Dutch authorities have arrested a 24-year-old convicted cybercriminal on suspicion of helping the hacker group ShinyHunters carry out data thefts and extortions, according to three sources familiar with the matter. The man is Pepijn van der Stap, a convicted cybercriminal from Almere and Lelystad in the Netherlands. In the days right after his arrest, the remaining ShinyHunters members sharply escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
Van der Stap was convicted in 2023 over a string of data thefts and extortions that prosecutors said brought in between €1.5 million and €2.7 million. At his trial in late 2023, he admitted to living what he described as a Dr. Jekyll and Mr. Hyde existence, secretly using the handle Umbreon to extort victims and post their data on English-language hacking communities such as RaidForums and Breached. By day, he worked as a software engineer at the Amsterdam-based cybersecurity startup Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure, a nonprofit security research group. He was sentenced to four years in prison, one of which was suspended, and was released in December 2025.
In an interview on September 9, 2026, van der Stap presented himself as a reformed hacker trying to turn his life around. He was then employed as offensive security lead at the Dutch company Neo Security, which did not respond to requests for comment. He said he was still dealing with civil lawsuits and restitution for his earlier victims. Shortly after that interview, he stopped replying to messages, and efforts by people close to him also failed to get a response for two weeks.
According to two sources, van der Stap was arrested by Dutch authorities on or around September 16 and has been held for questioning since. One source said a colleague personally saw Dutch authorities removing items from his residence. Dutch authorities had asked the public to help identify the voice in a February 2026 recorded call in which a native Dutch-speaking ShinyHunters member social engineered access into Odido, the country's largest mobile telecommunications provider, an intrusion that stole data on more than 6.2 million Dutch people.
ShinyHunters confirmed to Dutch news media that the suspect in the audio clip is a member of the collective, saying the team member has full emotional, mental and financial support, including a criminal defense lawyer. It remains unclear whether Dutch police have matched the Odido caller to a confirmed real-life identity, and the Dutch police unit handling the incident did not respond to requests for comment. Days after sources say van der Stap was detained, ShinyHunters claimed credit for a breach at the FBI's job application site, apply.fbijobs.gov, where data stolen included Social Security numbers and personal information on more than 5,000 officials.
ShinyHunters said it gained access by exploiting a recently patched vulnerability, CVE-2026-35273, in PeopleSoft, a software-as-a-service platform from Oracle widely used to manage hiring, human resources, benefits and payroll. Oracle quickly issued a fix for the flaw that ShinyHunters reportedly began exploiting as a zero-day in June, and Mandiant released web application firewall rules for organizations unable to apply the update quickly enough. On Friday, BleepingComputer reported that ShinyHunters used a URL-encoding trick to bypass those rules, and a September 25 report from Mandiant and the Google Threat Intelligence Group confirmed mass exploitation against dozens of systems across higher education, technology, healthcare, agriculture, transportation and government.
More cybersecurity news from TechManNews.






