Dutch hacker arrest intensifies ShinyHunters probe

Dutch authorities have arrested convicted cybercriminal Pepijn van der Stap on suspicion of aiding the prolific data-theft and extortion group ShinyHunters, a move that has coincided with a sharp escalation in the gang’s high-profile operations against government and corporate targets[2][5][9]. The 24-year-old, reportedly detained around mid-September, is being held for questioning in connection with the February 2026 hack of Dutch telecom giant Odido and other attacks attributed to ShinyHunters, though police have not publicly named him or formally tied him to specific incidents[5][7][9].

Van der Stap, known online by the alias “Umbreon,” was previously convicted in 2023 for a series of data breaches and extortion schemes that netted between €1.5 million and €2.7 million, earning him a four-year sentence with a portion suspended[2][6][11]. He was released from prison in December 2025 and surfaced months later as an offensive security lead at Amsterdam-based firm Neo Security, whose CEO publicly confirmed his identity after Dutch police declined to name the suspect[1][3][6][12]. Investigators are now scrutinizing whether Van der Stap’s past involvement in ShinyHunters-linked breaches overlaps with the Odido compromise, which reportedly exposed data on more than 6.2 million people, including sensitive customer information[5][6][10].

ShinyHunters has emerged since 2020 as a financially motivated data-theft and extortion outfit responsible for a string of headline-making breaches, including incidents at Ticketmaster via Snowflake and education software provider PowerSchool[4]. The group expanded its operations into ransomware-as-a-service in 2025 under the “shinysp1d3r” brand and has already seen several alleged members arrested in France, underscoring mounting law-enforcement pressure on the crew[4]. Despite those setbacks, threat intelligence sources say ShinyHunters is on pace to collect nearly $100 million in extortion payments in 2026, reflecting both the scale of its victim pool and the aggressiveness of its tactics[2].

In the days immediately following Van der Stap’s arrest, ShinyHunters dramatically escalated activity, claiming responsibility for an audacious breach of the FBI’s job application portal that exposed Social Security numbers and other personal data belonging to more than 5,000 officials, as well as launching an extortion campaign against the Russian ransomware group Cl0p[2]. Security researchers at Google Threat Intelligence Group and Mandiant have also linked a ShinyHunters-associated cluster, UNC6240, to renewed mass exploitation of CVE-2026-35273, a critical unauthenticated remote-code-execution flaw in Oracle PeopleSoft PeopleTools 8.61 and 8.62 that carries a CVSS 9.8 score and is being used to target organizations across technology, IT services, healthcare, agriculture, transportation and government sectors[14]. That combination of high-impact government breaches, intra-criminal extortion and opportunistic CVE exploitation cements ShinyHunters as one of the most disruptive actors in the current extortion landscape[2][14].

Despite the mounting circumstantial links, ShinyHunters has publicly denied any association with Van der Stap, dismissing Dutch investigators as “unskilled and incompetent” and insisting the arrested individual has no connection to the group[1][3][9][12][13][15]. Dutch police, for their part, have confirmed the arrest and ongoing investigation but have declined to attribute specific hacks to the suspect, leaving open questions about whether he played a direct operational role, acted as an intermediary, or is being leveraged primarily as a source of intelligence on the gang’s inner workings[5][7][9]. Multiple outlets, including KrebsOnSecurity and other specialist publications, have nevertheless identified Van der Stap as the detainee and tied his long-standing “Umbreon” persona—visible on forums like BreachForums where he used Pokémon-themed imagery—to ShinyHunters-linked activity[2][7][8].

For defenders, the case reinforces the need to treat ShinyHunters and affiliated clusters as a priority threat, especially for organizations that rely on Oracle PeopleSoft or operate in sectors already hit by the group’s mass data-theft campaigns[4][14]. Enterprises running PeopleTools 8.61 or 8.62 should ensure they have applied all available vendor patches for CVE-2026-35273, hardened internet-facing applications and closely monitored for signs of exploitation, including anomalous access to HR and financial systems[14]. More broadly, the Odido and FBI incidents highlight the group’s continued focus on large data warehouses and sensitive government workloads; security teams are being urged to revisit extortion-readiness playbooks, validate incident-response partners and stress-test identity and access controls as investigators in the Netherlands and elsewhere work to determine whether Van der Stap’s arrest will meaningfully disrupt ShinyHunters—or simply provoke further retaliation[2][5][14].

References

  1. Dutch ‘reformed hacker’ arrested in ShinyHunters …
  2. Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
  3. Dutch police arrest security professional in ShinyHunters …
  4. Shinyhunters
  5. Dutch authorities arrest suspected ShinyHunters member in Odido hack probe
  6. ShinyHunters hacker arrest tied to alleged FBI framing, sources say
  7. Convicted Hacker Umbreon Arrested on Suspicion of …
  8. 24-Year-Old Arrested in Dutch Investigation Into ShinyHunters
  9. Dutch police confirm arrest in ShinyHunters hacking investigation
  10. Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters …
  11. Convicted cybercriminal arrested in connection with ShinyHunters group
  12. Dutch Hacker Arrested in ShinyHunters Probe Linked to FBI Data Breach
  13. Previously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe
  14. ShinyHunters (Threat actor): news timeline & CVEs – ZeroHour
  15. ShinyHunters beweert geen connectie te hebben met …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply