NEWS

Dutch Police Arrest 'Reformed' Hacker in ShinyHunters Investigation

Dutch police arrested a 24-year-old convicted hacker tied to ShinyHunters, and the group then breached the FBI's job site and extorted Cl0p.

Dylan H.

News Desk

October 4, 2026
8 min read
Dutch Police Arrest 'Reformed' Hacker in ShinyHunters Investigation

Dutch Police Arrest Convicted Hacker Tied to ShinyHunters Extortion Spree

Dutch police arrested a 24-year-old man on September 15, 2026, on suspicion of aiding the prolific extortion group ShinyHunters in data thefts and extortions, authorities confirmed publicly on September 28-29, 2026. Police have not officially named the suspect, but KrebsOnSecurity identified him through multiple sources as Pepijn van der Stap, a Dutch national from Almere and Lelystad who was previously convicted in 2023 for hacking and extortion under the alias "Umbreon." A Rotterdam District Court ordered 90 additional days of pretrial detention. In a striking twist, remaining ShinyHunters members dramatically escalated their attacks in the days immediately following the arrest, breaching the FBI's job-application site and attempting to extort the Russian ransomware group Cl0p — fueling speculation that rivals inside the group may have used van der Stap's old hacker identity to frame him amid an internal leadership dispute.


Details

AttributeValue
Suspect (named by sources, not police)Pepijn van der Stap, age 24, Almere/Lelystad, Netherlands
Official police descriptionUnnamed "24-year-old Amsterdam man"
Arrest dateSeptember 15, 2026
Public confirmationSeptember 28-29, 2026
Court actionRotterdam District Court ordered 90 additional days of detention
Prior conviction2023, data theft and extortion prosecutors valued at roughly 1.5 to 2.7 million euros
Prior sentenceFour years (one year suspended); released December 2025
Former hacker alias"Umbreon"
Alleged current roleAiding ShinyHunters data theft and extortion, linked to the February 2026 Odido breach
Separate allegationInvestigators are examining material from a seized laptop suggesting an attempt to solicit two murders abroad
Employer at time of arrestNeo Security (offensive security lead); the company has found no evidence of wrongdoing against it or its clients

The "Reformed Hacker" Backstory

Van der Stap's history reads like a cautionary tale about redemption narratives in the security industry. During his earlier criminal run, he lived what he later admitted in court was a "Dr. Jekyll and Mr. Hyde existence" — by day, a software engineer at the Amsterdam cybersecurity startup Hadrian and a volunteer with the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit that responsibly discloses security flaws; by night, the hacker "Umbreon," who stole databases and posted them for sale on forums including RaidForums and Breached. Prosecutors said the scheme generated between 1.5 and 2.7 million euros before his 2023 conviction. After his December 2025 release, van der Stap took a job as offensive security lead at Neo Security and, in a September 9, 2026 interview with KrebsOnSecurity, described himself as reformed and said he was working toward paying restitution to his victims — just days before his arrest.

Investigators tied van der Stap to the February 2026 breach of Odido, the Netherlands' largest mobile carrier, in which ShinyHunters used social engineering to steal data on 6.2 million people. Dutch authorities had previously released audio of a native Dutch speaker believed to have orchestrated the intrusion and asked the public for help identifying the voice — a detail that points to how investigators may have connected the Odido operation to a Dutch national.

Escalation After the Arrest

Rather than going quiet, ShinyHunters ramped up activity almost immediately after van der Stap's detention became known. The group claimed credit for breaching the FBI's job-application portal, apply.fbijobs.gov, exposing Social Security numbers and other personal data — including psychiatric and medical records — belonging to more than 5,000 officials. Around the same time, ShinyHunters attempted to extort the Russian ransomware operation Cl0p. Both intrusions reportedly exploited CVE-2026-35273, a vulnerability in Oracle's PeopleSoft platform, with attackers using URL-encoding tricks to slip past web application firewall (WAF) rules deployed by incident responders at Mandiant. Oddly, the FBI site defacement included ASCII art of Umbreon, the Pokémon character van der Stap's alias was named after — a detail some sources believe was a deliberate attempt to implicate him in attacks he had no part in, rather than evidence of continued involvement. Suspicion has focused on "Rey," a teenage cybercriminal based in Amman, Jordan, first publicly identified by the threat intelligence firm KELA in March 2025, who reportedly took over leadership of ShinyHunters within a broader alliance called ScatteredLapsussHunters (SLSH) — combining members associated with Scattered Spider, LAPSUS$, and ShinyHunters. Sources say Rey had an ongoing dispute with van der Stap over control of the ShinyHunters brand before the arrest.

