Technology

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Krebs on Security September 28, 2026 3 views
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Advertisement

Dutch authorities have arrested Pepijn van der Stap, a 23-year-old convicted cybercriminal, on suspicion of aiding the prolific hacker group ShinyHunters in data thefts and extortions. According to sources familiar with the matter, van der Stap was detained on or around September 16 and has been held in custody for questioning since. The arrest occurred shortly after van der Stap gave an interview to KrebsOnSecurity in which he described himself as a reformed hacker attempting to make a positive contribution to society.

Van der Stap, from Almere and Leylstad, was previously convicted in 2023 for a series of data thefts and extortions that prosecutors stated generated between €1.5 million and €2.7 million. During his trial, he admitted to operating under the hacker handle “Umbreon” to extort victims and leak data on platforms such as RaidForums and Breached. At the time of his conviction, van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian and volunteering with the Dutch Institute for Vulnerability Disclosure. He was sentenced to four years in prison, one of which was suspended, and was released in December 2025.

In the days following the reported arrest, ShinyHunters escalated its operations significantly. The group claimed responsibility for a breach of the FBI’s job application site, apply.fbijobs.gov, stealing Social Security numbers and personal information on more than 5,000 officials. Reuters reported that the stolen documents included sensitive psychiatric and medical files, with job titles ranging from special agents to threat intake examiners. The FBI issued a brief statement confirming the hack. Additionally, ShinyHunters reportedly extorted the Russian ransomware group Cl0p during this period.

ShinyHunters stated that it exploited a recently patched vulnerability, CVE-2026-35273, in Oracle’s PeopleSoft platform, which is widely used for human resources and payroll management. The group reportedly began exploiting the flaw as a zero-day in June, before Oracle issued a fix. Mandiant subsequently released web application firewall rules to assist organizations unable to apply the security update immediately.

“Our team member has our full support – emotionally, mentally, and financially,” the hackers said in a statement to NL Times. “Everything has been arranged, including a criminal defense lawyer. We do not look down on our staff and members; we take excellent care of them.”

The group also directed sharp criticism at Dutch law enforcement, claiming the police were “incompetent” and “useless.” ShinyHunters warned that authorities would need “all the luck in the world” to apprehend the suspect before the group carried out another large-scale data theft in the Netherlands. This rhetoric followed Dutch police requests for public help in identifying a native Dutch-speaking ShinyHunters member who social engineered their way into Odido, the nation’s largest mobile telecommunications provider, in February 2026. That intrusion resulted in the theft of data belonging to more than 6.2 million Dutch people.

Van der Stap is currently employed as an offensive security lead at the Dutch company Neo Security, which did not respond to requests for comment. Prior to his disappearance from public view, van der Stap told KrebsOnSecurity he was dealing with civil lawsuits and restitution for his previous victims. However, he abruptly stopped replying to messages following the interview, and efforts by those close to him to contact him have failed for the past two weeks. It remains unclear whether Dutch police have definitively matched the Odido caller to van der Stap’s real-life identity.

<small>Source: Krebs on Security — read the original story there.</small>

How did this make you feel?

Never miss a story

Get the best of SpeakOX in your inbox. No spam, unsubscribe anytime.

Advertisement

Category
Technology

Advertisement