Authorities within the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in information thefts and extortions by the prolific hacker group ShinyHunters. Within the days instantly following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their assaults, stealing extremely delicate information from the FBI and extorting the Russian ransomware group Cl0p.
Based on three sources conversant in the matter, the Dutch man arrested by authorities this month is Pepijn van der Stap, a convicted cybercriminal from Almere and Lelystad within the Netherlands. Van der Stap was beforehand convicted in 2023 in reference to a string of information thefts and extortions that prosecutors stated earned between €1.5 million and €2.7 million.
At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly utilizing the hacker deal with “Umbreon” to extort victims and publish their information on English language hacking communities just like the now-defunct RaidForums and Breached. By day, nevertheless, van der Stap was working as a software program engineer on the Amsterdam-based cybersecurity startup Hadrian, whereas volunteering on the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit safety analysis group.
Pepijn van der Stap’s alter ego “Umbreon” promoting a database on RaidForums, providing info on 2.3 million individuals from The Netherlands in September 2021. This consumer’s avatar is an outline of the Pokemon character Umbreon. Picture: KELA.
Van der Stap confessed to his information theft and extortion exercise, and was sentenced to 4 years in jail (one among which was suspended). Throughout his trial, van der Stap opted to stay in custody for a time somewhat than at residence, saying he couldn’t discover higher therapy on the skin for his ongoing psychological points, which he claimed included PTSD associated to childhood trauma. He was launched from jail in December 2025.
In an interview with KrebsOnSecurity on September 9, 2026, Van der Stap solid himself as a reformed hacker who was making an attempt to show his life round and make a optimistic contribution to society. Van der Stap is at the moment employed as offensive safety lead on the Dutch firm Neo Safety, which didn’t reply to requests for remark.
Van der Stap stated he was nonetheless coping with civil lawsuits and restitution associated to his earlier cybercrime victims, and that he was making an attempt his greatest to make amends. However not lengthy after that interview, the Dutch hacker abruptly stopped replying to messages. Efforts by others near him additionally repeatedly didn’t elicit a response for the previous two weeks.
The LinkedIn profile for Pepijn van der Stap.
Based on two sources with information of the matter, Van der Stap was arrested by Dutch authorities on or round September 16, and has been held in custody for questioning since. One supply stated a colleague of theirs personally witnessed Dutch authorities carting gadgets out of Van der Stap’s residence.
Authorities within the Netherlands have been asking the general public for assist in figuring out the voice in a recorded phone name from February 2026 through which a local Dutch-speaking ShinyHunters member social engineered their means into Odido, the nation’s largest cellular telecommunications supplier. In that intrusion, ShinyHunters tricked an Odido worker into logging in at a spoofed web site, after which used that entry to steal information on greater than 6.2 million Dutch individuals.
Responding to Dutch information media, ShinyHunters confirmed that the suspect within the audio clip is certainly a member of the hacker collective.
“Our staff member has our full assist – emotionally, mentally, and financially,” the hackers stated. “The whole lot has been organized, together with a legal protection lawyer. We don’t look down on our workers and members; we take glorious care of them,” reads a press release ShinyHunters shared with NL Occasions. It stays unclear if the Dutch police have matched the Odido caller to a confirmed real-life id. The Dutch police unit dealing with the Odido incident didn’t reply to requests for remark.
The group additionally lashed out on the authorities within the Netherlands. “The Dutch police will want all of the luck on the earth – and everybody’s prayers – in the event that they need to catch him earlier than we supply out one other large-scale information theft within the Netherlands,” the ShinyHunters assertion stated. “Frankly, the Dutch police are a giant joke; they’re incapable of doing something. Incompetent. Irrelevant. Unimportant. Ineffective.”
FBI, CL0P HACKS
Simply days after sources say Van der Stap was detained by Dutch authorities, ShinyHunters claimed credit score for an unusually brazen breach on the FBI’s job software website apply.fbijobs.gov. Based on reporting from 404 Media, the info stolen from the FBI website contains Social Safety numbers and private info on greater than 5,000 officers.
404 Media and Reuters reported the FBI information included every individual’s job title or staff, equivalent to particular agent, risk consumption examiner, main cybercrimes unit, and people investigating cyber threats from overseas state-backed actors. Reuters examined paperwork shared by ShinyHunters and located they included delicate psychiatric and medical recordsdata of FBI workers. The FBI issued a quick assertion confirming the hack.
ShinyHunters stated it gained entry to the FBI website and different victims by exploiting a lately patched vulnerability (CVE-2026-35273) in PeopleSoft, a software-as-a-service platform from the software program large Oracle that’s broadly utilized by corporations to handle hiring and human assets, advantages and payroll. Oracle shortly issued a repair for the Peoplesoft vulnerability that ShinyHunters reportedly started exploiting as a zero-day in June, and on the time Mandiant launched net software firewall guidelines supposed for organizations who couldn’t apply the safety replace shortly sufficient.
However on Friday, BleepingComputer reported that ShinyHunters used a URL-encoding trick to bypass Mandiant’s recommended net software firewall guidelines designed to mitigate the risk from the PeopleSoft flaw. In a report launched Sept. 25, safety consultants at Mandiant and the Google Menace Intelligence Group (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal information from dozens of techniques throughout a spread of industries, together with increased training, know-how, healthcare, agriculture, transportation and authorities.
