Dutch Police Arrest Convicted Hacker Tied to ShinyHunters Extortion Spree
Dutch police arrested a 24-year-old man on September 15, 2026, on suspicion of aiding the prolific extortion group ShinyHunters in data thefts and extortions, authorities confirmed publicly on September 28-29, 2026. Police have not officially named the suspect, but KrebsOnSecurity identified him through multiple sources as Pepijn van der Stap, a Dutch national from Almere and Lelystad who was previously convicted in 2023 for hacking and extortion under the alias "Umbreon." A Rotterdam District Court ordered 90 additional days of pretrial detention. In a striking twist, remaining ShinyHunters members dramatically escalated their attacks in the days immediately following the arrest, breaching the FBI's job-application site and attempting to extort the Russian ransomware group Cl0p — fueling speculation that rivals inside the group may have used van der Stap's old hacker identity to frame him amid an internal leadership dispute.
Details
| Attribute | Value |
|---|---|
| Suspect (named by sources, not police) | Pepijn van der Stap, age 24, Almere/Lelystad, Netherlands |
| Official police description | Unnamed "24-year-old Amsterdam man" |
| Arrest date | September 15, 2026 |
| Public confirmation | September 28-29, 2026 |
| Court action | Rotterdam District Court ordered 90 additional days of detention |
| Prior conviction | 2023, data theft and extortion prosecutors valued at roughly 1.5 to 2.7 million euros |
| Prior sentence | Four years (one year suspended); released December 2025 |
| Former hacker alias | "Umbreon" |
| Alleged current role | Aiding ShinyHunters data theft and extortion, linked to the February 2026 Odido breach |
| Separate allegation | Investigators are examining material from a seized laptop suggesting an attempt to solicit two murders abroad |
| Employer at time of arrest | Neo Security (offensive security lead); the company has found no evidence of wrongdoing against it or its clients |
The "Reformed Hacker" Backstory
Van der Stap's history reads like a cautionary tale about redemption narratives in the security industry. During his earlier criminal run, he lived what he later admitted in court was a "Dr. Jekyll and Mr. Hyde existence" — by day, a software engineer at the Amsterdam cybersecurity startup Hadrian and a volunteer with the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit that responsibly discloses security flaws; by night, the hacker "Umbreon," who stole databases and posted them for sale on forums including RaidForums and Breached. Prosecutors said the scheme generated between 1.5 and 2.7 million euros before his 2023 conviction. After his December 2025 release, van der Stap took a job as offensive security lead at Neo Security and, in a September 9, 2026 interview with KrebsOnSecurity, described himself as reformed and said he was working toward paying restitution to his victims — just days before his arrest.
The Odido Breach and the ShinyHunters Link
Investigators tied van der Stap to the February 2026 breach of Odido, the Netherlands' largest mobile carrier, in which ShinyHunters used social engineering to steal data on 6.2 million people. Dutch authorities had previously released audio of a native Dutch speaker believed to have orchestrated the intrusion and asked the public for help identifying the voice — a detail that points to how investigators may have connected the Odido operation to a Dutch national.
Escalation After the Arrest
Rather than going quiet, ShinyHunters ramped up activity almost immediately after van der Stap's detention became known. The group claimed credit for breaching the FBI's job-application portal, apply.fbijobs.gov, exposing Social Security numbers and other personal data — including psychiatric and medical records — belonging to more than 5,000 officials. Around the same time, ShinyHunters attempted to extort the Russian ransomware operation Cl0p. Both intrusions reportedly exploited CVE-2026-35273, a vulnerability in Oracle's PeopleSoft platform, with attackers using URL-encoding tricks to slip past web application firewall (WAF) rules deployed by incident responders at Mandiant. Oddly, the FBI site defacement included ASCII art of Umbreon, the Pokémon character van der Stap's alias was named after — a detail some sources believe was a deliberate attempt to implicate him in attacks he had no part in, rather than evidence of continued involvement. Suspicion has focused on "Rey," a teenage cybercriminal based in Amman, Jordan, first publicly identified by the threat intelligence firm KELA in March 2025, who reportedly took over leadership of ShinyHunters within a broader alliance called ScatteredLapsussHunters (SLSH) — combining members associated with Scattered Spider, LAPSUS$, and ShinyHunters. Sources say Rey had an ongoing dispute with van der Stap over control of the ShinyHunters brand before the arrest.
