Executive Overview
In a dramatic convergence of international law enforcement, state-sponsored cyber espionage, and splintering criminal syndicates, Dutch authorities have arrested 24-year-old convicted cybercriminal Pepijn van der Stap. Known extensively within underground hacking forums by his digital handle “Umbreon,” van der Stap is suspected of playing a pivotal logistical and operational role in data thefts and extortion campaigns orchestrated by the prolific cybercrime collective ShinyHunters.
Van der Stap’s apprehension in mid-September triggered an immediate, volatile reaction across the global cyber underground. Within days of his detention, remaining elements of ShinyHunters—operating under a fractured leadership structure influenced by teenage cybercriminals—embarked on a high-stakes retaliatory spree. This escalation included an unprecedented breach of the Federal Bureau of Investigation’s (FBI) job application portal (apply.fbijobs.gov) and the extortion of the notorious Russian ransomware syndicate Cl0p.
The unfolding crisis highlights the volatile intersection between recidivist hackers, corporate dual-lives, and the geopolitical implications of modern supply-chain compromises. With investigators now probing allegations that link van der Stap to international murder-for-hire plots, and intelligence agencies like Mandiant and the Google Threat Intelligence Group (GTIG) tracking a massive Oracle PeopleSoft mass-exploitation campaign, the case represents one of the most complex geopolitical cyber operations of the decade.
Detailed Chronology: The Fall of ‘Umbreon’ and the FBI Breach
The Dr. Jekyll and Mr. Hyde of Almere
The saga of Pepijn van der Stap is a textbook case of underground dualism. Publicly, van der Stap maintained a respectable trajectory in the mainstream cybersecurity industry. By day, he worked as a software engineer for Amsterdam-based cybersecurity startup Hadrian and volunteered his technical expertise for the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research organization dedicated to public safety.
Behind closed doors, however, van der Stap operated as "Umbreon," a prolific extortionist and data broker who traded stolen institutional databases on English-language underground forums like RaidForums and Breached. His 2023 criminal trial revealed that his operations had harvested millions of euros, with prosecutors estimating his illicit enterprise earned between €1.5 million and €2.7 million.
During his late 2023 trial, van der Stap admitted to his crimes, attributing his descent into cybercrime to a compulsive desire to curate the world’s most comprehensive repository of stolen databases rather than monetary greed alone. He confessed to living a "Dr. Jekyll and Mr. Hyde" existence and was subsequently sentenced to four years in prison, with one year suspended. Preferring the controlled environment of a correctional facility to manage ongoing psychological health issues—including post-traumatic stress disorder (PTSD) stemming from childhood trauma—he remained incarcerated until his release in December 2025.
Rehabilitation and Recidivism
Following his release, van der Stap sought to cast himself as a reformed figure. In an interview with security journalist Brian Krebs on September 9, 2026, he spoke of making amends, satisfying civil restitution claims, and striving to contribute positively to society. At the time of the interview, he was employed as an offensive security lead at Dutch firm Neo Security.

However, this veneer of rehabilitation fractured abruptly in mid-September. Colleagues and journalists noted that van der Stap ceased all digital communications. Sources close to the matter confirmed that Dutch law enforcement detained van der Stap on or around September 16, executing a search of his residence and carting away digital evidence and hardware.
On September 29, the scope of the investigation expanded dramatically. Dutch news outlet RTL reported that investigators suspect van der Stap of attempting to orchestrate at least two murders abroad, allegedly issuing direct orders for the killings.
The Odido Intrusion and Law Enforcement Appeal
Van der Stap’s arrest was the culmination of an intensive dragnet led by Dutch police. Authorities had previously launched a public appeal seeking help to identify a native Dutch-speaking ShinyHunters member who executed a sophisticated social-engineering attack against Odido, the Netherlands’ largest mobile telecommunications provider, in February 2026.
By tricking an Odido employee into authenticating through a spoofed credential-harvesting website, the hacker exfiltrated sensitive data belonging to more than 6.2 million Dutch citizens. ShinyHunters later confirmed the suspect in the leaked audio clip was indeed a member of their collective, issuing a defiant statement promising financial and legal support while dismissing the Dutch police as "incompetent" and "useless."
The FBI Portal Hack and Oracle PeopleSoft Zero-Day Exploitation
The detention of van der Stap served as the catalyst for immediate retaliation. Days after his arrest, ShinyHunters claimed responsibility for a brazen breach of the FBI’s recruitment portal, apply.fbijobs.gov. According to investigations by 404 Media and Reuters, the breach compromised Social Security numbers, internal job classifications, specialized unit assignments (including major cybercrime units and foreign counterintelligence divisions), and sensitive medical and psychiatric files of over 5,000 personnel.
Forensic analysis revealed that the hackers leveraged a vulnerability (CVE-2026-35273) within Oracle PeopleSoft, a widely deployed enterprise human resources and payroll platform. Although Oracle moved quickly to patch the vulnerability—which ShinyHunters had been weaponizing as a zero-day since June—the group successfully bypassed web application firewall (WAF) mitigations recommended by Mandiant using advanced URL-encoding manipulation tricks.
In a signature piece of psychological warfare, the defacement page left on the FBI portal featured an ASCII art rendering of the Pokémon character Umbreon—van der Stap’s long-standing hacker moniker. The page declared: "This site has been seized by ShinyHunters. rooting your systems since ’19 ;)."

