The Shadow of Umbreon: Inside the Arrest, the FBI Breach, and the Fracturing of ShinyHunters
In a dramatic convergence of international law enforcement efforts and escalating cyber warfare, Dutch authorities have arrested a 24-year-old convicted cybercriminal, Pepijn van der Stap, on suspicion of facilitating large-scale data thefts and extortions for the notorious hacker collective known as ShinyHunters. The arrest, which took place in the Netherlands on or around September 16, 2026, has sent shockwaves through the global cybersecurity community, triggering a volatile response from the hacker group that has since targeted the highest echelons of United States federal law enforcement.
The Suspect: A Double Life Unmasked
Pepijn van der Stap, a resident of Almere and Lelystad, has long been a figure of fascination for security researchers. Previously convicted in 2023 for a spree of data thefts that netted between €1.5 million and €2.7 million, van der Stap’s story is a modern-day Dr. Jekyll and Mr. Hyde narrative. By day, he maintained a respectable career as a software engineer at the Amsterdam-based cybersecurity startup Hadrian and volunteered for the Dutch Institute for Vulnerability Disclosure (DIVD). By night, he operated under the alias "Umbreon," a handle named after a Pokémon character, which he used to extort victims and hawk stolen databases on dark-web forums such as RaidForums and Breached.
During his 2023 trial, van der Stap admitted to his crimes, citing psychological struggles, including PTSD related to childhood trauma, which led him to request time in custody rather than home detention. He was released in December 2025, claiming in an interview with KrebsOnSecurity on September 9, 2026, that he was a reformed individual attempting to make amends. At the time of his recent arrest, he was employed as an offensive security lead at the Dutch firm Neo Security. However, the veneer of reform shattered shortly after that interview, as van der Stap abruptly ceased all communication with associates and journalists alike.
Chronology of Escalation
The arrest of van der Stap has served as a catalyst for what analysts describe as an unhinged shift in tactics by the remaining members of ShinyHunters.

- February 2026: A native Dutch-speaking member of ShinyHunters successfully social-engineered an employee at Odido, the Netherlands’ largest mobile telecommunications provider. The breach resulted in the theft of personal data belonging to over 6.2 million Dutch citizens.
- September 7, 2026: Dutch police publicly released an audio clip from the Odido incident, pleading for public assistance in identifying the caller.
- September 16, 2026: Dutch authorities conducted a raid on van der Stap’s residence, reportedly seizing extensive hardware and digital evidence.
- Late September 2026: ShinyHunters launched a brazen attack on the FBI’s job application portal (apply.fbijobs.gov), exfiltrating the sensitive personal information—including Social Security numbers and psychiatric records—of over 5,000 FBI personnel.
- September 29, 2026: Van der Stap is scheduled to appear before the Rotterdam District Court as the investigation continues to unfold.
The FBI Breach and the "Umbreon" Signature
The attack on the FBI’s infrastructure was marked by a chilling display of bravado. Upon compromising the portal, the hackers left behind a defacement page featuring ASCII art of the Pokémon "Umbreon," accompanied by the taunting message: "This site has been seized by ShinyHunters. rooting your systems since ’19 ;)."
The use of this specific imagery is widely viewed by threat intelligence analysts as a tactical maneuver by the group’s new leadership to frame the arrested Dutchman for the FBI attack. The breach was facilitated by the exploitation of CVE-2026-35273, a critical vulnerability in Oracle’s PeopleSoft platform. Despite rapid patching efforts by Oracle and the implementation of web application firewall (WAF) rules by security giants like Mandiant, ShinyHunters successfully bypassed these defenses using sophisticated URL-encoding tricks.
The Rise of "Rey" and the SLSH Coalition
According to sources familiar with the inner workings of these criminal syndicates, the recent volatility within ShinyHunters is the direct result of a power vacuum filled by a teenage cybercriminal based in Amman, Jordan, known as "Rey." Rey is a key operative in a conglomerate called ScatteredLapsussHunters (SLSH)—an amalgamation of three distinct hacking groups: Scattered Spider, LAPSUS$, and ShinyHunters.
Rey’s ascendency has been marked by a departure from the group’s historically "measured" criminal operations. Security researchers suggest that the "bad blood" between Rey and van der Stap stems from a dispute over control of the ShinyHunters brand and the proceeds from stolen data. Rey’s recent social media activity—including memes depicting the destruction of FBI and Cl0p infrastructure—highlights a reckless, high-profile approach that seeks to maximize chaos as much as financial gain.

Official Responses and Industry Implications
The breach of the FBI jobs portal has drawn condemnation from federal authorities, who confirmed the compromise of PII (Personally Identifiable Information) regarding individuals working in sensitive areas, such as cybercrime units and foreign counter-intelligence. Oracle, for its part, has worked aggressively to mitigate the PeopleSoft exploits, but the persistent success of ShinyHunters in bypassing security controls has forced the cybersecurity industry to reconsider the limitations of WAFs against determined, zero-day-capable adversaries.
The Dutch police, while remaining tight-lipped on specific evidentiary details, have characterized the investigation as a high-priority effort. In a statement released via X (formerly Twitter), the Dutch National Police confirmed the arrest of a 24-year-old in connection with the investigation and promised further transparency following the court proceedings in Rotterdam.
Implications: The $100 Million Extortion Machine
The implications of this saga extend far beyond a single arrest. Mandiant researchers, including threat intelligence analyst Austin Larsen, estimate that ShinyHunters is currently on pace to extract nearly $100 million in extortion payments throughout 2026. Their ability to pivot between supply-chain compromises, social engineering, and zero-day exploitation has made them one of the most significant threats to global digital infrastructure.
Furthermore, the intersection of these groups with the now-dismantled TeamPCP—an upstart group that unsuccessfully attempted to monetize supply-chain credentials—underscores a shift in the criminal ecosystem. The "burning" of stolen credentials by cloud providers, often at the behest of security researchers like those at Mandiant, has created a hyper-competitive environment where hackers are increasingly turning on one another to secure their share of the spoils.

For Pepijn van der Stap, the journey from a self-proclaimed reformed security researcher to a central figure in a global FBI investigation highlights the blurred lines of the modern cyber-underground. As the Dutch legal system prepares to hear his case, the digital world watches to see if the arrest of "Umbreon" will cripple the ShinyHunters collective or merely accelerate the reckless trajectory set by his successor, Rey. One thing remains certain: as long as there is data to be collected, organized, and weaponized, the cycle of extortion will continue to evolve, leaving behind a trail of compromised systems and shattered security.
