Skip to main content

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

0
Critical
Published: 09/28/2026 (09/28/2026, 15:08:57 UTC)
Source: Krebs on Security

Description

Dutch authorities arrested Pepijn van der Stap, a convicted cybercriminal linked to the hacker group ShinyHunters, on suspicion of aiding data thefts and extortions. Van der Stap, known by the alias 'Umbreon,' was involved in multiple data breaches and extortion campaigns, including a major social engineering attack on Odido, the largest Dutch mobile provider, compromising data of over 6.2 million people. Following his arrest, ShinyHunters escalated attacks, breaching the FBI's job application site and extorting the Russian ransomware group Cl0p. The FBI breach exploited a recently patched PeopleSoft vulnerability (CVE-2026-35273). ShinyHunters used evasion techniques to bypass mitigations. Van der Stap had previously been convicted and sentenced to prison, released in late 2025, and had publicly claimed to be reformed before his recent arrest. The investigation and arrests are ongoing, with Dutch authorities seeking public assistance to identify members involved in social engineering intrusions.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/28/2026, 15:15:09 UTC

Technical Analysis

Pepijn van der Stap, a Dutch convicted cybercriminal and former member of the ShinyHunters hacking collective, was arrested in September 2026 for involvement in data thefts and extortion activities. Van der Stap operated under the hacker handle 'Umbreon' and was linked to selling stolen data on hacking forums. ShinyHunters conducted a significant social engineering attack on Odido, compromising data of over 6.2 million Dutch citizens. After Van der Stap's arrest, ShinyHunters intensified their operations, including a high-profile breach of the FBI's job application portal, exploiting a zero-day PeopleSoft vulnerability (CVE-2026-35273) that Oracle patched promptly. Despite mitigations, ShinyHunters used URL encoding techniques to bypass web application firewall rules. The group also extorted the Russian ransomware group Cl0p. The FBI confirmed the breach, which exposed sensitive personal and medical information of over 5,000 officials. The investigation remains active, with Dutch police seeking to identify additional members involved in the Odido intrusion.

Potential Impact

The arrest of Van der Stap disrupted ShinyHunters' operations but triggered an escalation in attacks, including breaches of high-profile targets such as the FBI and the ransomware group Cl0p. The FBI breach exposed sensitive personal data, including Social Security numbers and medical files of thousands of officials, posing significant privacy and national security risks. The Odido breach compromised personal data of over 6.2 million Dutch citizens, impacting privacy and potentially enabling further fraud or identity theft. The exploitation of a zero-day PeopleSoft vulnerability allowed ShinyHunters to access multiple organizations across various sectors. These incidents demonstrate the group's capability to conduct large-scale data theft and extortion campaigns with severe consequences for victims.

Defensive Guidance

Oracle has issued an official patch for the PeopleSoft vulnerability (CVE-2026-35273) exploited by ShinyHunters, and organizations are advised to apply this update promptly. Mandiant released web application firewall rules to mitigate the threat, but ShinyHunters have demonstrated evasion techniques against these rules, so additional monitoring and layered defenses are recommended. Dutch authorities continue their investigation and have requested public assistance to identify individuals involved in social engineering attacks. Organizations should verify that all patches are applied and remain vigilant against social engineering attempts. No further specific mitigations are indicated by the vendor or authorities at this time.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.63,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/","fetched":true,"fetchedAt":"2026-09-28T15:14:59.298Z","wordCount":1991}

Threat ID: 6aba8473f7a7c54106d72339

Added to database: 09/28/2026, 15:14:59 UTC

Last enriched: 09/28/2026, 15:15:09 UTC

Last updated: 09/28/2026, 17:52:21 UTC

Views: 29

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses