{"id":26284,"date":"2026-09-28T11:01:41","date_gmt":"2026-09-28T19:01:41","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/28\/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation\/"},"modified":"2026-09-28T11:01:41","modified_gmt":"2026-09-28T19:01:41","slug":"dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/28\/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation\/","title":{"rendered":"Dutch Police Arrest \u2018Reformed\u2019 Hacker in Shiny Hunters Investigation"},"content":{"rendered":"<p>Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group <strong>ShinyHunters<\/strong>. In the days immediately following the suspect\u2019s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the <strong>FBI<\/strong> and extorting the Russian ransomware group <strong>Cl0p<\/strong>.<\/p>\n<p>According to three sources familiar with the matter, the Dutch man arrested by authorities this month is <strong>Pepijn van der Stap<\/strong>, a convicted cybercriminal from Almere and Lelystad in the Netherlands. Van der Stap was previously convicted in 2023 in connection with a string of data thefts and extortions that prosecutors said earned between \u20ac1.5 million and \u20ac2.7 million.<\/p>\n<p>At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle \u201c<strong>Umbreon<\/strong>\u201d to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached. By day, however, van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup <strong>Hadrian<\/strong>, while volunteering at the <strong>Dutch Institute for Vulnerability Disclosure<\/strong> (DIVD), a nonprofit security research group.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74364\" style=\"width: 759px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74364\" height=\"852\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/09\/umbreon-nl-rf.png\" width=\"749\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74364\">Pepijn van der Stap\u2019s alter ego \u201cUmbreon\u201d selling a database on RaidForums, offering information on 2.3 million people from The Netherlands in September 2021. This user\u2019s avatar is a depiction of the Pokemon character Umbreon. Image: KELA.<\/p>\n<\/div>\n<p>Van der Stap confessed to his data theft and extortion activity, and was sentenced to four years in prison (one of which was suspended). During his trial, van der Stap opted to remain in custody for a time rather than at home, saying he could not find better treatment on the outside for his ongoing psychological issues, which he claimed included PTSD related to childhood trauma. He was released from prison in December 2025.<\/p>\n<p>In an interview with KrebsOnSecurity on September 9, 2026, Van der Stap cast himself as a reformed hacker who was trying to turn his life around and make a positive contribution to society. Van der Stap is currently employed as offensive security lead at the Dutch company <strong>Neo Security<\/strong>, which did not respond to requests for comment.<\/p>\n<p>Van der Stap said he was still dealing with civil lawsuits and restitution related to his previous cybercrime victims, and that he was trying his best to make amends. But not long after that interview, the Dutch hacker abruptly stopped replying to messages. Efforts by others close to him also repeatedly failed to elicit a response for the past two weeks.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74374\" style=\"width: 759px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74374\" height=\"820\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/09\/pvds-li.png\" width=\"749\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74374\">The LinkedIn profile for Pepijn van der Stap.<\/p>\n<\/div>\n<p>According to two sources with knowledge of the matter, Van der Stap was arrested by Dutch authorities on or around September 16, and has been held in custody for questioning since. One source said a colleague of theirs personally witnessed Dutch authorities carting items out of Van der Stap\u2019s residence.<\/p>\n<p>Authorities in the Netherlands have been <a href=\"https:\/\/www.politie.nl\/nieuws\/2026\/september\/7\/11-stem-van-verdachte-odido-hack-te-horen-in-opsporing-verzocht.html\" rel=\"noopener\" target=\"_blank\">asking the public for help<\/a> in identifying the voice in a recorded telephone call from February 2026 in which a native Dutch-speaking ShinyHunters member social engineered their way into <strong>Odido<\/strong>, the nation\u2019s largest mobile telecommunications provider. In that intrusion, ShinyHunters tricked an Odido employee into logging in at a spoofed website, and then used that access to steal data on more than 6.2 million Dutch people.