Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in massive data thefts and high-stakes extortions orchestrated by the prolific hacker collective known as ShinyHunters. The high-profile arrest has sent shockwaves through the underground cybercrime community, triggering a dramatic and aggressive escalation from the remaining members of the group, who have launched retaliatory attacks against major international targets, including the Federal Bureau of Investigation (FBI), and even moved to extort the notorious Russian ransomware syndicate Cl0p.
According to three independent sources familiar with the matter, the suspect detained by Dutch law enforcement this month is Pepijn van der Stap, a previously convicted cybercriminal hailing from Almere and Lelystad in the Netherlands. Van der Stap’s notoriety in the cybersecurity sphere dates back to a high-profile 2023 criminal trial connected to a sweeping string of data thefts and digital extortions. Dutch prosecutors at the time estimated that those illicit operations generated between €1.5 million and €2.7 million in illegal proceeds.
During his late 2023 trial, van der Stap offered a startling confession, admitting to leading a double life that echoed a modern-day Dr. Jekyll and Mr. Hyde existence. While maintaining a facade of legitimacy, he secretly operated under the hacker handle "Umbreon"—named after the popular Pokémon character—using the moniker to extort vulnerable victims and dump stolen corporate and personal databases onto English-language cybercrime forums, including the now-defunct RaidForums and Breached.
By day, however, van der Stap was employed as a software engineer at Hadrian, an Amsterdam-based cybersecurity startup. He also dedicated his time to altruistic tech efforts, volunteering with the Dutch Institute for Vulnerability Disclosure (DIVD), a well-known nonprofit security research organization dedicated to finding and patching software flaws before malicious actors could exploit them.
Following his confession to multiple counts of data theft and extortion, van der Stap was sentenced to four years in prison, with one year suspended. In a peculiar twist during legal proceedings, van der Stap initially chose to remain incarcerated rather than return home, arguing that he could not find adequate medical and psychological treatment on the outside for lingering mental health issues, which he stated included post-traumatic stress disorder stemming from childhood trauma. He was eventually released from custody in December 2025.
In an interview with KrebsOnSecurity on September 9, 2026, van der Stap sought to rebrand himself as a fully reformed individual trying to turn his life around and make positive contributions to society. At the time of the interview, he was employed as an offensive security lead at Neo Security, a Dutch cybersecurity firm that ultimately declined to comment on the unfolding situation.
During the conversation, van der Stap noted that he was still navigating complex civil lawsuits and court-mandated restitution payments tied to his past cybercrimes, emphasizing that he was making every effort to make amends. However, shortly after that interview, van der Stap abruptly ceased responding to communications. Attempts by colleagues and acquaintances to reach him over the subsequent two weeks also met with silence.

According to two sources with direct knowledge of the investigation, Dutch law enforcement officers arrested van der Stap on or around September 16, taking him into custody for intensive questioning. One source reported that a colleague personally witnessed police officers removing boxes and hardware from van der Stap’s residence.
Dutch police have faced mounting pressure following a series of devastating breaches, most notably an intrusion earlier this year into Odido, the nation’s largest mobile telecommunications provider. Authorities had previously appealed to the public for assistance in identifying a native Dutch-speaking ShinyHunters member whose voice was captured in a February 2026 telephone call. In that social engineering attack, the hacker tricked an Odido employee into authenticating credentials on a spoofed website, allowing the threat actors to siphon personal data belonging to more than 6.2 million Dutch citizens.
Responding to local media inquiries, ShinyHunters confirmed that the individual heard in the leaked audio clip was indeed a core member of their collective. In a statement released to the NL Times, the group vowed unconditional backing for their detained associate. "Our team member has our full support – emotionally, mentally, and financially," the hackers declared, adding that legal defense and logistics had already been arranged.
The collective also issued a fiery challenge to law enforcement. "The Dutch police will need all the luck in the world – and everyone’s prayers – if they want to catch him before we carry out another large-scale data theft in the Netherlands," the statement read, accompanying the threat with scathing insults directed at the competence of Dutch investigators.
FBI AND CL0P HACKS
The fallout from van der Stap’s detention materialized rapidly on the global stage. Just days after sources confirmed his arrest, ShinyHunters claimed responsibility for an exceptionally brazen cyberattack targeting the FBI’s job application portal, apply.fbijobs.gov. Reporting from 404 Media revealed that the stolen information included sensitive personally identifiable information, such as Social Security numbers and personnel records, impacting more than 5,000 individuals associated with the bureau.
Investigative findings shared by 404 Media and Reuters showed that the leaked database contained specific job titles and operational divisions, including records for special agents, threat intake examiners, and personnel assigned to major cybercrime units and foreign state-backed threat investigations. Furthermore, documents reviewed by Reuters indicated that the cache included highly sensitive medical and psychiatric files belonging to FBI personnel. The bureau subsequently issued a brief public statement confirming the compromise of the recruitment portal.
According to ShinyHunters, initial access to the FBI’s systems—alongside numerous other enterprise networks—was achieved by exploiting a recently patched vulnerability, tracked as CVE-2026-35273, affecting PeopleSoft. The software-as-a-service platform, developed by Oracle, is widely utilized by major corporations and government agencies worldwide for human resources management, payroll, and recruitment. Although Oracle quickly issued security patches after the flaw began seeing active zero-day exploitation in June, and Mandiant provided defensive web application firewall (WAF) rules, security researchers soon discovered new attack vectors.
BleepingComputer reported that ShinyHunters managed to bypass Mandiant’s recommended WAF mitigation rules by employing clever URL-encoding manipulation techniques. A joint threat intelligence report published on September 25 by Mandiant and the Google Threat Intelligence Group confirmed that the hackers had carried out a widespread mass-exploitation campaign leveraging the PeopleSoft vulnerability, compromising dozens of corporate, governmental, educational, healthcare, and technological infrastructure systems.

