Cybersecurity

Dutch Authorities Arrest Convicted Cybercriminal Linked to ShinyHunters as Syndicate Escalates Global Attacks

The landscape of international cybersecurity was jolted this month following a high-profile operation by law enforcement in the Netherlands, resulting in the arrest of a 24-year-old convicted cybercriminal. The suspect, identified by multiple knowledgeable sources as Pepijn van der Stap, is accused of providing vital technical and logistical assistance to the prolific and aggressive hacking syndicate known as ShinyHunters. The arrest has triggered a volatile chain reaction across the global digital underground, prompting the remaining leaders of the cybercrime collective to launch a wave of brazen retaliatory attacks against major international institutions, including the United States Federal Bureau of Investigation (FBI) and the Russian-speaking ransomware enterprise Cl0p.

The detention of van der Stap marks a dramatic chapter in an ongoing transcontinental effort to dismantle modern data-extortion cartels. As digital forensics experts, national security agencies, and threat intelligence groups piece together the fragments of these massive breaches, the incident underscores the complex intersection of institutional vulnerabilities, internal syndicate power struggles, and the persistent threat posed by insider-adjacent actors within the cybersecurity community.

The Dual Identity of Pepijn van der Stap

Pepijn van der Stap, a resident of Almere and Lelystad in the Netherlands, is no stranger to law enforcement agencies. In late 2023, he stood trial and was convicted for a sweeping series of data thefts and extortion schemes that Dutch prosecutors estimated generated between €1.5 million and €2.7 million in illicit proceeds. During the judicial proceedings, van der Stap candidly admitted to maintaining a paradoxical lifestyle—functioning as a legitimate software engineer by day while operating under the notorious hacker handle "Umbreon" by night.

Operating under this pseudonym, van der Stap specialized in extorting corporate victims and publishing purloined databases on English-language cybercrime forums, including the now-defunct RaidForums and Breached. Concurrently, he maintained professional legitimacy through employment at Hadrian, an Amsterdam-based cybersecurity startup, and volunteered his technical skills with the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organization dedicated to uncovering and resolving software vulnerabilities.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Van der Stap’s 2023 trial concluded with a four-year prison sentence, of which one year was suspended. Citing ongoing psychological challenges related to childhood trauma and post-traumatic stress disorder (PTSD), van der Stap initially opted to remain in custody rather than serve his sentence at home, believing the institutional environment offered better treatment. Following his release from prison in December 2025, van der Stap sought to rehabilitate his public image. In an interview with security journalists in September 2026, he presented himself as a reformed individual attempting to make amends, working as an offensive security lead at the Dutch firm Neo Security while grappling with lingering civil lawsuits and restitution demands from his past victims.

See also  Chinese AI Powerhouse Moonshot AI Unleashes Kimi K3, Igniting Global Debate on Open Source and Tech Sovereignty

However, this veneer of rehabilitation dissolved mid-September. After abruptly ceasing communication with associates and journalists, Dutch law enforcement detained van der Stap on or around September 16, 2026. Witnesses reported authorities removing physical equipment and materials from his residence, signaling the resumption of active criminal investigations. Dutch police subsequently confirmed the arrest of a 24-year-old male, scheduling his appearance before the Rotterdam District Court to address allegations tying him directly to the ShinyHunters network.

The Odido Breach and Escalating Hostilities

The immediate catalyst for the renewed Dutch law enforcement focus on ShinyHunters stems from a high-stakes social engineering attack earlier in the year. In February 2026, a native Dutch-speaking operative successfully infiltrated Odido, the largest mobile telecommunications provider in the Netherlands. By tricking an employee into authenticating credentials on a spoofed website, the attacker harvested sensitive personal data belonging to more than 6.2 million Dutch citizens.

In an unusual public appeal, Dutch police released a recorded telephone call from the incident, asking the public for assistance in identifying the suspect’s voice. ShinyHunters quickly claimed ownership of the audio clip, confirming that the voice belonged to a core member of their collective. In a defiant statement released to regional media outlets, the syndicate pledged complete emotional, mental, and financial support for their detained comrade, while launching vitriolic insults at Dutch law enforcement agencies, dismissing them as incapable and irrelevant.

