Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Dutch authorities have apprehended 24-year-old Pepijn van der Stap, a convicted cybercriminal and former security professional, on suspicion of facilitating large-scale data thefts and extortion operations for the notorious hacker group ShinyHunters. The arrest, which took place in the Netherlands on September 16, 2026, has sent shockwaves through the global cybersecurity community, triggering a volatile retaliation campaign from the remnants of the ShinyHunters collective. This development marks a significant escalation in the ongoing struggle between international law enforcement agencies and decentralized cybercrime syndicates, as investigators uncover evidence suggesting that the reach of these groups may extend beyond digital extortion into the realm of physical violence.
A Double Life: From Researcher to Cybercriminal
The suspect at the center of this investigation, Pepijn van der Stap, presents a classic case of the modern digital divide. Residing in Almere and Lelystad, Van der Stap had cultivated a dual persona. By day, he was a respected figure in the Dutch cybersecurity landscape, working as a software engineer for the Amsterdam-based startup Hadrian and contributing as a volunteer for the Dutch Institute for Vulnerability Disclosure (DIVD). However, behind this legitimate facade, he operated under the alias "Umbreon," an identity he utilized to orchestrate data breaches and auction off stolen information on underground forums such as RaidForums and Breached.
Van der Stap’s criminal career is not new to the courts. In 2023, he was convicted for a series of data thefts that reportedly generated between €1.5 million and €2.7 million. During those proceedings, Van der Stap described his internal struggle as a "Dr. Jekyll and Mr. Hyde" existence. He was sentenced to four years in prison, with one year suspended, and was released in December 2025. Following his release, Van der Stap attempted to rebrand himself as a reformed professional, securing a position as an offensive security lead at Neo Security. However, his recent arrest suggests that his involvement with the dark web never fully ceased.

The ShinyHunters Escalation and the Odido Breach
The arrest of Van der Stap coincided with an intensified effort by the Dutch police to identify the voice of a suspect linked to the February 2026 compromise of Odido, the Netherlands’ largest mobile telecommunications provider. In that incident, a native Dutch-speaking operative associated with ShinyHunters successfully social-engineered an employee into logging into a spoofed website, resulting in the theft of sensitive personal data belonging to over 6.2 million Dutch citizens.
Following the arrest, ShinyHunters issued a defiant response, confirming that the individual identified in the audio clips was a member of their collective. In a statement provided to the NL Times, the group claimed to be providing their associate with full emotional, mental, and financial support, including the provision of a high-profile criminal defense attorney. The group’s rhetoric was notably aggressive, dismissing the Dutch police as "incompetent" and "irrelevant," and warning of further large-scale attacks within the Netherlands as a direct response to the detention.
Global Impact: The FBI and Oracle PeopleSoft Vulnerabilities
The fallout from Van der Stap’s detention reached international borders within days. ShinyHunters claimed credit for a breach of the FBI’s recruitment portal, apply.fbijobs.gov. The breach exposed the personal identifiable information (PII) of more than 5,000 individuals, including special agents and personnel assigned to high-stakes units investigating foreign state-backed cyber threats. Reports from 404 Media and Reuters indicate that the stolen files even contained sensitive psychiatric and medical records of agency staff.
The technical mechanism behind this breach—and many others during the same period—involved the exploitation of a critical vulnerability in Oracle’s PeopleSoft software, tracked as CVE-2026-35273. While Oracle moved quickly to patch the flaw, researchers at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had utilized a URL-encoding technique to bypass security mitigations, effectively turning the PeopleSoft vulnerability into a mass-exploitation tool. This campaign hit sectors ranging from healthcare and agriculture to government and higher education, highlighting the systemic risk posed by flaws in widely used enterprise human resources software.

Internal Strife and the Rise of "Rey"
Security analysts have noted a marked change in the operating philosophy of ShinyHunters, which has shifted from data-harvesting to aggressive, high-profile extortion. This transition is widely attributed to a change in leadership. Sources indicate that a teenage cybercriminal based in Amman, Jordan, known as "Rey," has ascended to a leadership position within the group. Rey is a central figure in the ScatteredLapsussHunters (SLSH) coalition, a group formed by the remnants of Scattered Spider, LAPSUS$, and ShinyHunters.
The tension between the original ShinyHunters members and the SLSH coalition appears to have reached a boiling point. Evidence suggests that the inclusion of the "Umbreon" ASCII art in the FBI defacement was not merely a signature, but a strategic move by Rey to frame the Dutch suspect, effectively burning his bridges with the original collective. The interpersonal conflict, coupled with the failed monetization of stolen credentials from the "TeamPCP" supply-chain hacks, has created a volatile environment where former partners are now actively sabotaging one another.
Broader Implications and Legal Consequences
The investigation has taken a dark turn in recent days. On September 29, 2026, the Dutch outlet RTL reported that investigators are now looking into allegations that Van der Stap may have attempted to orchestrate at least two murders, with instructions allegedly sent abroad. If proven, these charges would represent a profound shift in the danger level posed by cybercriminal syndicates, moving from financial extortion to the facilitation of lethal violence.
In response to the escalating situation, the FBI has taken a firm public stance. Assistant Director of the FBI’s Cyber Division, Brett Leatherman, released a video statement emphasizing that the agency’s investigative reach is closing in on the group. "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who is left," Leatherman noted. The FBI’s message is clear: the window for voluntary cooperation is narrowing as law enforcement agencies pool their intelligence globally.

Analysis: A Systemic Crisis in Digital Security
The case of Pepijn van der Stap serves as a case study for the fragility of the digital economy. The ease with which a single individual, armed with technical expertise and a lack of moral or legal restraint, can compromise national security agencies and global infrastructure providers is alarming. The use of "zero-day" exploits in enterprise software like PeopleSoft, combined with the professionalization of hacking groups that provide legal and financial support to their members, underscores the evolution of cybercrime into a pseudo-corporate enterprise.
Furthermore, the involvement of AI-driven tools in recent incidents, such as the one disclosed by the DIVD, suggests that the next generation of cyber-attacks will be even more automated and difficult to detect. While law enforcement has successfully identified and arrested key players, the decentralized and anonymous nature of these groups ensures that the threat remains persistent. As the Dutch legal system prepares for the trial of Van der Stap, the global security community remains on high alert, anticipating further retaliatory strikes from a collective that has proven it is willing to attack the most sensitive institutions in the world to maintain its relevance. The coming months will likely be defined by a massive surge in international cooperation, as the FBI and its counterparts seek to dismantle the SLSH coalition before more sensitive data is compromised.