Official Statements
ShinyHunters publicly denied that van der Stap had "any association" with the group, dismissed Dutch police as "incapable," "incompetent," and "useless," and claimed the group provides members with emotional, mental, and financial support, including arranging legal defense. On the law enforcement side, FBI Cyber Division Assistant Director Brett Leatherman urged remaining ShinyHunters members to turn themselves in, noting that "arrests have a way of changing who is willing to talk." FBI Director Kash Patel said additional arrests remain on the table.
Impact Assessment
| Impact Area | Description |
|---|---|
| Telecom customer exposure | The February 2026 Odido breach exposed personal data on 6.2 million customers, one of the larger consumer-data incidents in the Netherlands this year |
| Law enforcement targeting | The breach of the FBI's job application site exposed sensitive personal and psychiatric data on more than 5,000 officials, a significant escalation in targets ShinyHunters is willing to hit |
| Criminal ecosystem instability | An apparent internal leadership struggle, allegedly involving the framing of a detained member, suggests ShinyHunters/SLSH is fracturing even as its attack tempo increases |
| Extortion economy scale | Mandiant analysts estimated the group's 2026 PeopleSoft exploitation campaign was on track to generate nearly 100 million dollars in extortion payments |
| Broad sector exposure | The underlying PeopleSoft zero-day campaign, active since June 2026, has hit organizations across higher education, technology, healthcare, agriculture, transportation, and government |
Recommendations
For Organizations Running Oracle PeopleSoft
- Confirm patches for CVE-2026-35273 are fully applied across all PeopleSoft instances, not just internet-facing ones.
- Review WAF rule sets for URL-encoding bypass gaps; attackers used encoding tricks to evade rules Mandiant had deployed, so signature-only defenses are insufficient.
- Hunt retroactively for indicators of compromise dating back to June 2026, when the exploitation campaign is believed to have begun, rather than assuming a recent patch date means no prior exposure.
For Incident Response and Threat Intelligence Teams
- Track the apparent leadership dispute within ShinyHunters/ScatteredLapsussHunters (SLSH) as a potential source of operational security lapses, leaked internal information, or cooperating insiders.
- Treat alias-based attribution (such as the "Umbreon" imagery left at the FBI breach) with caution — threat actors have both the motive and the means to plant misleading identity markers during internal conflicts.
- Expect continued high-tempo attacks from remaining group members even after high-profile arrests; this incident shows detentions can trigger escalation rather than deterrence in loosely organized extortion collectives.
For the General Public and Affected Customers
- Odido customers and anyone notified of involvement in a ShinyHunters-linked breach should watch for targeted phishing, SIM-swap attempts, and social engineering calls referencing their account details.
- Monitor credit reports and consider a credit freeze if notified that personal data was exposed in the Odido breach or any related incident.
- Use unique, strong passwords and enable multi-factor authentication on telecom and financial accounts, since stolen customer data is frequently reused for follow-on account-takeover attempts.
Key Takeaways
- Dutch police arrested a 24-year-old man on September 15, 2026, on suspicion of aiding ShinyHunters; KrebsOnSecurity identified him via sources as Pepijn van der Stap, though police have not officially named him.
- Van der Stap was previously convicted in 2023 for hacking under the alias "Umbreon" while working a day job in cybersecurity and volunteering at a vulnerability-disclosure nonprofit, and had publicly described himself as reformed days before his arrest.
- Investigators linked him to the February 2026 Odido breach, which exposed data on 6.2 million customers of the Netherlands' largest mobile carrier.
- Remaining ShinyHunters members escalated attacks immediately after the arrest, breaching the FBI's job site and attempting to extort the ransomware group Cl0p via a PeopleSoft vulnerability, CVE-2026-35273.
- Sources suggest a rival figure, "Rey," may have used van der Stap's old alias to frame him amid an internal dispute over control of the ShinyHunters brand.
- The FBI is urging remaining group members to surrender, warning that arrests tend to loosen tongues, while Mandiant estimates the group's 2026 campaign is on pace to generate close to 100 million dollars in extortion payments.