Dutch Police Nab 24-Year-Old in ShinyHunters Probe

Dutch authorities have taken into custody a 24-year-old man from Amsterdam in connection with the notorious hacker collective ShinyHunters. The person is expected to face the Rotterdam District Court on September 29, 2026. Exact charges have not been disclosed, but the arrest was confirmed by the Politie Landelijke Opsporing en Interventies in an official statement earlier this month.

Investigative reporting by independent security outlets has identified the suspect as Pepijn van der Stap, also known online as “Umbreon.” He was apprehended on September 15, 2026, and has a documented history: in 2023 he was convicted for involvement in multiple data thefts and extortion schemes. His past affiliations include a former role at cybersecurity firm Hadrian and volunteer contributions to the Dutch Institute for Vulnerability Disclosure.

Currently, van der Stap is working as the offensive security lead at Neo Security. His public views reflect a journey marked by ethical tension: he has acknowledged both legal and illegal work in his past, describing a period of hyper-vigilance and fear of arrest, especially after joining cybersecurity and vulnerability disclosure roles.

ShinyHunters and the FBI Breach Claims

ShinyHunters has recently claimed responsibility for a brazen breach of the FBI’s recruitment portal (apply.fbijobs.gov), asserting that the group exfiltrated terabytes of sensitive data. Initially, the group alleged that the intrusion was carried out using a previously unknown zero-day in Oracle PeopleSoft. But subsequent reporting suggests they instead exploited a URL-encoding bypass to evade web application firewall protections tied to CVE-2026-35273.

The group defended its actions as a form of militant transparency, claiming the breach served to protect its business and fight off misinformation. They said normal disclosure would have been ignored, but the hack ensured widespread attention to their concerns.

Law enforcement has not yet confirmed whether van der Stap was directly involved in that FBI incident or in planning it. Authorities also haven’t released details about how the suspect was linked to ShinyHunters, what evidence was uncovered, or whether others are being pursued in connection with the investigation.

This arrest follows heightened scrutiny of hacker groups leveraging data theft and manipulation as tools for publicity. ShinyHunters in particular has been active in posting stolen data and claiming responsibility for large-scale leaks, fueling both media attention and law enforcement interest globally.

Putting this all together, the case of van der Stap and ShinyHunters underscores a growing trend in cybercrime where breaches are used not just for financial gain, but to shape narratives online. The implications for cybersecurity policy and enforcement are significant: defenders must prepare for increasingly hybrid threats where PR, politics, and technical exploits intersect. Moving forward, watch for how this case influences international coordination on cyber threats, disclosures of evidence in court, and whether new legal precedents emerge around “hacktivist” style operations masquerading as activism.