Skip to content
CYBERSECURITY & DATA PRIVACY

Dutch Authorities Arrest Convicted Cybercriminal Linked to ShinyHunters as Group Escalates Global Attacks

Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in massive data thefts and high-stakes extortions orchestrated by the prolific hacker collective known as ShinyHunters. The arrest has sent immediate shockwaves through the cybercrime underworld, prompting remaining members of the group to dramatically escalate their campaign. In the days following the detention, the syndicate carried out aggressive breaches, stealing highly sensitive personal and medical data from the Federal Bureau of Investigation (FBI) and extorting the notorious Russian ransomware group Cl0p.

According to three sources familiar with the matter, the Dutch man taken into custody by law enforcement is Pepijn van der Stap, a convicted cybercriminal originally from Almere and Lelystad in the Netherlands. Van der Stap was previously convicted in 2023 for his involvement in a sweeping series of corporate data thefts and extortion schemes that prosecutors estimated generated between €1.5 million and €2.7 million in illicit proceeds.

A Dual Existence: Software Engineer by Day, Extortionist by Night

During his trial in late 2023, van der Stap candidly admitted to living a modern Dr. Jekyll and Mr. Hyde existence. While secretly wielding the hacker handle “Umbreon” to extort corporate victims and dump stolen databases on prominent English-language cybercrime forums like RaidForums and Breached, he maintained a respectable daytime professional profile. By day, van der Stap was employed as a software engineer at Hadrian, an Amsterdam-based cybersecurity startup, and actively volunteered his technical expertise for the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organization dedicated to independent security research.

Van der Stap confessed openly to his role in the data theft and extortion operations, resulting in a four-year prison sentence, of which one year was suspended. During the court proceedings, van der Stap surprised observers by opting to remain in custody rather than returning home, explaining that he could not find adequate medical or psychological care outside for his ongoing mental health struggles, which included post-traumatic stress disorder stemming from childhood trauma. He was subsequently released from prison in December 2025.

In an interview with KrebsOnSecurity on September 9, 2026, van der Stap sought to rebrand himself as a rehabilitated individual attempting to rebuild his life and make positive contributions to society. At the time of the interview, he was employed as an offensive security lead at Neo Security, a Dutch security firm that has thus far declined to respond to media requests for comment.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Van der Stap noted during the conversation that he was still navigating complex civil litigation and restitution demands related to his past cybercrime victims, emphasizing that he was doing his utmost to make amends. However, shortly after that interview concluded, the Dutch hacker abruptly ceased all communication. Repeated attempts by associates and acquaintances to reach him over the subsequent two weeks failed to elicit a response.

According to two sources with direct knowledge of the investigation, van der Stap was arrested by Dutch law enforcement on or around September 16 and has since been held in custody for intensive questioning. One source noted that a colleague personally witnessed Dutch authorities carting physical evidence and equipment out of van der Stap’s residence.

Dutch law enforcement agencies have spent months intensifying their public appeals for assistance. Earlier in September, authorities released an audio recording of a telephone call from February 2026, asking the public to help identify a native Dutch-speaking ShinyHunters member who successfully used social engineering techniques to breach Odido, the largest mobile telecommunications provider in the Netherlands. During that intrusion, the hacker tricked an Odido employee into authenticating through a spoofed web portal, allowing the syndicate to steal sensitive customer records belonging to more than 6.2 million Dutch citizens.

Responding to inquiries from local news media, representatives for ShinyHunters acknowledged that the voice in the released audio clip belongs to an active member of their collective. In a public statement shared with the NL Times, the group declared full financial, emotional, and legal backing for their detained associate, noting that they had already retained a criminal defense lawyer on his behalf. The statement launched a scathing critique of local law enforcement, calling the Dutch police incompetent, irrelevant, and incapable of preventing future intrusions.

FBI and CL0P Hacks

The geopolitical and operational fallout from the arrest materialized swiftly. Just days after sources confirmed van der Stap’s detention, ShinyHunters claimed responsibility for an extraordinarily brazen cyberattack targeting the FBI’s job application portal, apply.fbijobs.gov. According to reporting from 404 Media and Reuters, the stolen database contained Social Security numbers, detailed personal histories, and employment records for more than 5,000 individuals associated with the bureau.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

The compromised records included specific job titles and sensitive assignments, ranging from special agents and threat intake examiners to members of major cybercrimes units and specialized teams tasked with investigating foreign state-sponsored cyber operations. Furthermore, Reuters verified that the leaked documents included highly confidential psychiatric and medical files belonging to FBI personnel. The bureau subsequently issued a brief public statement confirming the compromise of the recruitment portal.

According to technical analyses by Google Threat Intelligence Group (GTIG) and Mandiant, the intrusion stemmed from the mass exploitation of a recently patched vulnerability, cataloged as CVE-2026-35273, affecting PeopleSoft, an enterprise resource planning platform developed by Oracle. The software giant quickly released emergency patches after discovering the flaw was actively exploited as a zero-day by June. While Mandiant deployed web application firewall (WAF) rules to assist organizations unable to immediately apply updates, security researchers reported that ShinyHunters managed to bypass these mitigations using sophisticated URL-encoding tricks.

Throughout the digital footprint left by the FBI job site defacement, investigators found subtle nods to van der Stap’s historical hacker persona. The defacement screen featured prominent ASCII art depicting the Pokémon character Umbreon alongside a taunting message declaring the site seized by ShinyHunters. This visual motif closely mirrored the defacement aesthetics the group utilized during previous attacks, such as their 2000 breach of the Hackforums community.

Security analysts following the investigation noted that these high-risk operations against the FBI and major ransomware players reflect a sharp tactical pivot for ShinyHunters. This operational shift reportedly followed an internal leadership transition marked by the rise of a teenage cybercriminal from Amman, Jordan, known by the moniker Rey. Rey operates within a coalition known as ScatteredLapsussHunters (SLSH), an amalgamation of threat groups including Scattered Spider, LAPSUS$, and ShinyHunters. Sources indicated that lingering animosity between Rey and the Dutch hacker regarding control over the ShinyHunters brand and infrastructure may have motivated the inclusion of the prominent Umbreon imagery in the FBI attack as an apparent effort to implicate van der Stap.

Shifting Alliances and Future Fallout

The friction between SLSH and ShinyHunters traces back to brief operational partnerships formed earlier in the year. According to reporting by Wired, the groups collaborated to monetize stolen credentials gathered by TeamPCP, an upstart supply-chain hacking collective whose leaders were arrested in Australia. While TeamPCP successfully compromised global code repositories, they struggled to monetize their access. The partnership dissolved rapidly after security firms covertly burned the compromised credentials, leading the allied hacking factions to accuse one another of sabotage.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Mandiant researcher Austin Larsen noted that despite internal friction, ShinyHunters has maintained a lucrative extortion spree throughout the year, projecting nearly $100 million in cumulative extortion revenue for 2026.

Meanwhile, van der Stap’s past motivations stand in sharp contrast to financially driven syndicates. Friends and investigators previously noted that his cybercriminal activities were primarily fueled by an obsessive compulsion to archive and organize stolen data repositories rather than a pursuit of direct financial gain.

As the legal proceedings unfold, the broader security community continues to process the ramifications of the international arrests. The Dutch police confirmed that van der Stap was scheduled to appear before the chambers of the Rotterdam District Court, with authorities promising further updates. Concurrently, international investigative bodies have intensified pressure on the remaining members of the syndicate, signaling that cross-border law enforcement cooperation remains a primary mechanism for disrupting sophisticated global cybercrime networks.

Leave a Reply

Your email address will not be published. Required fields are marked *