<\/p>\n<p>Responding to Dutch news media, ShinyHunters confirmed that the suspect in the audio clip is indeed a member of the hacker collective.<\/p>\n<p>\u201cOur team member has our full support \u2013 emotionally, mentally, and financially,\u201d the hackers said. \u201cEverything has been arranged, including a criminal defense lawyer. We do not look down on our staff and members; we take excellent care of them,\u201d reads a statement ShinyHunters shared with <a href=\"https:\/\/nltimes.nl\/2026\/09\/08\/shinyhunters-lawyer-police-release-audio-clip-suspect-odido-hack\" rel=\"noopener\" target=\"_blank\">NL Times<\/a>. It remains unclear if the Dutch police have matched the Odido caller to a confirmed real-life identity. The Dutch police unit handling the Odido incident did not respond to requests for comment.<\/p>\n<p>The group also lashed out at the authorities in the Netherlands. \u201cThe Dutch police will need all the luck in the world \u2013 and everyone\u2019s prayers \u2013 if they want to catch him before we carry out another large-scale data theft in the Netherlands,\u201d the ShinyHunters statement said. \u201cFrankly, the Dutch police are a big joke; they are incapable of doing anything. Incompetent. Irrelevant. Unimportant. Useless.\u201d<span id=\"more-74341\"><\/span><\/p>\n<h2>FBI, CL0P HACKS<\/h2>\n<p>Just days after sources say Van der Stap was detained by Dutch authorities, ShinyHunters claimed credit for an unusually brazen breach at the FBI\u2019s job application site apply.fbijobs.gov. According to <a href=\"https:\/\/archive.is\/IQgWr\" rel=\"noopener\" target=\"_blank\">reporting from 404 Media<\/a>, the data stolen from the FBI site includes Social Security numbers and <a href=\"https:\/\/www.bbc.com\/news\/articles\/cw62me2vlj07o\" rel=\"noopener\" target=\"_blank\">personal information<\/a> on more than 5,000 officials.<\/p>\n<p>404 Media and <a href=\"https:\/\/archive.is\/IQgWr\" rel=\"noopener\" target=\"_blank\">Reuters reported<\/a> the FBI data included each person\u2019s job title or team, such as special agent, threat intake examiner, major cybercrimes unit, and those investigating cyber threats from foreign state-backed actors. Reuters examined documents shared by ShinyHunters and found they included sensitive psychiatric and medical files of FBI staff. The FBI issued <a href=\"https:\/\/www.fbi.gov\/news\/press-releases\/fbi-statement-on-compromise-of-fbijobsgov-portal-and-alleged-impact-to-fbi-employee-pii?utm_campaign=email-Immediate&amp;utm_medium=email&amp;utm_source=national-press-releases&amp;utm_content=%5B2249041%5D-%2Fnews%2Fpress-releases%2Ffbi-statement-on-compromise-of-fbijobsgov-portal-and-alleged-impact-to-fbi-employee-pii\" rel=\"noopener\" target=\"_blank\">a brief statement<\/a> confirming the hack.<\/p>\n<p>ShinyHunters said it gained access to the FBI site and other victims by exploiting a recently patched vulnerability (CVE-2026-35273) in <strong>PeopleSoft<\/strong>, a software-as-a-service platform from the software giant <strong>Oracle<\/strong> that is broadly used by companies to manage hiring and human resources, benefits and payroll. Oracle quickly issued a fix for the Peoplesoft vulnerability that ShinyHunters reportedly began exploiting as a zero-day in June, and at the time Mandiant released web application firewall rules intended for organizations who couldn\u2019t apply the security update quickly enough.<\/p>\n<p>But on Friday, BleepingComputer reported that ShinyHunters <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks\/\" rel=\"noopener\" target=\"_blank\">used a URL-encoding trick<\/a> to bypass Mandiant\u2019s suggested web application firewall rules designed to mitigate the threat from the PeopleSoft flaw. In <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft\" rel=\"noopener\" target=\"_blank\">a report<\/a> released Sept. 25, security experts at <strong>Mandiant<\/strong> and the <strong>Google Threat Intelligence Group<\/strong> (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.