Online Security & Privacy

Cybercriminal Arrest in the Netherlands Sparks Global Data Theft Escalation and FBI Breach Investigations

The arrest of 24-year-old Dutch national Pepijn van der Stap on September 16, 2026, has sent shockwaves through the global cybersecurity landscape, triggering a series of retaliatory and high-profile data breaches orchestrated by the notorious hacker collective known as ShinyHunters. Van der Stap, a previously convicted cybercriminal who famously balanced a career in legitimate security research with an illicit alter ego, is currently being held by Dutch authorities on suspicion of facilitating extensive data thefts and extortion campaigns. In the immediate wake of his detention, the remaining members of ShinyHunters launched a series of brazen attacks, including a successful infiltration of the FBI’s job application portal, effectively weaponizing the arrest to signal their continued operational capacity.

The Double Life of Umbreon

The suspect, identified by three independent sources as Pepijn van der Stap, represents a complex archetype of modern cybercrime: the "dual-life" offender. Operating under the online handle "Umbreon," van der Stap gained notoriety for his role in large-scale data exfiltration and the subsequent sale of sensitive information on platforms such as RaidForums and Breached. His 2023 conviction, which resulted in a four-year prison sentence, was the culmination of a long-running investigation into data thefts that generated between €1.5 million and €2.7 million in illicit proceeds.

During his 2023 trial, van der Stap provided a candid, if unsettling, look into his psychological motivations. He described a "Dr. Jekyll and Mr. Hyde" existence where, by day, he functioned as a respected software engineer at Hadrian—an Amsterdam-based cybersecurity startup—and a volunteer for the Dutch Institute for Vulnerability Disclosure (DIVD). By night, he allegedly pivoted to the role of Umbreon, systematically dismantling the security of various organizations. Following his release from prison in December 2025, van der Stap sought to re-enter the professional security sector, securing a position as an offensive security lead at Neo Security. However, his recent arrest suggests a failure to fully detach from his former illicit associations, or perhaps a tactical move by his criminal peers to exploit his past reputation.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Chronology of the Escalation

The timeline leading to the current crisis began in early 2026, when the Dutch National Police initiated a public appeal to identify a suspect in the massive breach of Odido, the Netherlands’ largest mobile telecommunications provider. In February 2026, a Dutch-speaking operative associated with ShinyHunters successfully social-engineered an Odido employee, leading to the theft of personal data belonging to over 6.2 million Dutch citizens.

The situation reached a boiling point in mid-September 2026:

  • September 9, 2026: Van der Stap grants an interview to KrebsOnSecurity, positioning himself as a reformed professional working to make restitution for his past crimes.
  • September 16, 2026: Dutch authorities execute an arrest warrant for van der Stap. Witnesses report law enforcement removing hardware and evidence from his residence.
  • September 18-20, 2026: ShinyHunters publicly acknowledges the arrest of their member, providing a defiant statement to the NL Times claiming they have arranged legal representation for him and vowing further attacks.
  • September 22, 2026: The group claims responsibility for breaching the FBI’s job application site (apply.fbijobs.gov), exfiltrating personal data of over 5,000 employees.
  • September 29, 2026: The suspect is scheduled to appear before the Rotterdam District Court to face charges related to his ongoing involvement in the ShinyHunters collective.

The FBI Breach and Oracle Vulnerabilities

The breach of the FBI’s recruitment infrastructure serves as a significant escalation in the group’s tactics. According to reports from 404 Media and Reuters, the stolen data included Social Security numbers, job titles, and, in some instances, sensitive psychiatric and medical records of FBI staff. This incident was not a random occurrence but a calculated exploitation of a critical vulnerability in Oracle’s PeopleSoft software, tracked as CVE-2026-35273.

Despite Oracle issuing a patch and Mandiant providing mitigation strategies, ShinyHunters utilized advanced URL-encoding techniques to bypass web application firewalls. Security researchers at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that the group had used this specific exploit to compromise systems across healthcare, agriculture, and government sectors globally. The inclusion of the "Umbreon" ASCII art in the FBI site’s defacement page suggests a twofold motive: a display of technical dominance and a possible "frame job" orchestrated by rival elements within the hacker community.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Internal Strife: The Rise of Rey and SLSH

The recent aggression displayed by ShinyHunters is attributed by industry insiders to a shift in leadership. The group has reportedly fallen under the influence of a teenage cybercriminal based in Amman, Jordan, known as "Rey." Rey is a key figure in the "ScatteredLapsussHunters" (SLSH) alliance, a syndicate formed from the remnants of Scattered Spider, LAPSUS$, and ShinyHunters.

Tensions have simmered between the established ShinyHunters members and the newer, more aggressive faction led by Rey. Sources familiar with the internal dynamics of these groups suggest that the use of the Umbreon imagery in the FBI hack was likely an intentional maneuver by Rey to cast blame upon van der Stap, effectively burning his bridge to any potential "reformed" status and deepening the legal peril faced by the Dutchman. The "bad blood" appears rooted in a failed partnership with the supply-chain hacking group TeamPCP. After attempting to monetize stolen credentials together, the groups turned on each other when those credentials were invalidated by major cloud providers following covert interventions by security researchers.

Broader Implications and Institutional Impact

The economic and operational impact of these breaches is profound. Mandiant researcher Austin Larsen estimated that ShinyHunters is currently on track to extract nearly $100 million in extortion payments throughout 2026. This financial windfall provides the group with significant resources to fund advanced operations, legal protection for its members, and further exploitation of zero-day vulnerabilities.

For the Dutch police, the challenge is twofold: they must prosecute a high-level cybercriminal while simultaneously managing the fallout from a collective that views them with blatant contempt. The statement issued by ShinyHunters, calling the Dutch police "incompetent" and "irrelevant," highlights the growing divide between state law enforcement and decentralized, profit-driven hacking syndicates.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Furthermore, the incident at the Dutch Institute for Vulnerability Disclosure (DIVD), while officially unrelated to the ShinyHunters campaign, underscores the fragility of security institutions when faced with internal threats. The use of artificial intelligence in an internal security incident at DIVD—a group dedicated to tracking vulnerabilities—serves as a reminder that even the most security-conscious organizations are susceptible to the evolving tactics of sophisticated threat actors.

Conclusion: A War of Attrition

The arrest of Pepijn van der Stap is a tactical victory for Dutch law enforcement, yet it has served as a catalyst for a more aggressive phase in the ShinyHunters’ campaign. As the group continues to pivot away from traditional data theft toward high-visibility extortion, the global security community remains on high alert. The ongoing legal proceedings against van der Stap in the Rotterdam District Court will be closely monitored, not only for the fate of the individual but for the potential intelligence that may emerge regarding the inner workings of SLSH and the future trajectory of the ShinyHunters collective. With both sides now entrenched in a war of attrition, the security of global supply chains and government infrastructure remains significantly compromised.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button