DUTCH authorities arrested 23-year-old convicted cybercriminal Pepijn van der Stap around 16 September 2026 on suspicion of helping the ShinyHunters hacking group steal data and extort victims, according to sources cited by KrebsOnSecurity. Van der Stap, formerly known online as “Umbreon”, was sentenced in 2023 to four years in prison, with one year suspended, after admitting data thefts and extortions that prosecutors said generated €1.5 million to €2.7 million.
He was released in December 2025 and later worked as an offensive security lead at Dutch company Neo Security. The arrest followed a Dutch police appeal for help identifying the native Dutch speaker who allegedly social-engineered access to telecoms provider Odido, leading to the theft of data on more than 6.2 million people. Police have not confirmed whether that caller has been identified as van der Stap.
Sources said ShinyHunters intensified its activity after the arrest, claiming responsibility for a breach of the FBI’s apply.fbijobs.gov recruitment site. Reporting by 404 Media and Reuters said the stolen information affected more than 5,000 officials and included Social Security numbers, job details, and sensitive psychiatric and medical files; the FBI confirmed the compromise. ShinyHunters attributed the attacks to CVE-2026-35273 in Oracle PeopleSoft, which it reportedly exploited as a zero-day from June.
Mandiant and Google Threat Intelligence Group later confirmed mass exploitation against dozens of organisations, while BleepingComputer reported that URL encoding was used to bypass suggested web application firewall rules. The evidence linking van der Stap to the recent attacks remains unconfirmed; sources instead described an internal dispute involving teenage cybercriminal “Rey” and alleged efforts to blame him.