Authorities in the Netherlands have apprehended a 24-year-old convicted cybercriminal on suspicion of providing critical support to the notorious hacker collective known as "ShinyHunters." The arrest has triggered a volatile response from the group, which has dramatically escalated its illicit operations, including high-profile data thefts targeting the Federal Bureau of Investigation (FBI) and the extortion of the Russian-linked ransomware syndicate Cl0p.
According to three sources familiar with the ongoing investigation, the individual taken into custody this month is Pepijn van der Stap, a resident of the Dutch cities of Almere and Lelystad. Van der Stap is a known figure in European cybersecurity circles, having been convicted in 2023 for his involvement in a sophisticated series of data thefts and extortion schemes. Prosecutors in that earlier case estimated that his criminal activities yielded between €1.5 million and €2.7 million in illicit gains.
During his 2023 trial, van der Stap offered a candid, if unsettling, look into his dual life. He described a "Dr. Jekyll and Mr. Hyde" existence: by night, he operated under the alias "Umbreon," extorting victims and leaking sensitive databases on prominent English-language cybercrime forums like RaidForums and Breached. By day, however, he maintained the facade of a legitimate cybersecurity professional, working as a software engineer at the Amsterdam-based startup Hadrian and volunteering his time with the Dutch Institute for Vulnerability Disclosure (DIVD), a well-regarded nonprofit focused on security research.
Van der Stap eventually confessed to his role in the data thefts and was sentenced to four years in prison, with one year suspended. During the legal proceedings, he opted to remain in state custody rather than serve time at home, citing a need for structured treatment regarding his psychological health, including PTSD stemming from childhood trauma. He was released from prison in December 2025.
In an interview with KrebsOnSecurity on September 9, 2026, van der Stap painted a picture of a man attempting to distance himself from his past. He claimed to be a reformed individual dedicated to making positive contributions to society. At the time of the interview, he was employed as an offensive security lead at the Dutch firm Neo Security. When contacted for comment regarding the recent developments, Neo Security did not respond.

Despite his stated desire to move forward, van der Stap noted he was still navigating the complex legal and financial fallout of his past crimes, including civil lawsuits and restitution requirements. However, the veneer of his rehabilitation began to crack shortly after the interview, when he abruptly ceased all communication with reporters and associates. According to two sources with direct knowledge of the situation, Dutch authorities arrested van der Stap on or around September 16. The operation was significant enough that a witness reported seeing law enforcement officers removing a large volume of equipment and materials from his residence.
The Odido Intrusion and Police Pressure
The arrest coincides with a desperate, public-facing effort by Dutch law enforcement to identify members of ShinyHunters. Earlier in September, police released a recorded telephone call from February 2026, asking the public for assistance in identifying the voice of a native Dutch-speaking hacker. In the recording, the individual successfully used social engineering tactics to gain unauthorized access to Odido, the Netherlands’ largest mobile telecommunications provider. The breach was devastating, allowing the hackers to exfiltrate the personal data of more than 6.2 million Dutch citizens after tricking an employee into logging into a spoofed website.
ShinyHunters, via a statement provided to the NL Times, confirmed that the suspect in the audio recording is a member of their collective. The group’s response was defiant, vowing to support their associate: "Our team member has our full support—emotionally, mentally, and financially. Everything has been arranged, including a criminal defense lawyer. We do not look down on our staff and members; we take excellent care of them."
The group further insulted Dutch authorities, stating, "The Dutch police will need all the luck in the world—and everyone’s prayers—if they want to catch him before we carry out another large-scale data theft in the Netherlands. Frankly, the Dutch police are a big joke; they are incapable of doing anything. Incompetent. Irrelevant. Unimportant. Useless."
The Escalation: Targeting the FBI and Cl0p
The detention of van der Stap appears to have acted as a catalyst for the group. Days after his arrest, ShinyHunters claimed responsibility for a brazen breach of the FBI’s job application portal, apply.fbijobs.gov. The breach, which was corroborated by reporting from 404 Media, exposed the Social Security numbers and personal details of more than 5,000 FBI personnel.

The stolen files included sensitive information such as job titles, unit affiliations—ranging from special agents to those within the major cybercrimes unit—and even confidential psychiatric and medical records. The FBI confirmed the compromise in a brief statement. Investigators believe the group gained access by exploiting a recently patched vulnerability, CVE-2026-35273, in Oracle’s PeopleSoft software. While Oracle issued a fix for the vulnerability, which had been utilized as a zero-day exploit as early as June, security researchers at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had utilized a URL-encoding trick to bypass suggested web application firewall mitigations, allowing them to mass-exploit the flaw across numerous industries.
The "Umbreon" persona, previously associated with van der Stap, was prominently featured in the FBI site defacement. The hackers left an ASCII art design of the Pokémon character Umbreon alongside a taunting message: "This site has been seized by ShinyHunters. Rooting your systems since ’19 ;)." The design was nearly identical to the imagery used by the group in a 2020 attack on HackForums.
Internal Conflict and the Rise of "Rey"
Security experts suggest that the recent, high-risk attacks against the FBI and the Russian ransomware gang Cl0p signal a fundamental shift in the group’s hierarchy and strategy. Sources close to the investigation indicate that the group is now under the influence of a teenage cybercriminal based in Amman, Jordan, known as "Rey." Rey is allegedly a key operator within a collective called "ScatteredLapsussHunters" (SLSH), a group formed from the remnants of Scattered Spider, LAPSUS$, and ShinyHunters.
Evidence suggests a brewing conflict between Rey and the Dutch hacker over control of the ShinyHunters brand and its repository of stolen data. Experts believe the inclusion of the "Umbreon" imagery in the FBI hack was a calculated move by Rey to frame the Dutchman.
The transition to this new, more aggressive leadership is supported by the group’s recent activities. According to Mandiant researcher Austin Larsen, ShinyHunters is on track to extract nearly $100 million in extortion payments in 2026 alone. This aggressive monetization strategy is a stark departure from van der Stap’s stated motivation, which he previously characterized as a compulsion for "collecting" and organizing data rather than a purely financial endeavor.

The situation has become increasingly dire for those involved. In a late-September development, the Dutch news outlet RTL reported that investigators now suspect van der Stap of orchestrating at least two murders to be carried out abroad. Meanwhile, the FBI has signaled that the net is tightening. In a public video message, Brett Leatherman, assistant director of the FBI’s cyber division, thanked Dutch law enforcement and issued a warning to the remaining members of the group: "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out to us while the choice is still yours."
As of late September 2026, Dutch police confirmed that van der Stap was scheduled to appear before the Rotterdam District Court to face the charges leveled against him, marking a definitive chapter in the ongoing international pursuit of the ShinyHunters collective.

