Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
Dutch police arrested Pepijn van der Stap, a convicted hacker linked to the ShinyHunters extortion group. Van der Stap was previously convicted in 2023 for hacking, data theft, and extortion. The arrest is part of an ongoing investigation into ShinyHunters, which recently exploited an Oracle PeopleSoft vulnerability (CVE-2026-35273) to hack the FBI jobs site. The group also conducted a social engineering attack on a telecom provider, resulting in the theft of millions of records. Van der Stap was on supervised release at the time of arrest and currently works in offensive security. The investigation continues with further court proceedings pending.
AI Analysis
Technical Summary
Pepijn van der Stap, convicted in 2023 for multiple intrusions involving data theft and extortion, was arrested in connection with the ShinyHunters hacking group. ShinyHunters exploited a zero-day Oracle PeopleSoft vulnerability (CVE-2026-35273) to compromise the FBI jobs site. The group also conducted a social engineering attack against a telecommunications provider, stealing data of 6.2 million people. Van der Stap, known by the handle Umbreon, was previously involved in extortion activities and was on supervised release when arrested. The current leader of ShinyHunters is reportedly a teenage hacker from Jordan. The Dutch police continue their investigation and plan to provide more information after court hearings.
Potential Impact
The ShinyHunters group has conducted significant cybercriminal activities including hacking government and private sector sites, data theft of millions of individuals, and extortion. The exploitation of a zero-day Oracle PeopleSoft vulnerability allowed unauthorized access to sensitive systems such as the FBI jobs site. The social engineering attack on a telecom provider led to the compromise of personal data of over 6 million people. These actions have caused data breaches and potential harm to affected organizations and individuals. The arrest of a key suspect may disrupt the group's operations but the investigation is ongoing.
Mitigation Recommendations
No specific patch or remediation is applicable to this arrest event. Organizations using Oracle PeopleSoft should ensure they have applied the official fix for CVE-2026-35273 as disclosed by Oracle. Law enforcement continues to investigate and prosecute individuals involved. No immediate action is required beyond following official advisories related to the Oracle vulnerability and monitoring for related threat activity.
Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
Description
Dutch police arrested Pepijn van der Stap, a convicted hacker linked to the ShinyHunters extortion group. Van der Stap was previously convicted in 2023 for hacking, data theft, and extortion. The arrest is part of an ongoing investigation into ShinyHunters, which recently exploited an Oracle PeopleSoft vulnerability (CVE-2026-35273) to hack the FBI jobs site. The group also conducted a social engineering attack on a telecom provider, resulting in the theft of millions of records. Van der Stap was on supervised release at the time of arrest and currently works in offensive security. The investigation continues with further court proceedings pending.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Pepijn van der Stap, convicted in 2023 for multiple intrusions involving data theft and extortion, was arrested in connection with the ShinyHunters hacking group. ShinyHunters exploited a zero-day Oracle PeopleSoft vulnerability (CVE-2026-35273) to compromise the FBI jobs site. The group also conducted a social engineering attack against a telecommunications provider, stealing data of 6.2 million people. Van der Stap, known by the handle Umbreon, was previously involved in extortion activities and was on supervised release when arrested. The current leader of ShinyHunters is reportedly a teenage hacker from Jordan. The Dutch police continue their investigation and plan to provide more information after court hearings.
Potential Impact
The ShinyHunters group has conducted significant cybercriminal activities including hacking government and private sector sites, data theft of millions of individuals, and extortion. The exploitation of a zero-day Oracle PeopleSoft vulnerability allowed unauthorized access to sensitive systems such as the FBI jobs site. The social engineering attack on a telecom provider led to the compromise of personal data of over 6 million people. These actions have caused data breaches and potential harm to affected organizations and individuals. The arrest of a key suspect may disrupt the group's operations but the investigation is ongoing.
Defensive Guidance
No specific patch or remediation is applicable to this arrest event. Organizations using Oracle PeopleSoft should ensure they have applied the official fix for CVE-2026-35273 as disclosed by Oracle. Law enforcement continues to investigate and prosecute individuals involved. No immediate action is required beyond following official advisories related to the Oracle vulnerability and monitoring for related threat activity.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/dutch-police-arrest-convicted-hacker-in-shinyhunters-investigation/","fetched":true,"fetchedAt":"2026-09-29T11:03:17.461Z","wordCount":1013}
Threat ID: 6abb9af5f7a7c5410645a87e
Added to database: 09/29/2026, 11:03:17 UTC
Last enriched: 09/29/2026, 11:03:25 UTC
Last updated: 09/29/2026, 17:59:38 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.