Dutch Authorities Arrest Convicted Cybercriminal Linked to ShinyHunters Following Escalated Global Attacks

Authorities in the Netherlands have taken a significant step in the global fight against organized cybercrime, arresting a 24-year-old man on suspicion of facilitating data thefts and extortion campaigns for the notorious hacker collective known as ShinyHunters. The suspect, identified by multiple sources as Pepijn van der Stap, is a convicted cybercriminal from the Dutch cities of Almere and Lelystad. His arrest has sent shockwaves through the dark web, triggering a desperate and aggressive retaliation from the remaining members of the ShinyHunters group, who have launched a series of brazen attacks against high-profile targets, including the FBI and the Russian ransomware syndicate Cl0p.

The arrest, which occurred on or around September 16, 2026, marks the latest chapter in a long-standing investigation into the operations of ShinyHunters. According to sources familiar with the police operation, law enforcement officers were seen removing property and technical equipment from Van der Stap’s residence in the days following the detention. As of late September, he remains in custody, undergoing intensive questioning by Dutch authorities.

A Double Life Unmasked

Van der Stap’s history with the justice system is already well-documented. In 2023, he was convicted for his role in a series of data thefts and extortion schemes that prosecutors estimated generated between €1.5 million and €2.7 million in illicit gains. During his trial, Van der Stap offered a rare glimpse into the psyche of a modern cybercriminal, describing his life as a "Dr. Jekyll and Mr. Hyde" existence.

By night, he operated under the alias "Umbreon," a handle inspired by a Pokémon character, which he used to extort victims and leak their sensitive data on prominent English-language hacking forums such as the now-defunct RaidForums and Breached. By day, however, he maintained a veneer of legitimacy, working as a software engineer at Hadrian, an Amsterdam-based cybersecurity startup. He also volunteered his time with the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organization dedicated to security research—a role that put him in the unique position of observing security vulnerabilities from both sides of the fence.

Van der Stap admitted to these activities during his 2023 trial, where he was sentenced to four years in prison, with one year suspended. Throughout the proceedings, he claimed to be suffering from psychological distress, including PTSD stemming from childhood trauma, and he even requested to remain in custody rather than return home, citing better access to care. He was released from prison in December 2025.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

In a September 9, 2026, interview with KrebsOnSecurity, Van der Stap presented himself as a man striving for redemption. He claimed he was attempting to make amends for his past, noting that he was actively dealing with civil lawsuits and restitution payments to his victims. At the time of that interview, he was employed as an offensive security lead at the Dutch firm Neo Security. However, shortly after that conversation, communication with Van der Stap ceased, and he remained unreachable for weeks before the news of his arrest broke.

ShinyHunters’ Retaliation and the Odido Breach

The Dutch police have been actively seeking public assistance to identify a voice captured in a February 2026 recorded telephone call, in which a native Dutch-speaking member of ShinyHunters successfully social-engineered their way into Odido, the Netherlands’ largest mobile telecommunications provider. By tricking an employee into logging into a spoofed website, the attackers gained access to data belonging to over 6.2 million Dutch citizens.

ShinyHunters has since confirmed that the individual in the audio clip is indeed a member of their collective. In a statement provided to the NL Times, the group pledged their full support to the arrested member, stating, “Our team member has our full support—emotionally, mentally, and financially. Everything has been arranged, including a criminal defense lawyer. We do not look down on our staff and members; we take excellent care of them.”

The group also issued a defiant challenge to Dutch law enforcement, dismissing the police as "incompetent" and "irrelevant." The group’s aggressive rhetoric underscored the volatile nature of the collective following the arrest, as they threatened further large-scale attacks on Dutch soil if their member was not released.

Brazen Attacks: The FBI and Beyond

The fallout from the arrest extended far beyond the borders of the Netherlands. Just days after Van der Stap was detained, ShinyHunters claimed responsibility for an audacious breach of the FBI’s job application portal, apply.fbijobs.gov. Reports from 404 Media and Reuters confirmed that the breach exposed the Social Security numbers and personal information of more than 5,000 FBI officials, including special agents and personnel tasked with investigating foreign state-sponsored cyber threats.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

The stolen files reportedly included sensitive psychiatric and medical records of FBI staff. The FBI acknowledged the compromise in a brief statement, confirming that their job portal had been targeted.

Security researchers, including those at Mandiant and the Google Threat Intelligence Group, identified that the group exploited a vulnerability in Oracle’s PeopleSoft platform, a tool widely used for human resources and payroll management. Despite Oracle’s efforts to patch the flaw, ShinyHunters managed to bypass security mitigations by employing a URL-encoding trick, allowing them to mass-exploit systems across healthcare, government, and technology sectors.

The "Umbreon" alias, which Van der Stap once used, appeared prominently in the defacement images left by ShinyHunters on the FBI portal. This inclusion was viewed by many as a calculated move by the group’s new leadership to link the attack to the detained Dutchman, despite questions regarding his actual level of involvement in this latest campaign.

The Rise of "Rey" and the SLSH Coalition

Sources close to the investigation suggest that the recent shift in ShinyHunters’ behavior—moving toward more dangerous and high-stakes targets—coincides with a change in the group’s internal power structure. Intelligence reports point to a teenage cybercriminal based in Amman, Jordan, known as "Rey," as the current leader of the group. Rey is reportedly a central figure in "ScatteredLapsussHunters" (SLSH), an amalgamation of the LAPSUS$, Scattered Spider, and ShinyHunters gangs.

Rey, who was first identified by the cybersecurity firm KELA in 2025, has been described by his own family as an active participant in ransomware attacks, though he previously expressed a desire to extricate himself from the criminal lifestyle. The friction between Rey and Van der Stap appears to be rooted in a power struggle over the control of the ShinyHunters brand and the data they possess. By featuring the Umbreon character in the FBI defacement, Rey may have been attempting to frame his rival.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

The rivalry is further complicated by the collapse of a previous partnership between these groups and an upstart entity known as TeamPCP. According to reporting by Wired, the groups had attempted to monetize stolen credentials together, only to see the efforts thwarted by Mandiant, which was secretly feeding the stolen information to cloud providers, effectively rendering the data worthless. ShinyHunters subsequently went rogue, carrying out independent extortions using the credentials without providing a cut to their partners, leading to deep-seated animosity.

Escalating Legal Consequences

The legal net continues to tighten. On September 29, Dutch news outlet RTL reported that investigators are now looking into allegations that Van der Stap may have attempted to orchestrate at least two murders abroad, a development that signals a dramatic shift in the severity of the charges he faces.

In a public message, the FBI’s assistant director of the cyber division, Brett Leatherman, expressed gratitude to Dutch law enforcement for their collaboration. He issued a stern warning to the remaining members of the ShinyHunters collective: "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you."

As the Dutch justice system prepares to move forward with the case, the international cyber community watches closely, noting that the combination of high-stakes state-level attacks and the potential for violent criminal charges may signal the end of the era for one of the internet’s most persistent hacking collectives.

Share:

Muslim writes for Tech Maze.

Leave a comment