<\/p>\n<p>Van der Stap\u2019s former hacker alias Umbreon was hidden in plain sight throughout the imagery ShinyHunters used to spread news about the FBI hack: The defacement image that ShinyHunters left behind on the hacked FBI jobs site included an ASCII art design featuring the Pokemon character Umbreon. The message at the top read, \u201cThis site has been seized by ShinyHunters. rooting your systems since \u201919 ;)\u201d The image appears identical to a defacement message ShinyHunters used in their <a href=\"https:\/\/reliaquest.com\/blog\/the-eeveelution-of-shinyhunters-from-data-leaks-to-extortions\/\" rel=\"noopener\" target=\"_blank\">2020 hack<\/a> of the English-language cybercrime community Hackforums.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74359\" style=\"width: 757px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74359\" height=\"744\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/09\/fbi-umbreon-sh.png\" width=\"747\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74359\">The defacement message left by ShinyHunters on the FBI jobs site included an ASCII art rendition of the Pokemon character Umbreon. Image: Bleeping Computer.<\/p>\n<\/div>\n<p>Multiple sources close to the ShinyHunters investigation said the group\u2019s recent risky attacks against the FBI and one of Russia\u2019s most venerated ransomware groups amounted to a major pivot away from the more measured tenor of the hacking gang\u2019s operations. Those sources said the sudden shift came about after ShinyHunters was taken over by <a href=\"https:\/\/krebsonsecurity.com\/2025\/11\/meet-rey-the-admin-of-scattered-lapsus-hunters\/\" rel=\"noopener\" target=\"_blank\">a teenage cybercriminal from Amman, Jordan<\/a> who goes by the nickname <strong>Rey<\/strong> and operates as part of a cybercrime group called <strong>ScatteredLapsussHunters <\/strong>(SLSH), which experts say is an amalgamation of three hacking groups \u2014 <a href=\"https:\/\/krebsonsecurity.com\/?s=scattered+spider\" rel=\"noopener\" target=\"_blank\"><strong>Scattered Spider<\/strong><\/a>, <a href=\"https:\/\/krebsonsecurity.com\/?s=lapsus%24\" rel=\"noopener\" target=\"_blank\"><strong>LAPSUS$<\/strong><\/a> and <a href=\"https:\/\/krebsonsecurity.com\/?s=shiny+hunters\" rel=\"noopener\" target=\"_blank\"><strong>ShinyHunters<\/strong><\/a>.<\/p>\n<p>Those sources said Rey had an ongoing beef with the Dutch hacker over control of the ShinyHunters brand and data, and that the inclusion of the oversized Umbreon Pokemon image in the FBI jobs site defacement was likely an attempt by Rey to pin the hack on the Dutchman.<\/p>\n<p>Rey was <a href=\"https:\/\/www.kelacyber.com\/blog\/hellcat-hacking-group-unmasked-rey-and-pryx\/\" rel=\"noopener\" target=\"_blank\">first publicly identified<\/a> by the cybersecurity firm <strong>KELA<\/strong> in March 2025. In advance of our <a href=\"https:\/\/krebsonsecurity.com\/2025\/11\/meet-rey-the-admin-of-scattered-lapsus-hunters\/\" rel=\"noopener\" target=\"_blank\">November 2025 profile of Rey<\/a>, KrebsOnSecurity messaged Rey\u2019s father and asked for permission to interview his teenage son. Rey\u2019s dad merely forwarded the message to his son, who admitted to participating in ransomware attacks and said he was trying to extricate himself from the SLSH hacker group.<\/p>\n<h2>BLAMING UMBREON<\/h2>\n<p>Immediately after news of the FBI jobs site hack was picked up in the media, Rey\u2019s main account on Twitter\/X (Ryan Moran\/@rmoskovy) was taunting the Cl0p ransomware group and the FBI, crudely depicting them as the twin towers in New York being struck by planes labeled \u201ccl0p drama\u201d and \u201cfbi breach claim.\u201d In the foreground of the city is the giant Pokemon figure of Umbreon.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74362\" style=\"width: 637px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"size-full wp-image-74362\" height=\"843\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/09\/rey-cl0p-fbi.png\" width=\"627\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74362\">A taunting meme uploaded to Twitter\/X by Rey\u2019s now-defunct account on Sept. 22. A giant float-sized version of the Pokemon character Umbreon can be seen in the bottom left.