The father forwarded the inquiry directly to his son, who subsequently admitted to participating in various ransomware operations while expressing a desire to distance himself from the SLSH network.
Blaming Umbreon
Immediately following widespread media coverage of the FBI jobs portal breach, Rey’s primary social media account on X (formerly Twitter), operated under the handle @rmoskovy, began taunting both the Cl0p ransomware organization and the FBI. One shared meme crudely depicted the Twin Towers in New York City being struck by aircraft labeled "cl0p drama" and "fbi breach claim," with a giant, float-sized rendering of the Pokémon character Umbreon towering over the foreground.
On September 24, KrebsOnSecurity reached out to Rey’s father once again to request an interview regarding his son’s apparent ascent to leadership within ShinyHunters. Just hours after that inquiry was sent, Rey’s long-standing X account was permanently deleted. Meanwhile, Rey’s father, an employee of Royal Jordanian Airlines, failed to respond to multiple emailed requests for comment concerning his son’s alleged digital activities.
The underlying animosity between SLSH and traditional ShinyHunters factions stems from shifting alliances earlier in the year. According to an investigative report published by Wired, members of ShinyHunters and SLSH briefly partnered to better monetize valuable corporate credentials harvested by TeamPCP. TeamPCP was an upstart hacking cell that had achieved notable success compromising global code supply chains with malicious software, though its members struggled to extract substantial financial profits from their loot. Two alleged leaders of TeamPCP were subsequently arrested in Australia, with one claiming during interrogations that the group had netted a mere $20,000 from their efforts.

The Wired report detailed how Mandiant had covertly infiltrated TeamPCP and was secretly responsible for burning the group’s stolen credentials by leaking the active keys to major cloud infrastructure providers like Amazon and Microsoft. The cloud giants swiftly invalidated the compromised keys, turning the stolen data into digital worthless assets. In the aftermath, the newly partnered hacker factions began pointing fingers and blaming one another for the rapid neutralization of their access.
Wired reporter Andy Greenberg noted that shortly after forming the short-lived partnership with TeamPCP, ShinyHunters went rogue, executing independent extortion schemes using the shared supply-chain credentials without cutting in their partners.
Austin Larsen, a security researcher at Mandiant, noted that ShinyHunters has enjoyed a highly lucrative extortion spree throughout the year, placing the syndicate on track to pull in nearly $100 million in extortion payments from corporate victims by the end of 2026.
Despite the massive financial motives driving modern cybercrime gangs, van der Stap previously insisted that money was never his primary driver. In interviews following his 2024 legal proceedings, he told journalists from Bloomberg that his early criminal activity was fueled primarily by an obsessive desire to curate the world’s most comprehensive collection of stolen corporate databases.
"The hacking was very easy for me, and it wasn’t a compulsion," van der Stap told Bloomberg. "My habit was collecting. Collecting data, organizing data, downloading data, creating folders."
Meanwhile, the Dutch Institute for Vulnerability Disclosure (DIVD), where van der Stap previously volunteered, disclosed on social media that the nonprofit organization was managing an internal cybersecurity incident involving the suspected malicious use of artificial intelligence. While DIVD has released limited details regarding the breach, a spokesperson confirmed to KrebsOnSecurity that the incident does not appear connected to ShinyHunters, nor are there any indications that the matter involves the past actions of their former volunteer.
On Tuesday afternoon, the Dutch police officially confirmed the arrest of a 24-year-old suspect in connection with the ongoing ShinyHunters investigation. In a public statement shared on social media, law enforcement announced that the detained man would appear before the chambers of the Rotterdam District Court.
Leave a Reply