Cybersecurity

Dutch Authorities Arrest Convicted Cybercriminal Pepijn van der Stap in Connection with Massive ShinyHunters Data Thefts and Extortions

Law enforcement authorities in the Netherlands have apprehended 24-year-old convicted cybercriminal Pepijn van der Stap on suspicion of providing material assistance to data thefts and extortion campaigns orchestrated by the prolific and aggressive hacker collective known as ShinyHunters. The high-profile arrest, executed in mid-September 2026, has triggered an immediate and volatile escalation in the global threat landscape. In the days following the detention, remaining factions of ShinyHunters retaliated with brazen digital intrusions targeting the United States Federal Bureau of Investigation (FBI) and launched retaliatory extortion demands against the notorious Russian-speaking ransomware syndicate Cl0p.

The arrest marks a critical turning point in an international law enforcement investigation into a sprawling cybercrime enterprise that security experts estimate is on track to amass nearly $100 million in extortion payments throughout 2026. As federal agencies in both Europe and North America coordinate their next steps, the case exposes the precarious double lives led by modern threat actors, the fluid alliances within the criminal underground, and the shifting leadership dynamics driving some of the world’s most disruptive cyberattacks.

The Dual Life of Umbreon: From Cybersecurity Employee to Cyber Extortionist

According to multiple sources familiar with the ongoing investigation, the individual taken into custody by Dutch authorities is Pepijn van der Stap, a resident of Almere and Lelystad in the Netherlands. Van der Stap is hardly a newcomer to law enforcement agencies; he was previously convicted in late 2023 for his involvement in an extensive string of data thefts and corporate extortions that Dutch prosecutors estimated generated between €1.5 million and €2.7 million in illicit proceeds.

During his 2023 judicial proceedings, van der Stap candidly admitted to maintaining a bifurcated existence—a classic Dr. Jekyll and Mr. Hyde lifestyle. By night, he operated under the online hacker handle “Umbreon,” named after the fictional Pokémon character, using the moniker to extort victim organizations and peddle stolen corporate databases on prominent English-language cybercrime forums such as the now-defunct RaidForums and Breached.

By day, however, van der Stap projected the image of a reformed or legitimate technical professional. He was employed as a software engineer at Hadrian, an Amsterdam-based cybersecurity startup, and actively volunteered his technical expertise at the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organization dedicated to independent security research.

Following his confession to data theft and extortion charges during his trial, van der Stap was sentenced to four years in prison, with one year suspended. Bizarrely, during the legal proceedings, van der Stap elected to remain incarcerated rather than return home, citing a lack of comparable psychological treatment on the outside for what he described as post-traumatic stress disorder stemming from childhood trauma. He was ultimately released from custody in December 2025.

In an interview with cybersecurity journalist Brian Krebs on September 9, 2026, van der Stap attempted to rebrand himself once more. He portrayed himself as a genuinely rehabilitated individual striving to repair his life and make constructive contributions to society. At the time of the interview, he was working as an offensive security lead at Neo Security, a Dutch enterprise that has declined to comment on the arrest. Van der Stap maintained that he was actively cooperating with civil litigation and paying restitution to his past victims. However, communication abruptly ceased shortly after the interview, preceding his detention by Dutch authorities on or around September 16, 2026.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Escalation of Violence and Shocking Allegations

The fallout from van der Stap’s arrest extended far beyond standard operational disruptions for ShinyHunters. Investigators and intelligence analysts monitoring the group noted an immediate pivot from calculated data theft toward high-risk, highly confrontational targets.

See also  Lockbit Leads Global Ransomware Resurgence as Conti Offshoots Regroup and Expand Operations

Adding an alarming dimension to the legal proceedings, Dutch news outlet RTL reported that investigators increasingly suspect van der Stap of attempting to orchestrate at least two murders. According to these findings, the alleged plots were intended to be executed abroad, and prosecutors possess indications that the suspect issued direct orders for the killings. While the full scope of these allegations continues to unfold in the Rotterdam District Court, the revelation underscores the dangerous intersections between digital extortion syndicates and physical violence.

The Odido Breach and Public Appeals

Dutch law enforcement agencies have spent much of 2026 unraveling the domestic footprint of ShinyHunters. Earlier in the year, authorities launched a public appeal to identify a native Dutch-speaking voice captured in a recorded telephone call from February 2026. In that audio, a ShinyHunters operative successfully used social engineering tactics to manipulate an employee at Odido, the Netherlands’ largest mobile telecommunications provider, into logging into a spoofed phishing website.

The resulting breach compromised sensitive personal data belonging to more than 6.2 million Dutch citizens. When local media publicized the audio clip, ShinyHunters brazenly confirmed that the speaker was a member of their collective, issuing a public statement that promised financial, emotional, and legal support for their detained comrade. Furthermore, the group hurled insults at Dutch law enforcement, describing the police force as incompetent and irrelevant.

The Dutch police officially confirmed the arrest of a 24-year-old male in connection with the ongoing investigation, stating that the suspect would appear before the chambers of the Rotterdam District Court to face formal charges.