<\/p>\n<\/div>\n<p>On Sept. 24, KrebsOnSecurity again contacted Rey\u2019s dad, asking to interview him and his son for a story on Rey\u2019s apparent ascendency as the head of ShinyHunters. Just hours after that request, Rey deleted his longtime Twitter\/X account. Meanwhile, Rey\u2019s dad, who works for the Royal Jordanian Airlines, has failed to respond to a half-dozen emailed requests for comment about his son\u2019s alleged activities.<\/p>\n<p>Where does the bad blood between SLSH and ShinyHunters come from? According to <a href=\"https:\/\/www.wired.com\/story\/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang\/\" rel=\"noopener\" target=\"_blank\">a story in Wired<\/a> this month, ShinyHunters and SLSH members briefly partnered earlier this year to help better monetize important stolen credentials collected by <strong>TeamPCP<\/strong>, an upstart group that was having great success compromising global code supply chains with malicious software but hadn\u2019t been able to profit much from their stolen data (two alleged leaders of TeamPCP <a href=\"https:\/\/krebsonsecurity.com\/2026\/08\/two-alleged-teampcp-hackers-arrested-in-australia\/\" rel=\"noopener\" target=\"_blank\">were arrested last month in Australia<\/a>, and in an interview the TeamPCP leader claimed they made just $20,000).<\/p>\n<p>The Wired story noted how Mandiant had infiltrated TeamPCP and was secretly responsible for having the crime group\u2019s stolen credentials burned so quickly: Mandiant was secretly feeding those credentials to the major cloud providers like Amazon and Microsoft, who quickly invalidated the stolen keys. Meanwhile, the formerly cooperating hacker groups began to blame one another for causing the credentials to become worthless.<\/p>\n<p>Wired\u2019s <strong>Andy Greenberg<\/strong> reported that a few weeks after partnering with TeamPCP, \u201cShinyHunters went rogue, carrying out its own extortions with TeamPCP\u2019s credentials but without giving the supply-chain hackers their cut.\u201d<\/p>\n<p>Mandiant researcher <strong>Austin Larsen<\/strong> told KrebsOnSecurity earlier this month that ShinyHunters has been enjoying a successful extortion spree so far this year, and is on track to pull in nearly $100 million in extortion payments from cybercrime victims in 2026.<\/p>\n<p>Van der Stap claims he was never motivated by money and that his earlier hacker activity was driven by a desire to have the world\u2019s most complete collection of stolen databases. Speaking with reporters from Bloomberg in 2024, Van der Stap said that singular focus in turn fueled his desire to carry out cyberattacks.<\/p>\n<p>\u201cThe hacking was very easy for me, and it wasn\u2019t a compulsion,\u201d he <a href=\"https:\/\/archive.ph\/K47wB#selection-1447.0-1447.321\" rel=\"noopener\" target=\"_blank\">told Bloomberg<\/a>. \u201cMy habit was collecting. Collecting data, organizing data, downloading data, creating folders.\u201d<\/p>\n<p>DIVD, the nonprofit security research group where Van der Stap previously served as a volunteer, <a href=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:activity:7508986131779088384\/\" rel=\"noopener\" target=\"_blank\">disclosed on LinkedIn last week<\/a> that the organization was dealing with an internal cybersecurity incident that appears to have involved the malicious use of artificial intelligence. DIVD has released few details about that incident, but a spokesperson for the nonprofit told KrebsOnSecurity it does not appear related to ShinyHunters, nor are there any signs the matter involves the work of a previous volunteer.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker groupShinyHunters. In the days immediately following the suspect\u2019s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from theFBIand extorting the Russian ransomware groupCl0p.According to three sources familiar with the matter, the Dutch man arrested by authorities this month isPepi<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10642],"tags":[],"class_list":["post-26284","post","type-post","status-publish","format-standard","hentry","category-krebs"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26284","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26284"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26284\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26284"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26284"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26284"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}