Law enforcement authorities in the Netherlands have apprehended a 24-year-old convicted cybercriminal suspected of providing vital assistance to the prolific hacking collective known as ShinyHunters. The suspect, identified by sources familiar with the ongoing investigation as Pepijn van der Stap, was taken into custody mid-September following a series of high-profile data thefts and corporate extortions. The arrest has triggered a volatile reaction from the cybercrime syndicate, which has sharply escalated its offensive operations, launching high-profile assaults against the Federal Bureau of Investigation (FBI) and targeting rival cybercrime factions.
The detention of van der Stap marks a significant escalation in a coordinated international crackdown on elite digital extortion rings. As global intelligence agencies close in on the infrastructure supporting these groups, the fallout from van der Stap’s arrest underscores the precarious intersection of institutional cybersecurity defenses, insider threats, and the increasingly complex geopolitical landscape of transnational cybercrime.
The Dual Life of Pepijn van der Stap
Pepijn van der Stap, a resident of Almere and Lelystad in the Netherlands, is no stranger to law enforcement. In late 2023, he was convicted for his role in a sweeping campaign of corporate data thefts and extortions that prosecutors estimated generated between €1.5 million and €2.7 million in illicit proceeds. During his initial trial, van der Stap openly admitted to maintaining a paradoxical lifestyle: by day, he operated as a legitimate software engineer for Amsterdam-based cybersecurity startup Hadrian and volunteered his technical expertise for the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit research collective. By night, he transformed into the notorious English-language forum extortionist operating under the alias “Umbreon.”
Operating primarily on underground cybercrime forums such as the now-defunct RaidForums and Breached, Umbreon specialized in aggregating and monetizing vast troves of stolen data. Despite his criminal activities, van der Stap was sentenced to a four-year prison term, of which one year was suspended. Citing ongoing psychological challenges, including post-traumatic stress disorder stemming from childhood trauma, he initially opted to remain in custody before his eventual release in December 2025.

Following his release, van der Stap appeared to seek rehabilitation, securing employment as an offensive security lead at Neo Security and engaging in restitution efforts with past victims. However, his quiet re-entry into society was cut short. Sources indicate that Dutch police arrested van der Stap on or around September 16, subsequently executing searches of his residence and seizing electronic equipment. Further compounding the gravity of his legal predicament, subsequent reports from Dutch media outlets such as RTL have revealed that investigators are probing suspicions that van der Stap may have attempted to orchestrate murders abroad, a development that dramatically broadens the scope of the criminal case against him.
The Odido Breach and ShinyHunters’ Defiant Response
The Dutch police’s focus on the broader ShinyHunters network intensified following a sophisticated social engineering attack in February 2026 against Odido, the Netherlands’ largest mobile telecommunications provider. In that intrusion, a native Dutch-speaking operative tricked an employee into authenticating through a spoofed portal, enabling the group to exfiltrate sensitive data concerning more than 6.2 million citizens.
Authorities recently released audio recordings of the telephone social engineering call, asking the public for assistance in identifying the speaker. In response, ShinyHunters publicly confirmed that the individual in the audio recording is a core member of their collective. In a defiant statement issued to regional media, the group vowed to support their detained comrade financially and legally while dismissing the competency of Dutch law enforcement in volatile terms.
Despite the bravado, the arrest of van der Stap and the exposure of operational infrastructure have deeply rattled the collective, prompting an aggressive retaliatory posture that crossed international boundaries and targeted formidable institutional adversaries.
Escalation: The FBI Portal Compromise and Cl0p Extortion
In the immediate wake of van der Stap’s detention, the remaining architects of ShinyHunters launched an unusually brazen wave of attacks designed to demonstrate operational resilience and punish investigators. Chief among these was a high-profile breach of the FBI’s employment application portal, apply.fbijobs.gov.

According to joint reports by specialized cybersecurity journalists and threat intelligence firms, the breach compromised sensitive personal identifiable information (PII) belonging to more than 5,000 individuals, including Social Security numbers, job classifications, and sensitive medical and psychological evaluation files of personnel assigned to critical national security units, such as major cybercrime divisions and foreign threat intelligence squads.
The intrusion was facilitated through the mass exploitation of a zero-day vulnerability (tracked as CVE-2026-35273) residing within Oracle PeopleSoft, an enterprise human resources and payroll software-as-a-service platform widely utilized across global industries. Although Oracle quickly issued patches, and security firms like Mandiant deployed mitigation web application firewall (WAF) rules, ShinyHunters bypassed these defenses using sophisticated URL-encoding tricks. Google Threat Intelligence Group and Mandiant confirmed that the campaign successfully compromised dozens of systems across healthcare, government, higher education, and technology sectors.
Significantly, the digital fingerprints left at the scene of the FBI portal hack featured an ASCII art rendition of the Pokémon character Umbreon, alongside a mocking proclamation that the systems had been seized. Security analysts suggest that this branding was deliberately utilized by rival faction leaders within the syndicate to implicate van der Stap or shift the blame amidst internal power struggles.
Internal Strife and the Rise of "Rey"
The aggressive pivot toward high-risk, high-reward targets like the FBI reflects a profound internal restructuring within the upper echelons of the cybercrime underworld. Intelligence sources indicate that leadership of ShinyHunters was recently subsumed by a teenage cybercriminal from Amman, Jordan, known by the alias “Rey.” Rey operates as a prominent figure within the "ScatteredLapsussHunters" (SLSH) alliance—a volatile amalgamation of operatives drawn from notorious prior syndicates including Scattered Spider, LAPSUS$, and original ShinyHunters cells.
The merger between these factions was initially forged to monetize credentials harvested by supply-chain hacking cells like TeamPCP. However, the partnership quickly devolved into mutual recriminations after security researchers—secretly funneling compromised credentials directly to cloud providers such as Amazon and Microsoft—neutralized the stolen keys before they could be fully monetized. Internal friction over financial payouts and brand control created deep animosity between Rey and veteran hackers like van der Stap.

Following the FBI hack, Rey utilized social media channels to taunt both law enforcement and rival cybercrime organizations, including the notorious Russian-speaking ransomware syndicate Cl0p, further illustrating the chaotic and unpredictable nature of modern digital syndicates operating without traditional geographical or ideological constraints.
Broader Implications and International Enforcement
The rapid sequence of events—culminating in van der Stap’s arrest, the catastrophic exposure of federal personnel data, and the aggressive public posture of international hackers—highlights the structural vulnerabilities inherent in modern digital supply chains and enterprise administrative software. Cybersecurity analysts project that ShinyHunters and its associated cells are on track to amass near-record extortion revenues, underscoring the limitations of conventional defensive postures against persistent, highly agile adversaries.
Law enforcement agencies are responding with heightened cross-border collaboration. In the wake of the arrests in the Netherlands and Australia, FBI Cyber Division Assistant Director Brett Leatherman issued a direct warning to remaining members of the ShinyHunters collective. Emphasizing that seized infrastructure and cooperative defendants provide unprecedented visibility into illicit networks, Leatherman urged remaining operatives to surrender voluntarily.
As Pepijn van der Stap prepares to face the Rotterdam District Court to address charges that now span complex data extortion and potential conspiracy to commit murder, the global cybersecurity community watches closely. The unfolding case serves as both a landmark victory for international law enforcement cooperation and a stark reminder of the volatile, high-stakes nature of contemporary cyber warfare.












