Dutch authorities have apprehended Pepijn van der Stap, a 24-year-old convicted cybercriminal from Almere and Lelystad, on suspicion of facilitating data breaches and extortion activities orchestrated by the notorious hacker collective ShinyHunters. This arrest, occurring in early September 2026, precipitated a dramatic surge in ShinyHunters’ operations, with the group subsequently claiming responsibility for significant data thefts from the FBI and attempting to extort the Russian ransomware group Cl0p. Van der Stap, who previously operated under the hacker alias "Umbreon," was convicted in 2023 for his involvement in a string of data thefts and extortion schemes that prosecutors estimated netted between €1.5 million and €2.7 million. During his 2023 trial, van der Stap confessed to leading a double life, using his hacker persona to extort victims and disseminate their data on now-defunct forums like RaidForums and Breached, while simultaneously working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian and volunteering for the Dutch Institute for Vulnerability Disclosure (DIVD). He received a four-year prison sentence, with one year suspended, and was released in December 2025. In a September 9, 2026, interview with KrebsOnSecurity, van der Stap presented himself as a reformed individual dedicated to contributing positively to society, stating he was employed as an offensive security lead at Neo Security and was actively working to make amends for his past actions through civil lawsuits and restitution. However, shortly after this interview, van der Stap ceased communication, prompting concern among those who knew him. Sources familiar with the investigation confirm van der Stap’s arrest around September 16, 2026, and his ongoing detention for questioning. One source reported witnessing Dutch authorities removing items from his residence. The Dutch police have been actively seeking public assistance to identify a ShinyHunters member whose voice was captured in a February 2026 social engineering attack that compromised Odido, the Netherlands’ largest mobile provider, leading to the theft of data belonging to over 6.2 million Dutch citizens. ShinyHunters confirmed the individual in the audio clip was a member of their group, offering him full support and highlighting their commitment to their members’ well-being, including legal representation. The group also issued a defiant statement mocking the Dutch police’s capabilities and vowing further large-scale attacks in the Netherlands. The timing of van der Stap’s arrest coincided with ShinyHunters’ audacious claims of breaching the FBI’s job application site, apply.fbijobs.gov, stealing sensitive personal information, including Social Security numbers, of over 5,000 officials. This data reportedly included personal and medical files of FBI staff. The FBI confirmed the breach, attributing it to the exploitation of a vulnerability (CVE-2026-35273) in Oracle’s PeopleSoft software, a platform widely used for human resources management. ShinyHunters had reportedly been exploiting this vulnerability as a zero-day since June 2026. Security experts from Mandiant and the Google Threat Intelligence Group (GTIG) confirmed in a September 25, 2026, report that ShinyHunters had extensively exploited this PeopleSoft vulnerability across various sectors. Notably, the defacement message left by ShinyHunters on the compromised FBI site featured an ASCII art depiction of the Pokémon character Umbreon, van der Stap’s former hacker alias, a detail that sources suggest was a deliberate attempt by a rival cybercriminal to implicate him. Multiple sources close to the ShinyHunters investigation indicate that the group’s recent aggressive attacks on the FBI and the Cl0p ransomware group marked a significant shift in their operational strategy, potentially orchestrated by a teenage cybercriminal from Jordan known as "Rey," who leads the ScatteredLapsussHunters (SLSH) collective, an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters. These sources suggest Rey harbors animosity towards van der Stap over control of the ShinyHunters brand and data, and that the prominent inclusion of Umbreon in the FBI hack’s defacement was a ploy to frame the Dutchman. Rey was first identified by cybersecurity firm KELA in March 2025. In a taunting meme posted on his now-defunct Twitter/X account on September 22, 2026, Rey alluded to the FBI and Cl0p breaches, featuring a giant Umbreon figure. Following a September 24, 2026, inquiry about interviewing Rey and his father, Rey deleted his Twitter/X account. The bad blood between SLSH and ShinyHunters reportedly stems from a failed partnership earlier in 2026. ShinyHunters and SLSH members had briefly collaborated with TeamPCP, a group specializing in supply chain compromises, to monetize stolen credentials. However, ShinyHunters allegedly "went rogue," extorting victims with TeamPCP’s data without sharing profits, leading to mutual blame when the stolen credentials were invalidated by cloud providers, a move orchestrated by Mandiant’s infiltration of TeamPCP. Austin Larsen, a Mandiant researcher, noted that ShinyHunters has been highly successful in extortion, projecting nearly $100 million in earnings for 2026. Van der Stap, however, maintained that his primary motivation was not financial gain but the accumulation of the world’s most comprehensive collection of stolen databases. In a 2024 interview with Bloomberg, he described his hacking as a "habit" of collecting, organizing, and downloading data. The DIVD, where van der Stap formerly volunteered, recently disclosed an internal cybersecurity incident involving the malicious use of AI, though a spokesperson stated it does not appear to be related to ShinyHunters or the work of a former volunteer. The Dutch police confirmed the arrest of a 24-year-old in connection with the ShinyHunters investigation and stated that the suspect would appear before the Rotterdam District Court on September 29, 2026.


