Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in massive data thefts and extortion schemes orchestrated by the prolific and aggressive hacker collective known as ShinyHunters. The high-stakes arrest has triggered immediate and volatile repercussions across the global cybersecurity landscape. In the days following the suspect’s detention, remaining members of the ShinyHunters group dramatically escalated their international operations, carrying out an unprecedented, brazen cyberattack against the Federal Bureau of Investigation (FBI) and directly targeting the Russian ransomware syndicate Cl0p.
According to three sources familiar with the matter, the Dutch man taken into custody by law enforcement this month is Pepijn van der Stap, a convicted cybercriminal originally hailing from Almere and Lelystad in the Netherlands. Van der Stap was previously convicted in 2023 for his involvement in an extensive string of high-profile data thefts and corporate extortions. According to Dutch prosecutors, those illicit activities successfully netted between €1.5 million and €2.7 million.
During his late-2023 criminal trial, van der Stap openly admitted to living a dual existence akin to Dr. Jekyll and Mr. Hyde. Secretly operating under the hacker handle “Umbreon,” he extorted corporate victims and leaked their sensitive data across prominent English-language cybercrime and hacking forums, including the now-defunct RaidForums and Breached. By day, however, van der Stap maintained a completely respectable facade as a software engineer working for Hadrian, an Amsterdam-based cybersecurity startup. He also dedicated his time as a volunteer for the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organization focused on security research and vulnerability mitigation.
Van der Stap confessed fully to his data theft and extortion enterprises during his judicial proceedings, ultimately receiving a four-year prison sentence, of which one year was suspended. During the trial, van der Stap made the unusual choice to remain in custody rather than await proceedings at home, stating that he could not find comparable medical and psychological treatment on the outside for his ongoing mental health struggles, which included post-traumatic stress disorder stemming from childhood trauma. He was subsequently released from prison in December 2025.
In an interview with KrebsOnSecurity on September 9, 2026, van der Stap attempted to rebrand himself as a thoroughly reformed individual striving to turn his life around and make constructive contributions to society. At the time of the interview, he was employed as an offensive security lead at Neo Security, a Dutch security firm that has thus far declined to respond to media requests for comment.
During that conversation, van der Stap noted that he was still actively navigating complicated civil lawsuits and mandatory restitution tied to his past cybercrime offenses, emphasizing that he was doing his utmost to make proper amends. However, shortly after that interview concluded, van der Stap abruptly stopped responding to electronic messages. Efforts by associates and individuals close to him to establish contact repeatedly failed over the following two weeks.
According to two sources with direct knowledge of the investigation, Dutch law enforcement officers arrested van der Stap on or around September 16. He has since been held in custody for intensive questioning. One source reported that a colleague personally witnessed Dutch authorities hauling physical items and equipment out of van der Stap’s residence during the raid.
For months, Dutch authorities have been actively appealing to the public for assistance in identifying the voice featured in a recorded telephone call from February 2026. In that audio recording, a native Dutch-speaking member of ShinyHunters successfully utilized social engineering techniques to breach Odido, the largest mobile telecommunications provider in the Netherlands. During that intrusion, the hackers tricked an Odido employee into logging into a spoofed, malicious website, subsequently leveraging that compromised access to steal sensitive data belonging to more than 6.2 million Dutch citizens.

In statements provided to local Dutch news media, ShinyHunters explicitly confirmed that the individual heard in the released audio clip is indeed an active member of their hacker collective.
“Our team member has our full support – emotionally, mentally, and financially,” the hackers stated in a message shared with the NL Times. “Everything has been arranged, including a criminal defense lawyer. We do not look down on our staff and members; we take excellent care of them.” At the time, it remained unclear whether the Dutch police had successfully matched the Odido caller to a confirmed, real-world identity. The specific Dutch police unit managing the Odido investigation declined to comment on the matter.
