Home Cybersecurity & Hacking Dutch Authorities Arrest Convicted Cybercriminal Linked to ShinyHunters as Syndicate Escalates Global Attacks

Dutch Authorities Arrest Convicted Cybercriminal Linked to ShinyHunters as Syndicate Escalates Global Attacks

by admin

The landscape of international cybersecurity was shaken this month following the high-profile arrest of a 24-year-old Dutch national suspected of providing critical infrastructure support to the prolific cybercrime syndicate known as ShinyHunters. The detention of the suspect—identified by multiple intelligence sources as Pepijn van der Stap—has triggered a volatile retaliation campaign from remaining faction members. Within days of the enforcement action, the syndicate executed a series of audacious, high-stakes breaches targeting major international entities, including the Federal Bureau of Investigation (FBI) and the notorious Russian-speaking ransomware group Cl0p.

Law enforcement officials in the Netherlands confirmed that the operation culminated around September 16, 2026, when tactical teams executed search warrants at van der Stap’s residence, seizing electronic hardware and data storage media. The Dutch police later verified that a 24-year-old male would face preliminary hearings before the Rotterdam District Court, setting the stage for a complex legal battle centered on international data theft, corporate extortion, and supply chain compromises.

A Jekyll and Hyde Existence in the Dutch Cyber Underworld

Pepijn van der Stap is no stranger to European law enforcement. In late 2023, he was convicted in the Netherlands for orchestrating a series of large-scale corporate data thefts and subsequent extortions that prosecutors estimated yielded between €1.5 million and €2.7 million in illicit proceeds. During those legal proceedings, van der Stap candidly admitted to maintaining a dual existence: by day, he functioned as a legitimate software engineer for Amsterdam-based cybersecurity startup Hadrian and volunteered with the Dutch Institute for Vulnerability Disclosure (DIVD); by night, he operated under the alias "Umbreon," publishing stolen corporate databases on illicit English-language forums like RaidForums and Breached.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Despite receiving a four-year prison sentence—with one year suspended—van der Stap served a portion of his time before being released in December 2025. In subsequent interviews, including a dialogue with security researchers in September 2026, van der Stap portrayed himself as a reformed individual attempting to make restitution and build a legitimate career as an offensive security lead at Neo Security. However, investigators tracking the ShinyHunters collective allege that van der Stap’s underworld ties persisted beneath the surface, culminating in his mid-September apprehension as Dutch authorities closed in on the masterminds behind a massive mobile telecommunications breach.

The Odido Compromise and the Voice That Betrayed the Syndicate

The investigation that ultimately led to van der Stap’s recent detention traces back to a sophisticated social engineering attack executed in February 2026. In that intrusion, perpetrators targeted Odido, the Netherlands’ largest mobile telecommunications provider, tricking an employee into authenticating credentials on a lookalike spoofed domain. The attackers exfiltrated sensitive records belonging to more than 6.2 million Dutch citizens.

In an unusual move, Dutch police broadcasted an intercepted audio recording of the social engineering phone call in September 2026, appealing to the public for assistance in identifying the native Dutch speaker. ShinyHunters publicly acknowledged that the voice belonged to a syndicate member, issuing defiant statements vowing full emotional, mental, and financial support for the detained operative. The group’s leadership concurrently launched aggressive verbal attacks against Dutch law enforcement agencies, dismissing their capabilities while threatening further domestic cyber operations.

Escalation Tactics: The FBI and Cl0p Breaches

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

The arrest served as a catalyst for an immediate and aggressive escalation by the remaining ShinyHunters operatives. Days after van der Stap was taken into custody, the group claimed responsibility for a brazen cyber intrusion targeting the FBI’s employment portal, apply.fbijobs.gov.

According to forensic findings reported by digital security publications and verified by federal announcements, the breach compromised personally identifiable information (PII) of more than 5,000 individuals, including Social Security numbers, internal job classifications, and operational team assignments. Sensitive medical and psychiatric documentation pertaining to bureau personnel was also accessed. The FBI subsequently issued public notices confirming the unauthorized access of the recruitment portal.

Security researchers from Mandiant and the Google Threat Intelligence Group (GTIG) revealed that the FBI breach—alongside widespread attacks across higher education, healthcare, technology, and government sectors—relied on the mass exploitation of a zero-day vulnerability (tracked as CVE-2026-35273) within Oracle’s PeopleSoft enterprise software platform. Although Oracle quickly issued patches, ShinyHunters bypassed subsequent web application firewall (WAF) mitigations using sophisticated URL-encoding tricks.

Intriguingly, the digital calling cards left behind on compromised systems bore explicit references to van der Stap’s former hacker moniker. Defacement pages on the FBI jobs portal featured ASCII art depicting the Pokémon character Umbreon alongside slogans claiming responsibility for network incursions dating back years.

Internal Fractures and the Rise of "Rey"

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Intelligence analysts specializing in cybercrime attribution note that the syndicate’s recent tactical shift reflects a broader, more volatile leadership transition within the underground ecosystem. According to internal sources, ShinyHunters underwent a structural takeover led by a teenage cybercriminal from Amman, Jordan, known by the alias "Rey." Rey operates within an amalgamated cybercrime collective known as ScatteredLapsussHunters (SLSH), which combines elements historically associated with Scattered Spider, LAPSUS$, and ShinyHunters.

Investigators suggest that the inclusion of oversized Umbreon imagery in the FBI defacement was an intentional maneuver by Rey to cast suspicion and pin the fallout of the high-risk federal attack squarely on the imprisoned Dutch national. Tensions between SLSH and traditional ShinyHunters factions have simmered for months, stoked by disputes over monetizing credentials stolen from software supply chain targets like TeamPCP—whose alleged leaders were arrested in Australia following coordinated international police actions.

Security analysts project that despite law enforcement pressures, groups like ShinyHunters and their splinter networks remain on track to extract record-breaking extortion sums from corporate targets throughout 2026. As the Rotterdam District Court prepares to hear arguments regarding van der Stap’s alleged complicity, the wider cybersecurity community continues to grapple with the shifting alliances, aggressive retaliation strategies, and persistent vulnerabilities defining the modern threat landscape.

You may also like

Leave a Comment