The recent apprehension of 24-year-old Dutch national Pepijn van der Stap by authorities in the Netherlands has sent shockwaves through the global cybersecurity landscape, triggering a series of retaliatory digital offensives that have targeted some of the world’s most sensitive institutions. Van der Stap, a previously convicted cybercriminal who operated under the alias "Umbreon," was taken into custody around September 16, 2026, on suspicion of facilitating large-scale data thefts and extortion schemes on behalf of the prolific hacker collective known as ShinyHunters.

The arrest has acted as a catalyst for a dramatic shift in the operational behavior of ShinyHunters. In the days following the detention, the group pivoted from its established pattern of corporate data theft to high-stakes political and security-focused disruptions. Most notably, the syndicate claimed responsibility for breaching the Federal Bureau of Investigation’s (FBI) job application portal, exposing the personal identifiable information (PII) of thousands of officials, and engaged in a brazen extortion attempt against the notorious Russian ransomware group, Cl0p. This volatility underscores a dangerous new phase in the lifecycle of modern cyber-syndicates, where the capture of a key operative does not signal the dissolution of a group, but rather the activation of its most aggressive elements.

A Portrait of the "Jekyll and Hyde" Hacker

Pepijn van der Stap, a resident of Almere and Lelystad, represents a complex archetype in the world of modern cybercrime: the dual-life digital operative. In 2023, he was convicted for his involvement in a massive string of data thefts that prosecutors estimated generated between €1.5 million and €2.7 million in illicit gains. During his trial, van der Stap offered a candid, if unsettling, window into his motivations, describing his life as a "Dr. Jekyll and Mr. Hyde" existence.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

By day, van der Stap maintained the veneer of a legitimate professional, serving as a software engineer for the Amsterdam-based cybersecurity firm Hadrian and volunteering his technical expertise for the Dutch Institute for Vulnerability Disclosure (DIVD). By night, however, he assumed the identity of "Umbreon," a handle synonymous with the trade of stolen databases on dark-web forums such as RaidForums and Breached. Following his initial conviction, he was sentenced to four years in prison—one of which was suspended—and was released in December 2025.

In a September 2026 interview with KrebsOnSecurity, van der Stap insisted he was a reformed individual attempting to make amends for his past, currently employed as an offensive security lead at Neo Security. However, his abrupt silence following that interview coincided precisely with his detention by Dutch authorities. The arrest, confirmed by police, saw investigators seizing digital assets and hardware from his residence, marking the end of his brief and controversial attempt at institutional rehabilitation.

The Rise of the SLSH Coalition and the "Rey" Factor

The current turmoil surrounding ShinyHunters is not merely a reaction to the loss of a member; it is reflective of a wider power struggle within the dark-web ecosystem. Intelligence analysts point to the influence of "Rey," a teenage cybercriminal based in Amman, Jordan, who has emerged as a central figure in the newly formed alliance known as ScatteredLapsussHunters (SLSH). This group represents a fusion of three historically significant threat actors: Scattered Spider, LAPSUS$, and ShinyHunters.

Evidence suggests that the recent, uncharacteristically aggressive attacks—specifically the defacement of the FBI portal—were orchestrated by Rey to consolidate power and, potentially, to frame van der Stap. The inclusion of the "Umbreon" Pokémon avatar in the FBI site’s defacement was, according to multiple security sources, a calculated "false flag" designed to draw the ire of law enforcement toward the Dutch suspect while simultaneously asserting the dominance of the SLSH coalition.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

This internal conflict stems from a failed partnership earlier in 2026 between SLSH and the supply-chain hacking group TeamPCP. The alliance, intended to monetize stolen credentials from global code supply chains, collapsed after ShinyHunters reportedly went "rogue," utilizing TeamPCP’s stolen data for its own extortion campaigns without distributing the agreed-upon shares. The resulting friction, combined with the intervention of security firms like Mandiant—which fed stolen credentials to major cloud providers to invalidate them—has created a climate of desperation and paranoia within the hacker collective.

Chronology of Escalation: February to September 2026

The trajectory of ShinyHunters throughout 2026 highlights an increasingly sophisticated approach to social engineering and zero-day exploitation:

  • February 2026: A native Dutch-speaking member of ShinyHunters successfully executes a social engineering attack against Odido, the Netherlands’ largest mobile telecommunications provider. The breach results in the theft of data pertaining to 6.2 million Dutch citizens.
  • June 2026: ShinyHunters begins exploiting a zero-day vulnerability (CVE-2026-35273) in Oracle’s PeopleSoft platform, a critical tool for HR and payroll management.
  • August 2026: The Australian Federal Police arrest two leaders of TeamPCP, thinning the ranks of the supply-chain hacking ecosystem and further destabilizing the fragile alliances between various groups.
  • September 9, 2026: Pepijn van der Stap gives an interview claiming to be a reformed security professional.
  • September 16, 2026: Dutch authorities arrest van der Stap.
  • Late September 2026: ShinyHunters retaliates by attacking the FBI’s job portal and taunting the Cl0p ransomware group on social media, while simultaneously launching a mass-exploitation campaign across multiple global industries via the PeopleSoft vulnerability.

Technical Implications and Security Vulnerabilities

The breach of the FBI’s job portal serves as a case study in the dangers of unpatched enterprise software. Security researchers at Mandiant and Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters utilized a URL-encoding technique to bypass web application firewall (WAF) rules that had been implemented to mitigate the CVE-2026-35273 vulnerability.

This move highlights a critical failure point in modern cybersecurity: the lag between the discovery of a vulnerability and the implementation of effective, non-bypassable mitigations. Despite Oracle’s rapid release of a patch, the sheer scale of the PeopleSoft deployment across higher education, healthcare, and government sectors left a vast surface area for the attackers to exploit. As of late September, Mandiant reported that ShinyHunters is on track to extract nearly $100 million in extortion payments for the 2026 calendar year, a figure that dwarfs their previous earnings and cements their status as a tier-one threat actor.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Official Responses and the Broader Threat Landscape

The Dutch police have been notably proactive, publicly appealing for assistance in identifying the voice of the operative who compromised Odido. Their success in detaining van der Stap demonstrates a growing capacity for international law enforcement to bridge the gap between digital aliases and physical identities. In an official statement following the arrest, the police confirmed that the suspect is scheduled for a court appearance on September 29, 2026.

However, the response from ShinyHunters itself has been one of defiance. In a statement provided to the NL Times, the group openly mocked the Dutch police, labeling them "incompetent" and "irrelevant," while pledging their full support to the arrested member. This rhetoric marks a shift toward a more political, confrontational stance against national governments, moving away from the purely profit-driven motives that characterized the earlier years of the group’s existence.

Conclusion: The Future of Cyber-Syndicates

The situation involving Pepijn van der Stap and the subsequent actions of the ShinyHunters/SLSH alliance underscore a grim reality for cybersecurity defenders. The professionalization of these groups, their willingness to target high-level government infrastructure, and their ability to absorb the loss of individual members suggest that the threat is not waning.

As groups like SLSH continue to merge and compete, the digital economy faces a period of heightened risk. The ability of a teenager in Jordan to influence the tactical decisions of a group based in Europe, while simultaneously sabotaging the operations of a Russian ransomware gang, indicates that the "geography" of cybercrime has become entirely untethered from traditional borders. For organizations and governments alike, the focus must now shift from reactive patching to proactive, intelligence-led defense strategies that account for the volatile and often personal vendettas that now drive the world’s most dangerous hacking syndicates.

Leave a Reply

Your email address will not be published. Required fields are marked *