Home Cybersecurity & Hacking Dutch Authorities Arrest Convicted Cybercriminal Linked to ShinyHunters as International Hackers Launch Unprecedented Retaliation

Dutch Authorities Arrest Convicted Cybercriminal Linked to ShinyHunters as International Hackers Launch Unprecedented Retaliation

by admin

Law enforcement authorities in the Netherlands have apprehended a 24-year-old convicted cybercriminal on suspicion of facilitating high-profile data thefts and corporate extortions orchestrated by the prolific and aggressive hacker collective known as ShinyHunters. The arrest has triggered a massive escalation in cyber hostilities worldwide, with remaining members of the hacking syndicate launching brazen retaliatory attacks against elite global targets, including the Federal Bureau of Investigation (FBI) and the notorious Russian ransomware syndicate Cl0p.

According to multiple intelligence sources familiar with the ongoing international investigation, the suspect detained by Dutch authorities is Pepijn van der Stap, a resident of Almere and Lelystad who previously faced prosecution for a massive string of digital intrusions. Van der Stap’s arrest highlights the persistent threat of insider-adjacent threat actors moving fluidly between legitimate cybersecurity positions and the criminal underworld.

The Chronology of a Dual Life: From Cybersecurity Professional to Cybercriminal

The trajectory of Pepijn van der Stap’s criminal career provides a stark illustration of the modern convergence between ethical cybersecurity research and malicious exploitation. In late 2023, van der Stap stood trial in the Netherlands for a series of sophisticated data thefts and extortion campaigns that Dutch prosecutors estimated yielded illicit profits ranging between €1.5 million and €2.7 million.

During the 2023 proceedings, van der Stap admitted to living a paradoxical existence. By day, he functioned as a competent software engineer for Hadrian, an Amsterdam-based cybersecurity startup, while simultaneously volunteering his time and technical skills to the Dutch Institute for Vulnerability Disclosure (DIVD), a well-regarded nonprofit security research collective. By night, however, he assumed the hacker handle “Umbreon”—named after the Pokémon character—to extort corporate victims and monetize stolen databases on English-language cybercrime forums, including the now-seized marketplaces RaidForums and Breached.

Van der Stap ultimately confessed to the charges and received a four-year prison sentence, with one year suspended. Opting to remain institutionalized rather than return home immediately to manage ongoing psychological health challenges, including post-traumatic stress disorder stemming from childhood trauma, van der Stap served his time until his release in December 2025.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

In subsequent interviews, including a conversation with cybersecurity journalist Brian Krebs on September 9, 2026, van der Stap projected the image of a thoroughly reformed individual attempting to make amends and rebuild his life. At the time of his second apprehension, he was employed as an offensive security lead at Neo Security, a Dutch cybersecurity firm. However, friends and associates noted an abrupt halt in his communications shortly after the interview, preceding the confirmation that Dutch authorities had executed a search and seizure operation at his residence and taken him into custody around September 16, 2026.

Escalation and Retaliation: The Odido Breach and ShinyHunters’ Defiance

The apprehension of van der Stap marks a significant escalation in a sweeping Dutch police investigation into the February 2026 compromise of Odido, the largest mobile telecommunications provider in the Netherlands. During that intrusion, a native Dutch-speaking member of ShinyHunters utilized advanced social engineering tactics, tricking an Odido employee into authenticating credentials on a spoofed web portal. This unauthorized access enabled the threat actors to exfiltrate sensitive personal data belonging to more than 6.2 million Dutch citizens.

In an unusual public relations move, the Dutch police released an audio recording of the social engineering phone call in September 2026, appealing to the public for assistance in identifying the speaker. ShinyHunters promptly confirmed to Dutch media outlets that the voice belonged to a core member of their collective, offering aggressive vocal and financial support to the detained individual.

In statements released to regional publications, ShinyHunters lashed out at law enforcement, dismissing the Dutch police as incompetent and warning of severe impending retaliation. True to their word, the syndicate launched an aggressive campaign of retaliatory cyberattacks that stunned international intelligence agencies and private cybersecurity firms alike.