Threat intelligence analysts noted that this aggressive posturing was not merely rhetorical. Within days of van der Stap’s detention, the syndicate abandoned its historical operational discretion, pivoting toward high-risk, high-impact targets that invited immediate international scrutiny.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

The FBI Jobs Site Compromise and Global Fallout

The most explosive manifestation of this operational pivot occurred when ShinyHunters claimed responsibility for a sophisticated breach of the FBI’s employment portal, apply.fbijobs.gov. Security reports confirmed that the attackers exfiltrated sensitive personally identifiable information (PII) belonging to more than 5,000 individuals, including Social Security numbers, detailed professional histories, and specific departmental assignments within the bureau.

The leaked records exposed personnel tied to sensitive divisions, including special agents, threat intake examiners, and units dedicated to combating cyber threats from foreign state-sponsored actors. Furthermore, investigative findings from news organizations and security firms revealed that the compromised data included confidential medical and psychological evaluation files of FBI staff. The bureau subsequently issued a public statement confirming the unauthorized access to the portal.

According to technical analyses by Google Threat Intelligence Group (GTIG) and Mandiant, the intrusion relied on the mass exploitation of a critical vulnerability (CVE-2026-35273) within Oracle PeopleSoft, a widely deployed enterprise human resources and payroll platform. Although Oracle rapidly issued security patches, and security firms released defensive web application firewall (WAF) mitigations, ShinyHunters managed to bypass these protective measures utilizing advanced URL-encoding tricks. The campaign ultimately impacted dozens of organizations across diverse sectors, including healthcare, higher education, government, technology, and transportation.

See also  Twitter Faces Explosive Whistleblower Allegations of Grave Security Lapses and National Security Risks

Cryptic signaling permeated the FBI breach. The defacement message left by the hackers featured prominent ASCII art depicting the Pokémon character Umbreon alongside the declaration: "This site has been seized by ShinyHunters. rooting your systems since ’19." This visual motif closely mirrored the imagery utilized by van der Stap during his historical cybercriminal activities, setting off alarms among investigators tracking internal syndicate dynamics.

Syndicate Fragmentation and the Rise of "Rey"

Security researchers tracking the cybercrime underground attribute this aggressive escalation to a fundamental shift in leadership within ShinyHunters. Sources familiar with the syndicate’s internal politics indicate that control of the group was recently assumed by a teenage cybercriminal operating out of Amman, Jordan, known by the handle "Rey."

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Rey operates within an amalgamated cybercrime collective designated as ScatteredLapsussHunters (SLSH), which integrates remnants and methodologies from three notorious hacking groups: Scattered Spider, LAPSUS$, and ShinyHunters. Investigative profiles published by cybersecurity firm KELA and independent journalists have traced Rey’s rise through the digital criminal ecosystem, noting his involvement in multiple high-profile extortion campaigns.

Intelligence analysts suggest that the inclusion of the oversized Umbreon imagery in the FBI portal defacement was not an accidental homage, but a calculated maneuver by Rey to implicate van der Stap directly. Reports indicate that deep-seated animosity existed between Rey and the Dutch hacker regarding control over the ShinyHunters brand and monetized data repositories. This friction was further exacerbated by a brief, volatile partnership earlier in the year with TeamPCP—a supply-chain hacking gang whose credentials were rapidly burned by security researchers, leading to mutual accusations of betrayal and rogue extortions within the alliance.

Following the international media coverage of the FBI breach, Rey’s primary social media presence featured taunting memes aimed at both federal investigators and the rival Cl0p ransomware syndicate, juxtaposing global landmarks with satirical representations of the ongoing cyber conflicts. Shortly after journalists initiated further inquiries regarding his role as the head of ShinyHunters, those accounts were abruptly deactivated, and familial contacts declined to comment on the allegations.

Institutional Implications and Future Outlook

The convergence of insider threats, AI-augmented social engineering, and decentralized cartel structures highlights the evolving challenges confronting global cybersecurity defenses. While institutions grapple with resilient zero-day exploits targeting foundational enterprise infrastructure like Oracle PeopleSoft, law enforcement agencies face the arduous task of untangling complex webs of shifting aliases, ideological rivalries, and international jurisdictions.

The arrest of Pepijn van der Stap in the Netherlands, paired with the aggressive retaliation by the fragmented ShinyHunters collective under new leadership, signals that modern cybercrime syndicates are increasingly resilient to traditional disruption efforts. As judicial proceedings against van der Stap progress in the Rotterdam District Court, cybersecurity professionals and international law enforcement agencies remain on high alert, anticipating further retaliatory digital campaigns from a syndicate that continues to weaponize sophisticated technical exploits and psychological warfare against global institutions.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Tech Newst
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.