Supporting Context & Metrics: The Mechanics of the Syndicate
Leadership Shifts and the Rise of "Rey"
Security researchers tracking the evolution of ShinyHunters note that the group’s recent, hyper-aggressive operational tempo stems from a fundamental internal power shift. Control of the brand reportedly transitioned to a teenage cybercriminal from Amman, Jordan, known by the alias "Rey."
Rey operates within ScatteredLapsussHunters (SLSH), a hybrid criminal syndicate amalgamating tactics from Scattered Spider, LAPSUS$, and ShinyHunters. Intelligence firms such as KELA and Mandiant have tracked Rey’s rise through underground forums. Sources suggest that the inclusion of the oversized Umbreon imagery in the FBI portal defacement was an intentional maneuver by Rey to cast suspicion and pin the fallout of the high-risk federal breach directly onto the newly arrested Dutch hacker, with whom Rey held a documented feud.
Supply Chain Collusion and Financial Projections
The animosity between SLSH and traditional ShinyHunters factions traces back to an earlier, short-lived partnership with TeamPCP, an emerging supply-chain compromise gang. TeamPCP successfully compromised global software supply chains but struggled to monetize stolen institutional credentials.
When ShinyHunters and SLSH partnered with TeamPCP to monetize the data, operations quickly unraveled. Mandiant analysts secretly compromised TeamPCP’s infrastructure, burning the stolen credentials by feeding them directly to major cloud service providers like Amazon and Microsoft to invalidate them. Accusations flew between the allied criminal factions, with ShinyHunters ultimately going rogue and executing independent extortions using the contested credentials—cutting out TeamPCP entirely.
Despite internal friction and law enforcement pressure, financial tracking by Mandiant researcher Austin Larsen indicates that ShinyHunters remains on a historic financial trajectory, pacing toward nearly $100 million in cumulative extortion payouts for the year 2026.
Official Statements and Law Enforcement Responses
The international dimensions of the case have prompted high-level reactions from global cybersecurity agencies.
In a coordinated video address released by the FBI Cyber Division, Assistant Director Brett Leatherman formally thanked Dutch law enforcement partners for their decisive intervention and issued a direct ultimatum to the remaining members of ShinyHunters:

"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left," Leatherman stated. "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out to us while the choice is still yours."
Meanwhile, the Dutch Police confirmed the detention of the 24-year-old suspect via official channels on social media, announcing that van der Stap would face the Rotterdam District Court to answer for charges tied to the expansive ShinyHunters investigations.
Corporate entities affected by the wave of exploits—including Oracle, which issued rapid hotfixes for the PeopleSoft platform, and Neo Security, van der Stap’s most recent employer—have faced intense scrutiny regarding internal vetting processes and third-party software hardening.
Future Outlook
The arrest of Pepijn van der Stap and the subsequent digital retaliation by ShinyHunters mark a watershed moment in contemporary cybersecurity. Several critical trends are likely to define the landscape moving forward:
- Intensified Transnational Collaboration: The rapid information sharing between the FBI, Dutch National Police, Mandiant, and European cybercrime units demonstrates that law enforcement is increasingly capable of piercing the pseudonymous veils of elite extortion syndicates.
- Internal Fractures as an Enforcement Vector: As Assistant Director Leatherman highlighted, the arrest of key figures induces paranoia within decentralized chat groups. The internal warfare between Rey’s SLSH faction and traditional operatives creates exploitable intelligence gaps that investigators will likely weaponize.
- The Weaponization of Corporate Software: The mass exploitation of the Oracle PeopleSoft zero-day underlines the extreme vulnerability of enterprise human resources platforms. Threat actors are pivoting away from simple perimeter breaches toward deep supply-chain and HR software infiltration to harvest high-value credentials.
- Escalation of Kinetic Consequences: With investigative reports now surfacing regarding alleged murder-for-hire plots tied to van der Stap, the boundary between digital extortion and traditional violent crime continues to blur, cementing cybercrime syndicates as formal national security threats.
As van der Stap faces trial in Rotterdam and international warrants and investigations target the remaining nodes of the ShinyHunters and SLSH networks, the digital underworld faces an unprecedented level of scrutiny from global law enforcement coalitions determined to dismantle the infrastructure of modern corporate extortion.