Retaliatory Cyberattacks: The FBI and Cl0p Breaches

Just days after sources confirmed van der Stap’s detention, ShinyHunters executed one of the most audacious cyberattacks in recent memory: a breach of the FBI’s employment portal, apply.fbijobs.gov.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

According to investigative reports by 404 Media and Reuters, the unauthorized intrusion compromised Social Security numbers and deeply sensitive personal information belonging to more than 5,000 bureau personnel. The stolen documentation included specific job titles and operational team assignments, identifying individuals working within specialized units such as special agent teams, threat intake examiners, major cybercrimes divisions, and units tasked with investigating state-sponsored foreign cyber threats. Furthermore, Reuters confirmed that the exfiltrated files contained confidential medical and psychiatric evaluations of FBI employees. The bureau subsequently issued a formal statement acknowledging the compromise of the recruitment portal.

Security researchers identified the primary vector for the FBI breach as the exploitation of a recently patched vulnerability, cataloged as CVE-2026-35273, affecting PeopleSoft—a widely utilized enterprise human resources, payroll, and recruitment software platform developed by Oracle. Although Oracle swiftly issued a security advisory and patch after the flaw was exploited as a zero-day vulnerability in June, ShinyHunters demonstrated sophisticated evasion capabilities. BleepingComputer reported that the group utilized advanced URL-encoding techniques to bypass web application firewall (WAF) mitigation rules recommended by Mandiant.

A joint threat intelligence report published by Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters conducted a mass-exploitation campaign targeting Oracle PeopleSoft instances across diverse sectors, including healthcare, technology, higher education, agriculture, transportation, and government agencies.

Adding a mocking signature to the FBI breach, the defacement page left behind on the compromised recruitment portal featured an ASCII art illustration of the Pokémon character Umbreon—a direct nod to van der Stap’s former hacker handle. The accompanying text read, “This site has been seized by ShinyHunters. rooting your systems since ’19 ;)” This visual motif closely mirrored the digital graffiti the group utilized during its 2020 compromise of the Hackforums cybercrime community.

See also  RefluXFS: New Linux Kernel Flaw (CVE-2026-64600) Exposes XFS Filesystems to Persistent Root Access

Shifting Power Dynamics: The Rise of "Rey" and ScatteredLapsussHunters

Cybersecurity analysts tracking the upper echelons of the cybercriminal underground emphasize that the recent pivot toward reckless, high-visibility attacks reflects a fundamental shift in leadership and operational philosophy within ShinyHunters.

According to intelligence sources, the group underwent a structural takeover spearheaded by a teenage cybercriminal from Amman, Jordan, known online as Rey. Rey operates as a core administrator within ScatteredLapsussHunters (SLSH), an aggressive hybrid syndicate formed through the amalgamation of three notorious hacking groups: Scattered Spider, LAPSUS$, and ShinyHunters.

Rey was publicly unmasked in March 2025 by the threat intelligence firm KELA. Sources suggest that a deep personal and operational rivalry existed between Rey and van der Stap over control of the ShinyHunters brand and its vast repositories of stolen data. Investigators believe the prominent inclusion of the Umbreon Pokémon imagery in the FBI job site defacement was a deliberate framing tactic engineered by Rey to shift law enforcement focus squarely onto the Dutch hacker.

The friction between SLSH and traditional ShinyHunters factions was further exacerbated by a botched partnership earlier in the year with TeamPCP, an upstart group specializing in code supply-chain compromises. As detailed in investigative reporting by Wired, the groups attempted to pool stolen corporate credentials to maximize monetization. However, Mandiant analysts covertly infiltrated TeamPCP’s operations, neutralizing the stolen keys by feeding them directly to cloud giants like Amazon and Microsoft, which invalidated the access tokens.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Amid the ensuing chaos, cooperative ties fractured. According to Mandiant researcher Austin Larsen, while internal fractionalization has intensified, ShinyHunters has maintained a lucrative extortion pipeline, remaining on pace to extract nearly $100 million from corporate victims throughout 2026.

International Response and Implications

The convergence of international law enforcement actions, internal syndication warfare, and high-stakes targeting of law enforcement infrastructure underscores a new era in global cybersecurity governance.

Following the arraignment in Rotterdam, Brett Leatherman, Assistant Director of the FBI’s Cyber Division, released a video statement expressing gratitude to Dutch law enforcement partners for their decisive intervention. Leatherman issued a direct warning to the remaining members of ShinyHunters who continue to evade capture.

"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left," Leatherman stated. "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out to us while the choice is still yours."

As judicial proceedings against Pepijn van der Stap advance in the Netherlands and global intelligence agencies work to dismantle the infrastructure supporting ScatteredLapsussHunters, the case serves as a stark reminder of the fragile boundary between legitimate technical proficiency and malicious cyber insurgency. The fallout from the ShinyHunters investigation is expected to reverberate across corporate boardrooms, government intelligence agencies, and underground forums for months to come.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Tech Newst
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.