Van der Stap’s former hacker alias Umbreon was hidden in plain sight all through the imagery ShinyHunters used to unfold information concerning the FBI hack: The defacement picture that ShinyHunters left behind on the hacked FBI jobs website included an ASCII artwork design that includes the Pokemon character Umbreon. The message on the high learn, “This website has been seized by ShinyHunters. rooting your techniques since ’19 ;)” The picture seems equivalent to a defacement message ShinyHunters used of their 2020 hack of the English-language cybercrime group Hackforums.
The defacement message left by ShinyHunters on the FBI jobs website included an ASCII artwork rendition of the Pokemon character Umbreon. Picture: Bleeping Pc.
A number of sources near the ShinyHunters investigation stated the group’s latest dangerous assaults in opposition to the FBI and one among Russia’s most commemorated ransomware teams amounted to a serious pivot away from the extra measured tenor of the hacking gang’s operations. These sources stated the sudden shift took place after ShinyHunters was taken over by a teenage cybercriminal from Amman, Jordan who goes by the nickname Rey and operates as a part of a cybercrime group known as ScatteredLapsussHunters (SLSH), which consultants say is an amalgamation of three hacking teams — Scattered Spider, LAPSUS$ and ShinyHunters.
These sources stated Rey had an ongoing beef with the Dutch hacker over management of the ShinyHunters model and information, and that the inclusion of the outsized Umbreon Pokemon picture within the FBI jobs website defacement was possible an try by Rey to pin the hack on the Dutchman.
Rey was first publicly recognized by the cybersecurity agency KELA in March 2025. Upfront of our November 2025 profile of Rey, KrebsOnSecurity messaged Rey’s father and requested for permission to interview his teenage son. Rey’s dad merely forwarded the message to his son, who admitted to collaborating in ransomware assaults and stated he was making an attempt to extricate himself from the SLSH hacker group.
BLAMING UMBREON
Instantly after information of the FBI jobs website hack was picked up within the media, Rey’s essential account on Twitter/X (Ryan Moran/@rmoskovy) was taunting the Cl0p ransomware group and the FBI, crudely depicting them as the dual towers in New York being struck by planes labeled “cl0p drama” and “fbi breach declare.” Within the foreground of town is the large Pokemon determine of Umbreon.
A taunting meme uploaded to Twitter/X by Rey’s now-defunct account on Sept. 22. An enormous float-sized model of the Pokemon character Umbreon will be seen within the backside left.
On Sept. 24, KrebsOnSecurity once more contacted Rey’s dad, asking to interview him and his son for a narrative on Rey’s obvious ascendency as the top of ShinyHunters. Simply hours after that request, Rey deleted his longtime Twitter/X account. In the meantime, Rey’s dad, who works for the Royal Jordanian Airways, has failed to answer a half-dozen emailed requests for remark about his son’s alleged actions.
The place does the unhealthy blood between SLSH and ShinyHunters come from? Based on a narrative in Wired this month, ShinyHunters and SLSH members briefly partnered earlier this yr to assist higher monetize essential stolen credentials collected by TeamPCP, an upstart group that was having nice success compromising world code provide chains with malicious software program however hadn’t been in a position to revenue a lot from their stolen information (two alleged leaders of TeamPCP had been arrested final month in Australia, and in an interview the TeamPCP chief claimed they made simply $20,000).
The Wired story famous how Mandiant had infiltrated TeamPCP and was secretly answerable for having the crime group’s stolen credentials burned so shortly: Mandiant was secretly feeding these credentials to the main cloud suppliers like Amazon and Microsoft, who shortly invalidated the stolen keys. In the meantime, the previously cooperating hacker teams started responsible each other for inflicting the credentials to develop into nugatory.
Wired’s Andy Greenberg reported that a couple of weeks after partnering with TeamPCP, “ShinyHunters went rogue, finishing up its personal extortions with TeamPCP’s credentials however with out giving the supply-chain hackers their reduce.”
Mandiant researcher Austin Larsen informed KrebsOnSecurity earlier this month that ShinyHunters has been having fun with a profitable extortion spree thus far this yr, and is on observe to tug in practically $100 million in extortion funds from cybercrime victims in 2026.
Van der Stap claims he was by no means motivated by cash and that his earlier hacker exercise was pushed by a need to have the world’s most full assortment of stolen databases. Talking with reporters from Bloomberg in 2024, Van der Stap stated that singular focus in flip fueled his need to hold out cyberattacks.
“The hacking was very straightforward for me, and it wasn’t a compulsion,” he informed Bloomberg. “My behavior was gathering. Amassing information, organizing information, downloading information, creating folders.”
DIVD, the nonprofit safety analysis group the place Van der Stap beforehand served as a volunteer, disclosed on LinkedIn final week that the group was coping with an inside cybersecurity incident that seems to have concerned the malicious use of synthetic intelligence. DIVD has launched few particulars about that incident, however a spokesperson for the nonprofit informed KrebsOnSecurity it doesn’t seem associated to ShinyHunters, nor are there any indicators the matter includes the work of a earlier volunteer.
Replace: 3:44 p.m. ET: Corrected Van der Stap’s age, which is 24 (not 23).
Replace, 4:54 p.m. ET: The Dutch police have confirmed the arrest of a 24-year-old in reference to the ShinyHunters investigation. In a press release on Twitter/X, the Dutch police stated the person will seem on Tuesday, September 29 earlier than the chambers of the Rotterdam District Courtroom, and that it’s going to present extra info tomorrow.









