Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions carried out by the prolific and aggressive hacker collective known as ShinyHunters. The detention, which took place in mid-September, immediately triggered a dramatic and volatile escalation from the group’s remaining members. Within days of the suspect being taken into custody, ShinyHunters launched high-profile attacks, stealing highly sensitive personnel data from the Federal Bureau of Investigation (FBI) and moving to extort the notorious Russian ransomware syndicate Cl0p.
According to three sources familiar with the matter, the Dutch man taken into custody by law enforcement this month is Pepijn van der Stap, a convicted cybercriminal originally from Almere and Lelystad in the Netherlands. Van der Stap previously faced prosecution and was convicted in late 2023 for his involvement in a sweeping series of data thefts and corporate extortions. Dutch prosecutors estimated at the time that those illicit operations generated between €1.5 million and €2.7 million in illicit proceeds.
During his 2023 trial, van der Stap admitted to living a double life, maintaining a Dr. Jekyll and Mr. Hyde existence. Secretly operating under the hacker handle "Umbreon"—named after the fictional Pokémon character—he extorted corporate victims and published stolen databases on English-language underground cybercrime forums, including the now-defunct platforms RaidForums and Breached. By day, however, van der Stap maintained a conventional professional profile, working as a software engineer at Hadrian, an Amsterdam-based cybersecurity startup, while simultaneously volunteering for the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organization dedicated to security research.
Van der Stap confessed to his extensive data theft and extortion activities during legal proceedings and was subsequently sentenced to four years in prison, with one year suspended. In a somewhat unusual move during his trial, van der Stap chose to remain incarcerated rather than return home, stating that he could not find adequate medical and psychological treatment on the outside for his ongoing mental health struggles, which he asserted included post-traumatic stress disorder stemming from childhood trauma. He was eventually released from custody in December 2025.
In an interview with KrebsOnSecurity on September 9, 2026, van der Stap portrayed himself as a fully reformed individual trying to turn his life around and make constructive contributions to society. At the time of the interview, he was employed as an offensive security lead at Neo Security, a Dutch cybersecurity firm that ultimately did not respond to requests for comment regarding the arrest.
During the discussion, van der Stap noted that he was still navigating complex civil lawsuits and restitution agreements tied to his past cybercrimes, emphasizing that he was doing his utmost to make amends. However, shortly after that interview concluded, van der Stap abruptly stopped responding to messages. Individuals close to him confirmed that all attempts to reach him failed over the subsequent two weeks.
According to two sources with direct knowledge of the situation, Dutch authorities arrested van der Stap on or around September 16, subsequently holding him in secure custody for intensive questioning. One source reported that a colleague personally witnessed law enforcement officers carrying items and electronic equipment out of van der Stap’s residence during the raid.

The Dutch police had previously launched public appeals for assistance in identifying a native Dutch-speaking member of ShinyHunters whose voice appeared in a recorded telephone call from February 2026. In that call, the suspect successfully social-engineered their way into Odido, the largest mobile telecommunications provider in the Netherlands. By tricking an Odido employee into authenticating through a spoofed, malicious website, the hackers gained unauthorized access and stole sensitive data belonging to more than 6.2 million Dutch citizens.
Responding to inquiries from Dutch media outlets, ShinyHunters openly acknowledged that the individual heard in the police audio clip was indeed a core member of their collective. In a statement shared with the NL Times, the group promised unwavering support to their detained associate. "Our team member has our full support—emotionally, mentally, and financially," the hackers stated, adding that a criminal defense lawyer had already been retained on his behalf.
The collective also issued scathing remarks directed at Dutch law enforcement. "The Dutch police will need all the luck in the world—and everyone’s prayers—if they want to catch him before we carry out another large-scale data theft in the Netherlands," the statement read. "Frankly, the Dutch police are a big joke; they are incapable of doing anything. Incompetent. Irrelevant. Unimportant. Useless."
Following the arrest, the Dutch police officially confirmed that a 24-year-old man had been taken into custody in connection with the ongoing ShinyHunters investigation. Authorities announced that the suspect would appear before the chambers of the Rotterdam District Court. Furthermore, investigative reporting from the Dutch news outlet RTL revealed that investigators are examining suspicions that van der Stap may have attempted to orchestrate at least two murders abroad, with indications suggesting he issued orders for the planned killings.
FBI, CL0P HACKS
Just days after sources indicated van der Stap was detained by Dutch law enforcement, ShinyHunters claimed responsibility for an extraordinarily brazen cyberattack targeting the FBI’s job application portal, apply.fbijobs.gov. According to investigative reports from 404 Media and Reuters, the data compromised during the breach included Social Security numbers and detailed personal information concerning more than 5,000 personnel.
The stolen records reportedly detailed specific job titles and operational units, including special agents, threat intake examiners, members of major cybercrimes units, and personnel tasked with investigating foreign state-backed cyber threats. Furthermore, Reuters reviewed documents shared by the hackers that contained highly sensitive medical and psychiatric files belonging to FBI employees. The bureau subsequently issued a brief public statement confirming the compromise of the recruitment portal.
ShinyHunters stated that they breached the FBI’s portal and systems belonging to other organizations by exploiting a recently patched zero-day vulnerability, tracked as CVE-2026-35273, affecting PeopleSoft—a widely used enterprise software-as-a-service platform managed by Oracle for human resources, recruitment, payroll, and benefits administration. Oracle swiftly released a security update to address the flaw after ShinyHunters began weaponizing it in June. Simultaneously, security firm Mandiant issued web application firewall (WAF) rules to protect organizations unable to immediately apply the patch.