Subtle clues left behind at the crime scenes suggested lingering internal friction within the cybercrime underworld. The defacement image posted by ShinyHunters on the compromised FBI jobs portal featured an unmistakable ASCII art rendering of the Pokémon character Umbreon—van der Stap’s former hacking alias. Atop the image, a taunting message read: "This site has been seized by ShinyHunters. rooting your systems since ’19 ;)." Security analysts noted that the visual layout was identical to a defacement banner deployed by ShinyHunters during their 2020 breach of Hackforums.
Sources close to the ongoing law enforcement investigations noted that the group’s sudden pivot toward high-risk targets like the FBI and a prominent Russian ransomware syndicate marked a sharp departure from their traditional operational tempo. This tactical shift reportedly coincided with a leadership change within the collective, following a takeover by a teenage cybercriminal from Amman, Jordan. Operating under the alias "Rey," this individual is a key figure in ScatteredLapsussHunters (SLSH), an umbrella cybercrime syndicate merging operatives from Scattered Spider, LAPSUS$, and ShinyHunters.
Investigators indicated that Rey harbored a persistent grudge against van der Stap over control of the ShinyHunters brand and proprietary stolen databases. Consequently, security experts believe the prominent placement of the Umbreon imagery in the FBI portal defacement was an intentional maneuver by Rey to implicate and frame the imprisoned Dutch hacker.
Rey was first unmasked publicly by the cybersecurity firm KELA in March 2025. In the lead-up to a profile published later that year, inquiries directed to Rey’s family led to the teenager acknowledging his participation in various ransomware operations while simultaneously expressing a desire to distance himself from the SLSH network.
Following widespread media coverage of the FBI portal breach, Rey’s primary account on X (formerly Twitter) engaged in extensive taunting directed at both the FBI and the Cl0p ransomware faction, publishing inflammatory memes juxtaposed alongside a massive floating image of the Umbreon Pokémon character. Shortly after security researchers renewed inquiries regarding Rey’s elevated status within ShinyHunters, the account was abruptly deleted. Repeated email inquiries directed to Rey’s father, an employee of Royal Jordanian Airlines, regarding his son’s alleged digital activities went unanswered.
The underlying animosity between SLSH and traditional ShinyHunters factions stems from recent commercial partnerships gone sour. According to an investigative report published by Wired, members of ShinyHunters and SLSH briefly joined forces earlier in the year to help monetize high-value corporate credentials gathered by TeamPCP. TeamPCP was an emerging threat group that successfully compromised global software supply chains but struggled to convert stolen access into financial gains—reportedly netting a mere $20,000 before two of its alleged leaders were arrested in Australia.
In reality, Mandiant analysts had covertly infiltrated TeamPCP’s operations, systematically leaking stolen credentials to major cloud infrastructure providers like Amazon and Microsoft to invalidate the access keys before the hackers could exploit them. As the profits dried up, the allied cybercrime factions began accusing each other of sabotage. According to Wired, ShinyHunters ultimately went rogue, executing independent extortion schemes using the shared credentials without distributing cuts to their supply-chain partners.
Despite these internal frictions, threat intelligence analysts estimate that ShinyHunters has maintained a lucrative extortion campaign throughout the year, putting the collective on track to amass nearly $100 million in illicit payments by the end of 2026.

Van der Stap had previously maintained that his actions were never driven purely by financial gain, telling Bloomberg in a 2024 interview that his primary motivation was an obsessive compulsion to archive data. "The hacking was very easy for me, and it wasn’t a compulsion," he stated. "My habit was collecting. Collecting data, organizing data, downloading data, creating folders."
Meanwhile, the Dutch Institute for Vulnerability Disclosure announced that it had recently addressed an internal cybersecurity incident involving the suspected malicious application of artificial intelligence. Although DIVD provided limited details, a spokesperson confirmed that the event bore no relation to ShinyHunters and showed no ties to the activities of any former volunteers.
Dutch police formally confirmed the arrest of the 24-year-old suspect in connection with the broadening ShinyHunters investigation, stating that the individual would appear before the Rotterdam District Court. Subsequent investigative reporting from Dutch news outlet RTL revealed that authorities are examining allegations that van der Stap may have attempted to orchestrate at least two murders abroad, allegedly issuing directives for the planned crimes.
Providing an international update on the ongoing joint operations, Brett Leatherman, assistant director of the FBI’s cyber division, released a video statement thanking Dutch law enforcement partners for their pivotal assistance while warning remaining members of ShinyHunters that the net is closing.
"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left," Leatherman said. "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out to us while the choice is still yours."
Leave a Reply