The cybercrime collective also launched a furious verbal assault against Dutch law enforcement agencies. “The Dutch police will need all the luck in the world – and everyone’s prayers – if they want to catch him before we carry out another large-scale data theft in the Netherlands,” the ShinyHunters statement declared. “Frankly, the Dutch police are a big joke; they are incapable of doing anything. Incompetent. Irrelevant. Unimportant. Useless.”
FBI, CL0P HACKS
Just days after sources confirmed van der Stap had been detained by Dutch authorities, ShinyHunters shocked the cybersecurity community by claiming responsibility for an extraordinarily brazen breach targeting the FBI’s official job application portal, apply.fbijobs.gov. According to reporting from 404 Media, the data stolen from the federal recruitment site included Social Security numbers and deeply sensitive personal information belonging to more than 5,000 bureau officials and applicants.
Both 404 Media and Reuters reported that the compromised FBI data included specific job titles and internal team designations, identifying individuals working as special agents, threat intake examiners, and members of the major cybercrimes unit, including personnel tasked with investigating foreign state-sponsored cyber threats. Furthermore, Reuters examined document samples shared directly by the hackers, confirming that they included highly confidential psychiatric and medical files pertaining to FBI personnel. The bureau subsequently issued a brief public statement acknowledging the compromise of the portal.
ShinyHunters asserted that they gained initial access to the FBI portal and other victim systems by aggressively exploiting a recently patched vulnerability, tracked as CVE-2026-35273, affecting PeopleSoft. This software-as-a-service platform, developed by tech giant Oracle, is widely utilized by major enterprises, educational institutions, and government agencies to manage corporate hiring, human resources, employee benefits, and payroll infrastructure. Oracle moved quickly to issue a security fix after discovering that ShinyHunters had begun weaponizing the PeopleSoft flaw as a zero-day exploit in June. Concurrently, Mandiant released targeted web application firewall rules for organizations unable to immediately apply the official software patch.
However, security reporting from BleepingComputer revealed that ShinyHunters managed to circumvent Mandiant’s mitigation measures by employing a clever URL-encoding trick to bypass the suggested web application firewall rules. In a joint threat intelligence report released on September 25, security experts at Mandiant and the Google Threat Intelligence Group confirmed that ShinyHunters had conducted a massive, sweeping exploitation campaign targeting the PeopleSoft vulnerability across dozens of corporate networks spanning higher education, technology, healthcare, agriculture, transportation, and government sectors.
Significantly, van der Stap’s former hacker moniker, Umbreon, was hidden in plain sight within the digital artifacts left behind by the hackers. The defacement image posted by ShinyHunters on the compromised FBI recruitment portal featured prominent ASCII art depicting the Pokémon character Umbreon. A message emblazoned across the top of the graphic read, “This site has been seized by ShinyHunters. rooting your systems since ’19 ;)” This visual asset appeared identical to a defacement banner previously utilized by the group during their 2020 compromise of the English-language cybercrime forum Hackforums.

According to multiple sources close to the international investigation into ShinyHunters, the group’s recent high-risk attacks against the FBI and a major Russian ransomware syndicate marked a sharp departure from the more calculated, methodical approach that previously defined their operations. Investigators indicate this sudden strategic shift followed an internal leadership takeover led by a teenage cybercriminal based in Amman, Jordan. Known by the online alias Rey, this individual operates within a cybercrime coalition called ScatteredLapsussHunters, which security analysts describe as an amalgamation of three notorious hacker groups: Scattered Spider, LAPSUS$, and ShinyHunters.
Sources familiar with the underground landscape reported that Rey maintained a persistent personal feud with the Dutch hacker regarding control over the ShinyHunters brand and its proprietary data repositories. Consequently, the inclusion of the oversized Umbreon Pokémon graphic in the FBI job site defacement was likely an intentional maneuver by Rey to publicly frame the imprisoned Dutchman for the high-profile federal breach.
Rey was first publicly identified by the cybersecurity firm KELA in March 2025. Prior to a detailed profile published by KrebsOnSecurity in November 2025, journalists contacted Rey’s father to request an interview with his teenage son. The father merely forwarded the inquiry to Rey, who ultimately admitted to participating in various ransomware operations while expressing a desire to distance himself from the scattered hacker collective.