The FBI Job Portal Breach and the Oracle PeopleSoft Zero-Day Campaign

Just days after van der Stap’s detention, ShinyHunters claimed responsibility for an extraordinarily audacious cyberattack targeting the FBI’s job application web portal, apply.fbijobs.gov. According to investigative reporting and federal disclosures, the breach compromised sensitive personally identifiable information (PII), including Social Security numbers and detailed background files of more than 5,000 bureau personnel.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

The compromised records included sensitive psychiatric evaluations, medical histories, and operational rosters detailing the assignments of special agents, threat intake examiners, and officers assigned to major cybercrime units and foreign counterintelligence divisions. The FBI subsequently issued a formal public statement acknowledging the unauthorized access and the impact on employee data.

Security analysts at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters achieved the breach—alongside dozens of parallel intrusions across higher education, healthcare, technology, agriculture, transportation, and government sectors—by mass-exploiting a critical vulnerability (CVE-2026-35273) in Oracle’s PeopleSoft enterprise software. Although Oracle rapidly released patches following the zero-day discovery in June, ShinyHunters successfully bypassed mitigation rules, including web application firewall (WAF) mitigations suggested by Mandiant, by leveraging sophisticated URL-encoding evasion techniques.

Further linking the current wave of attacks to the detained Dutch hacker, the defacement banner left by ShinyHunters on the compromised FBI portal prominently featured an ASCII art depiction of the Pokémon character Umbreon, alongside the defiant declaration: "This site has been seized by ShinyHunters. rooting your systems since ’19 ;)."

Internal Power Struggles and the Rise of "Rey"

According to intelligence gathered by private security firms and researchers, the recent pivot toward high-risk, high-visibility attacks against federal law enforcement agencies and prominent ransomware syndicates like Cl0p represents a major strategic shift for ShinyHunters. This operational evolution reportedly followed a leadership transition within the collective.

The syndicate is now allegedly under the strong influence of a teenage cybercriminal from Amman, Jordan, who operates under the alias "Rey" and serves as a key administrator for ScatteredLapsussHunters (SLSH)—a coalition uniting elements of notorious threat groups including Scattered Spider, LAPSUS$, and ShinyHunters.

Investigators suggest that the inclusion of the oversized Umbreon imagery in the FBI job portal defacement was not merely a stylistic choice, but a calculated maneuver by Rey to intentionally implicate van der Stap in the high-profile federal crime. Tensions between the legacy ShinyHunters faction and the newer SLSH members had reportedly simmered for months following a botched monetization scheme involving stolen supply-chain credentials obtained from TeamPCP, an upstart hacking group whose leaders were arrested in Australia in August 2026. Mandiant analysts revealed that security teams had preemptively burned those credentials by feeding them directly to cloud giants like Amazon and Microsoft, triggering mutual accusations of betrayal among the allied cybercrime factions.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Broader Implications and the Global Cybersecurity Impact

The fallout from the van der Stap arrest and the subsequent ShinyHunters campaign carries profound implications for international cybersecurity resilience and law enforcement cooperation.

Financially, threat intelligence assessments indicate that despite constant law enforcement pressure, ShinyHunters remains on a lucrative trajectory, projected to extract nearly $100 million in extortion payments throughout 2026. The group’s ability to operationalize zero-day vulnerabilities in enterprise resource planning software underscores the acute vulnerabilities inherent in global supply chains and human resources infrastructure.

Furthermore, the investigation took a chilling turn when Dutch news outlet RTL reported that investigators suspect van der Stap of attempting to orchestrate at least two contract murders overseas, signaling a disturbing convergence between digital extortion rings and physical transnational crime.

In response to these developments, law enforcement agencies have redoubled their efforts to dismantle the remaining infrastructure of the ShinyHunters network. Brett Leatherman, Assistant Director of the FBI’s Cyber Division, issued a direct warning to the remaining members of the collective, emphasizing that international cooperation and digital forensics are rapidly closing the net around them.

"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left," Leatherman stated. "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out to us while the choice is still yours."

You may also like

Leave a Comment