Shadows of the Hive: The Fall of ‘Umbreon,’ the Ascent of ‘Rey,’ and ShinyHunters’ Global Cyber War

Main page › Cyber Security & Privacy › Shadows of the Hive: The…
From ZizzMedia, the free news encyclopedia
Shadows of the Hive: The Fall of ‘Umbreon,’ the Ascent of ‘Rey,’ and ShinyHunters’ Global Cyber War
Shadows of the Hive: The Fall of ‘Umbreon,’ the Ascent of ‘Rey,’ and ShinyHunters’ Global Cyber War
Published: 8 October 2026
Author: Iffa Jayyana
Category: Cyber Security & Privacy
Read time: 7 min read
Words: 1,318

Executive Overview

The global cybersecurity landscape has been rocked by an extraordinary sequence of events linking the arrest of a notorious Dutch cybercriminal to a massive escalation in international digital warfare. Authorities in the Netherlands have taken 24-year-old Pepijn van der Stap into custody on suspicion of coordinating data thefts and extortion schemes for the prolific and destructive hacker collective known as ShinyHunters.

Van der Stap—previously convicted in late 2023 for a multi-million-euro data-trafficking spree carried out under the online moniker “Umbreon”—had ostensibly attempted to rehabilitate his image. By day, he worked as an offensive security lead at a Dutch cybersecurity firm; by night, he claimed to be reforming. However, his mid-September 2026 arrest shattered that facade, triggering immediate and violent shockwaves across the global cyber underground.

In the immediate wake of van der Stap’s detention, the remaining members of ShinyHunters launched an aggressive, highly publicized campaign of retaliation. This campaign included an unprecedented cyberattack on the FBI’s job application portal (apply.fbijobs.gov), exposing the personal identifiable information (PII) and sensitive medical files of thousands of federal personnel, as well as an audacious extortion campaign targeting the Russian ransomware syndicate Cl0p.

Behind this sudden, reckless pivot lies a turbulent internal power struggle. Intelligence points to a hostile takeover of the ShinyHunters brand by a teenage hacker from Jordan known as Rey, operating within an amalgamation of elite cybercrime factions dubbed ScatteredLapsussHunters (SLSH). As international law enforcement closes in—culminating in public warnings from the FBI and shocking new allegations from Dutch prosecutors accusing van der Stap of commissioning murders—the global cybersecurity community finds itself confronting an unprecedented nexus of insider threats, state-sponsored cyber espionage, and splintered cybercrime syndicates.


Detailed Chronology

The Dr. Jekyll and Mr. Hyde of Almere

To understand the current crisis, investigators must trace the dual life of Pepijn van der Stap. In his 2023 trial, van der Stap confessed to running an underground empire of data theft and extortion under the handle “Umbreon”—a nod to the Pokémon character that would later become a recurring motif in high-profile cyberattacks. Operating primarily on English-language hacking forums like RaidForums and Breached, van der Stap compiled massive troves of stolen databases, accumulating illicit revenues estimated between €1.5 million and €2.7 million.

Remarkably, while running these operations, van der Stap maintained a respectable day job as a software engineer for Amsterdam-based cybersecurity startup Hadrian and volunteered for the Dutch Institute for Vulnerability Disclosure (DIVD). Sentenced to four years in prison (with one year suspended), van der Stap served time until his release in December 2025.

In a September 9, 2026 interview, van der Stap painted a picture of a reformed man trying to make amends through restitution and his work as an offensive security lead at Neo Security. However, this narrative abruptly dissolved just a week later. According to sources close to the investigation, Dutch authorities raided van der Stap’s residence on or around September 16, carting away hardware and placing him under indefinite arrest.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

The Odido Intrusion and Police Public Pleas

Van der Stap’s arrest did not occur in a vacuum. Dutch law enforcement had been actively hunting for the native Dutch-speaking voice behind a February 2026 social engineering attack against Odido, the Netherlands’ largest mobile telecommunications provider. Tricking an employee into authenticating through a spoofed website, ShinyHunters compromised the data of over 6.2 million Dutch citizens.

When police publicly released audio recordings of the Odido extortionist, ShinyHunters unapologetically claimed the suspect as one of their own. In a statement to the NL Times, the group vowed emotional, mental, and financial support for their detained member while issuing vitriolic insults toward Dutch authorities, calling them "incompetent" and "irrelevant."