BLAMING UMBREON
Immediately following widespread media coverage of the FBI job site compromise, Rey’s primary social media account on X (formerly Twitter) began taunting both the Cl0p ransomware syndicate and federal law enforcement. One shared meme crudely depicted the Twin Towers in New York City being struck by aircraft labeled “cl0p drama” and “fbi breach claim,” with a giant floating Pokémon figure of Umbreon looming in the foreground.
On September 24, KrebsOnSecurity again reached out to Rey’s father to request an interview concerning his son’s reported ascent to leadership within ShinyHunters. Just hours after that communication, Rey deleted his long-standing social media account. Meanwhile, Rey’s father, an employee of Royal Jordanian Airlines, failed to respond to subsequent email inquiries regarding his son’s alleged cybercriminal activities.
The underlying animosity between the newer coalition and older factions stems from complex underground alliances. According to a report published by Wired, members of ShinyHunters and the coalition briefly partnered earlier in the year to better monetize valuable stolen credentials collected by TeamPCP. TeamPCP was an upstart hacking faction that achieved significant success compromising global software supply chains with malicious code, though its members struggled to effectively profit from their harvested data. (Two alleged leaders of TeamPCP were arrested in Australia, with one claiming they earned a mere $20,000 from their exploits.)
As Wired detailed, Mandiant analysts had secretly infiltrated TeamPCP and were actively responsible for burning the group’s stolen credentials by quietly feeding them to major cloud infrastructure providers like Amazon and Microsoft, which promptly invalidated the keys. As the stolen access credentials rapidly became worthless, the allied cybercrime factions began aggressively blaming one another for the operational failures.
Wired reporter Andy Greenberg noted that weeks after partnering with TeamPCP, ShinyHunters went rogue, executing independent extortion schemes using the shared supply-chain credentials while refusing to distribute financial cuts to their partners. Austin Larsen, a researcher with Mandiant, noted that ShinyHunters has enjoyed a highly lucrative extortion spree throughout the year, putting the collective on track to amass nearly $100 million in illicit payments from corporate victims.

In contrast to financially driven syndicates, van der Stap previously insisted that money was never his primary motivator. Instead, he claimed his early hacking endeavors were fueled by an obsessive compulsion to amass the world’s most comprehensive collection of stolen databases. Speaking with Bloomberg reporters in 2024, van der Stap described how his singular focus drove his malicious activities.
“The hacking was very easy for me, and it wasn’t a compulsion,” he told Bloomberg. “My habit was collecting. Collecting data, organizing data, downloading data, creating folders.”
Meanwhile, the DIVD, the nonprofit security research organization where van der Stap once volunteered, disclosed that it experienced an internal cybersecurity incident involving the potential malicious use of artificial intelligence. While the nonprofit released few specifics regarding the event, a DIVD spokesperson confirmed that the incident bore no relation to ShinyHunters and showed no indication of involving the past actions of any former volunteers.
Dutch police officially confirmed the arrest of a 24-year-old suspect in connection with the ongoing ShinyHunters investigation. In a public statement posted to social media, law enforcement announced that the suspect would appear before the Rotterdam District Court, promising further updates as the judicial process unfolds.
Adding to the gravity of the ongoing international probe, Dutch news outlet RTL reported that investigators harbor suspicions that van der Stap attempted to orchestrate at least two murders. According to RTL, investigators found indications that the suspect allegedly issued orders for these targeted killings to be carried out abroad.
Concurrently, the FBI released a video message addressing the ShinyHunters investigation featuring Brett Leatherman, assistant director of the FBI’s cyber division. Leatherman thanked Dutch law enforcement partners for their critical assistance and urged remaining members of the hacker collective to surrender voluntarily.
“Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left,” Leatherman stated. “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out to us while the choice is still yours.”
Leave a Reply