Official Statements

ShinyHunters publicly denied that van der Stap had "any association" with the group, dismissed Dutch police as "incapable," "incompetent," and "useless," and claimed the group provides members with emotional, mental, and financial support, including arranging legal defense. On the law enforcement side, FBI Cyber Division Assistant Director Brett Leatherman urged remaining ShinyHunters members to turn themselves in, noting that "arrests have a way of changing who is willing to talk." FBI Director Kash Patel said additional arrests remain on the table.

Impact Assessment

Impact AreaDescription
Telecom customer exposureThe February 2026 Odido breach exposed personal data on 6.2 million customers, one of the larger consumer-data incidents in the Netherlands this year
Law enforcement targetingThe breach of the FBI's job application site exposed sensitive personal and psychiatric data on more than 5,000 officials, a significant escalation in targets ShinyHunters is willing to hit
Criminal ecosystem instabilityAn apparent internal leadership struggle, allegedly involving the framing of a detained member, suggests ShinyHunters/SLSH is fracturing even as its attack tempo increases
Extortion economy scaleMandiant analysts estimated the group's 2026 PeopleSoft exploitation campaign was on track to generate nearly 100 million dollars in extortion payments
Broad sector exposureThe underlying PeopleSoft zero-day campaign, active since June 2026, has hit organizations across higher education, technology, healthcare, agriculture, transportation, and government

Recommendations

For Organizations Running Oracle PeopleSoft

  • Confirm patches for CVE-2026-35273 are fully applied across all PeopleSoft instances, not just internet-facing ones.
  • Review WAF rule sets for URL-encoding bypass gaps; attackers used encoding tricks to evade rules Mandiant had deployed, so signature-only defenses are insufficient.
  • Hunt retroactively for indicators of compromise dating back to June 2026, when the exploitation campaign is believed to have begun, rather than assuming a recent patch date means no prior exposure.

For Incident Response and Threat Intelligence Teams

  • Track the apparent leadership dispute within ShinyHunters/ScatteredLapsussHunters (SLSH) as a potential source of operational security lapses, leaked internal information, or cooperating insiders.
  • Treat alias-based attribution (such as the "Umbreon" imagery left at the FBI breach) with caution — threat actors have both the motive and the means to plant misleading identity markers during internal conflicts.
  • Expect continued high-tempo attacks from remaining group members even after high-profile arrests; this incident shows detentions can trigger escalation rather than deterrence in loosely organized extortion collectives.

For the General Public and Affected Customers

  • Odido customers and anyone notified of involvement in a ShinyHunters-linked breach should watch for targeted phishing, SIM-swap attempts, and social engineering calls referencing their account details.
  • Monitor credit reports and consider a credit freeze if notified that personal data was exposed in the Odido breach or any related incident.
  • Use unique, strong passwords and enable multi-factor authentication on telecom and financial accounts, since stolen customer data is frequently reused for follow-on account-takeover attempts.

Key Takeaways

  1. Dutch police arrested a 24-year-old man on September 15, 2026, on suspicion of aiding ShinyHunters; KrebsOnSecurity identified him via sources as Pepijn van der Stap, though police have not officially named him.
  2. Van der Stap was previously convicted in 2023 for hacking under the alias "Umbreon" while working a day job in cybersecurity and volunteering at a vulnerability-disclosure nonprofit, and had publicly described himself as reformed days before his arrest.
  3. Investigators linked him to the February 2026 Odido breach, which exposed data on 6.2 million customers of the Netherlands' largest mobile carrier.
  4. Remaining ShinyHunters members escalated attacks immediately after the arrest, breaching the FBI's job site and attempting to extort the ransomware group Cl0p via a PeopleSoft vulnerability, CVE-2026-35273.
  5. Sources suggest a rival figure, "Rey," may have used van der Stap's old alias to frame him amid an internal dispute over control of the ShinyHunters brand.
  6. The FBI is urging remaining group members to surrender, warning that arrests tend to loosen tongues, while Mandiant estimates the group's 2026 campaign is on pace to generate close to 100 million dollars in extortion payments.

Sources