The FBI Breach and the Oracle PeopleSoft Zero-Day Campaign

Just days after van der Stap’s detention, ShinyHunters executed one of the most brazen attacks in federal law enforcement history: the infiltration of the FBI’s job application portal.

Utilizing a recently patched vulnerability (CVE-2026-35273) within Oracle PeopleSoft, the hackers exfiltrated Social Security numbers and personnel profiles belonging to over 5,000 FBI officials. The compromised data included sensitive assignments—such as special agents, major cybercrimes investigators, and counterintelligence examiners tracking foreign state actors—alongside confidential psychiatric and medical records.

Security firms Mandiant and the Google Threat Intelligence Group (GTIG) subsequently revealed that ShinyHunters had deployed url-encoding techniques to bypass web application firewall (WAF) mitigations, mass-exploiting PeopleSoft vulnerabilities across diverse sectors including healthcare, education, agriculture, and government.

Significantly, the defacement page left on the FBI jobs portal featured an ASCII art rendering of Umbreon alongside a taunting message: "This site has been seized by ShinyHunters. rooting your systems since ’19 ;)."


Supporting Context & Metrics

The Rise of ‘Rey’ and the SLSH Takeover

Security researchers and intelligence sources confirm that ShinyHunters’ abrupt shift from quiet, targeted data harvesting to chaotic, high-risk global attacks stems from a leadership coup. The group was effectively commandeered by Rey, a teenage cybercriminal based in Amman, Jordan. Rey operates within ScatteredLapsussHunters (SLSH), a hybrid conglomerate combining remnants of Scattered Spider, LAPSUS$, and ShinyHunters.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

According to intelligence sources, Rey harbored a fierce personal feud with van der Stap over the control of the ShinyHunters brand and its vast data repositories. The inclusion of the oversized Umbreon Pokémon imagery in the FBI portal defacement was not a tribute, but a calculated framing maneuver designed by Rey to pin the fallout squarely on the detained Dutch hacker.

The Supply-Chain Collapse and the $100 Million Pace

This internal warfare was exacerbated by a short-lived partnership earlier in the year with TeamPCP, an upstart group specializing in code supply chain compromises. As detailed by Wired, Mandiant operatives had covertly infiltrated TeamPCP, systematically burning stolen credentials by feeding them directly to cloud providers like Amazon and Microsoft.

While TeamPCP walked away with a paltry $20,000, ShinyHunters went rogue, leveraging those credentials to fuel an unprecedented extortion spree. According to Mandiant analyst Austin Larsen, ShinyHunters is currently on track to extract nearly $100 million in extortion payments throughout 2026.


Official Statements

The fallout from the dual crises of the van der Stap arrest and the FBI breach prompted high-level responses from international authorities:

  • The FBI Cyber Division: In a video address, Assistant Director Brett Leatherman thanked Dutch law enforcement partners and issued a direct ultimatum to the remaining members of ShinyHunters:

    "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out to us while the choice is still yours."

  • The Dutch National Police: Confirming the arrest of the 24-year-old suspect, the Dutch police announced that van der Stap would face the Rotterdam District Court to answer for his involvement in the ShinyHunters network.

    Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security
  • ShinyHunters Collective: Dismissing law enforcement pressure, the group released defiant statements across encrypted channels, maintaining that their arrested comrade enjoys full legal and financial backing from the organization.


Future Outlook

As the investigation enters late September 2026, the case has taken an even darker turn. Dutch news outlet RTL reported that investigators now suspect van der Stap of attempting to orchestrate at least two murders abroad—representing a terrifying evolution from digital extortion to physical violence.

Meanwhile, van der Stap’s scheduled court appearance at the Rotterdam District Court is expected to shed light on the inner workings of modern cybercrime syndicates. For international law enforcement, the operational disruption caused by the Dutch police raid provides a critical wedge to fracture the SLSH and ShinyHunters alliances.

However, as long as decentralized figures like Rey remain operational across international jurisdictions, and as long as zero-day vulnerabilities in enterprise software like Oracle PeopleSoft remain ripe for exploitation, the global threat ecosystem will continue to feel the tremors originating from the arrest of the hacker once known as Umbreon.

Related News

Leave a Reply / Join Discussion

Your email address will not be published. Required fields are marked with *