However, security researchers reported that ShinyHunters managed to circumvent Mandiant’s defensive mitigations by utilizing a clever URL-encoding trick. In a joint threat intelligence report released on September 25, analysts from Mandiant and the Google Threat Intelligence Group confirmed that ShinyHunters carried out a mass-exploitation campaign targeting the PeopleSoft vulnerability, successfully compromising dozens of systems across critical sectors, including higher education, technology, healthcare, agriculture, transportation, and government.
Intriguingly, van der Stap’s former hacker alias, Umbreon, was prominently displayed within the visual assets deployed by ShinyHunters to publicize the FBI breach. The digital defacement message left behind on the compromised FBI portal featured an ASCII art depiction of the Pokémon character Umbreon alongside text declaring that the site had been seized by the collective. This imagery closely mirrored defacement art used by ShinyHunters during their 2020 breach of the English-language cybercrime forum Hackforums.
Sources close to the ongoing investigation noted that the group’s reckless escalation against high-value targets like the FBI and a prominent Russian ransomware syndicate marked a sharp departure from their traditional operational style. This strategic pivot reportedly followed a leadership shift within ShinyHunters, which fell under the control of a teenage cybercriminal based in Amman, Jordan. Operating under the pseudonym "Rey," this individual is a prominent figure within an amalgamated cybercrime entity known as ScatteredLapsussHunters (SLSH), which security researchers describe as a coalition blending elements of Scattered Spider, LAPSUS$, and ShinyHunters.
Investigators suggested that Rey harbored a persistent rivalry with van der Stap regarding control over the ShinyHunters brand and accumulated data assets. Consequently, the prominent inclusion of the Umbreon imagery in the FBI portal defacement was interpreted as a deliberate effort by Rey to frame the imprisoned Dutch hacker for the attack.
Rey was first publicly unmasked by cybersecurity firm KELA in March 2025. When approached by journalists prior to a published profile, Rey’s father merely forwarded inquiries to his son, who subsequently admitted to participating in ransomware activities while expressing a desire to distance himself from the SLSH collective. Following intense media scrutiny surrounding the FBI breach, Rey deleted his primary social media accounts on X, while his father—an employee of Royal Jordanian Airlines—did not respond to subsequent requests for comment regarding his son’s alleged illicit activities.
The underlying friction between SLSH and ShinyHunters stems from previous opportunistic partnerships. Earlier in the year, members of both groups briefly collaborated to better monetize stolen credentials harvested by TeamPCP, an emerging cybercrime faction that successfully compromised global code supply chains but struggled to convert stolen access into substantial financial profits. Two alleged leaders of TeamPCP were arrested in Australia, with initial estimates indicating the group had generated only modest returns from their breaches.
Investigative reporting revealed that Mandiant had covertly infiltrated TeamPCP’s infrastructure and proactively neutralized stolen credentials by feeding them directly to major cloud service providers like Amazon and Microsoft, which promptly invalidated the compromised API keys and login sessions. As the operations collapsed, the cooperating cybercrime factions began trading blame for the rapid exposure of their stolen assets. Shortly thereafter, ShinyHunters allegedly went rogue, utilizing the contested credentials to execute independent extortion schemes without sharing proceeds with their supply-chain partners.

Despite these internal frictions, security analysts note that ShinyHunters has maintained a lucrative extortion spree throughout the year, remaining on track to amass nearly $100 million in extortion payments from corporate victims by the close of 2026.
Van der Stap consistently maintained that his own cybercriminal endeavors were never driven primarily by financial gain. Instead, during interviews following his 2023 conviction, he described his compulsion as an obsessive desire to curate the world’s most comprehensive repository of stolen databases. Explaining his motivations to reporters, he noted that the technical execution of hacking felt effortless, functioning less as a malicious compulsion and more as an unchecked drive for collecting, organizing, and cataloging stolen data.
Meanwhile, the Dutch Institute for Vulnerability Disclosure (DIVD), where van der Stap previously volunteered, reported an internal security incident involving the suspected malicious use of artificial intelligence. While the nonprofit released limited details regarding the event, representatives confirmed that the occurrence bore no connection to ShinyHunters and showed no indication of involvement by any former volunteers.
Law enforcement agencies continue to pressure the remaining members of the collective. In a video address released by the FBI’s Cyber Division, Assistant Director Brett Leatherman commended Dutch law enforcement partners for their crucial assistance in the ongoing investigation and directly addressed the remaining members of ShinyHunters.
"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left," Leatherman warned. "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out to us while the choice is still yours."
Leave a Reply