1. Executive Overview
In one of the most sprawling cybersecurity investigations in recent years, Dutch authorities have arrested 24-year-old convicted cybercriminal Pepijn van der Stap on suspicion of facilitating large-scale data thefts and extortions alongside the notorious hacking collective ShinyHunters. Operating historically under the online moniker "Umbreon," van der Stap lived a double life that spanned legitimate cybersecurity engineering and high-stakes criminal extortion.
However, what began as a targeted law enforcement action against a prolific data broker quickly metastasized into a global cyber crisis and a bizarre criminal saga. Immediately following van der Stap’s detention in mid-September 2026, remaining factions of ShinyHunters executed a series of retaliatory and chaotic attacks. These included a high-profile breach of the Federal Bureau of Investigation’s (FBI) recruitment portal—exposing sensitive personal and medical files of top U.S. cyber investigators—and a brazen extortion campaign targeting the Russian ransomware syndicate Cl0p.
Investigators believe these dramatic attacks were not merely acts of defiance, but part of a calculated campaign by an internal rival—a Jordanian teenager operating under the alias "Rey"—to frame van der Stap and seize full control of the ShinyHunters apparatus. Adding a chilling gravity to the case, Dutch media revealed on September 29 that investigators now suspect van der Stap of orchestrating contract murder plots abroad, elevating the judicial proceedings from complex financial cybercrime to a capital offense investigation.
[Pepijn van der Stap ("Umbreon")]
/
(By Day: Cybersecurity) (By Night: Extortion)
- Ex-Hadrian / DIVD Volunteer - RaidForums / Breached Data Seller
- Neo Security Offensive Lead - Odido Telecom Hack (6.2M Victims)
/
[Arrested: Sept 16, 2026 (Rotterdam)]
|
+-------------------------+-------------------------+
| |
[Murder-for-Hire Allegations] [Syndicate Power Struggle]
- Suspected contract hits abroad - "Rey" (Amman, Jordan) / SLSH
- Uncovered during post-arrest probe - FBI Jobs Portal Hack (CVE-2026-35273)
- Framed "Umbreon" via ASCII Art
2. Detailed Chronology
Phase 1: The Dual Existence of "Umbreon" (2021–2025)
Long before his late-2026 arrest, van der Stap was well known to law enforcement and illicit hacking undergrounds. Between 2021 and 2023, operating under the avatar of the Pokémon character Umbreon, van der Stap brokered massive stolen databases on illicit cybercrime hubs such as RaidForums and Breached. Prosecutors estimated his early extortion activities yielded between €1.5 million and €2.7 million.
During his late-2023 trial, van der Stap confessed to his criminal endeavors, describing his reality as a "Dr. Jekyll and Mr. Hyde existence." While secretly extorting enterprise victims by night, he maintained legitimate employment by day as a software engineer at the Amsterdam-based cybersecurity startup Hadrian and volunteered as a security analyst for the Dutch Institute for Vulnerability Disclosure (DIVD).
Sentenced to four years in prison with one year suspended, van der Stap cited severe psychological trauma and requested to remain in custody to access structured mental health care. He was released in December 2025.
Phase 2: Reform Claims and the Odido Telecom Compromise (Early–Mid 2026)
Following his release, van der Stap secured a position as the offensive security lead at the Dutch firm Neo Security. In an interview on September 9, 2026, he presented himself as a reformed hacker attempting to make financial restitution to his past victims and rebuild his professional standing.
Behind the scenes, however, law enforcement was already tracking a critical breach that occurred in February 2026. A native Dutch-speaking operative associated with ShinyHunters executed a social engineering attack against Odido, the Netherlands’ largest mobile telecommunications provider. By tricking an employee into entering credentials on a credential-harvesting phishing domain, the operative compromised the personal information of more than 6.2 million Dutch citizens.

When Dutch law enforcement broadcast a recorded phone call of the suspect to the public, ShinyHunters issued a taunt, claiming the voice belonged to one of their core members and promising full legal and financial backing for their operative.
+-----------------------------------------------------------------------------------+
| TIMELINE OF KEY DEVELOPMENTS (2026) |
+-------------------+---------------------------------------------------------------+
| February 2026 | ShinyHunters breaches Odido Telecom (6.2M victims affected). |
| June 2026 | Zero-day exploitation of Oracle PeopleSoft flaw begins. |
| Sept 9, 2026 | Van der Stap claims reformation in media interview. |
| Sept 16, 2026 | Dutch police raid van der Stap's residence; suspect detained. |
| Sept 22–25, 2026 | FBI jobs portal breached; ShinyHunters bypasses Mandiant WAF. |
| Sept 29, 2026 | Dutch media reports murder-for-hire charges against suspect. |
+-------------------+---------------------------------------------------------------+
Phase 3: Detention, Raid, and Murder-for-Hire Suspicions (September 2026)
On or around September 16, 2026, Dutch law enforcement raided van der Stap’s residence in Lelystad/Almere, seizing digital infrastructure and taking him into custody. Silence followed as colleagues and associate contacts failed to reach him.
On September 29, Dutch news outlet RTL broke a critical update: prosecutors had expanded their investigation beyond digital extortion. Investigators revealed compelling evidence suggesting van der Stap had attempted to orchestrate at least two contract murders abroad. While details regarding the intended targets remain sealed, the revelations reframed the arrest from an anti-cybercrime action into a multi-jurisdictional violent crime investigation.
Phase 4: Escalation, FBI Compromise, and the "Rey" Frame Job
Within days of van der Stap’s arrest, remaining elements of ShinyHunters launched an aggressive exploitation spree targeting enterprise victims. The group exploited a critical vulnerability (CVE-2026-35273) in Oracle PeopleSoft, a Human Resources and payroll platform widely utilized across corporate and government institutions.
Using sophisticated URL-encoding techniques, the attackers bypassed Web Application Firewall (WAF) mitigation guidelines published by Mandiant, compromising dozens of organizations across healthcare, higher education, government, and transportation sectors.
The crown jewel of this campaign was the breach of the FBI’s job application system (apply.fbijobs.gov). The hackers exfiltrated sensitive Personal Identifiable Information (PII)—including Social Security numbers, psychiatric profiles, and medical evaluations—belonging to more than 5,000 FBI personnel, focusing heavily on agents in major cybercrime units and counter-foreign intelligence divisions.
On the defaced portal, the hackers left an ASCII art representation of the Pokémon character Umbreon—van der Stap’s signature handle. Intelligence sources indicate this was deliberate: an internal rival named "Rey" placed the imagery on the site to pin the high-profile federal breach squarely on the detained Dutch hacker.
3. Supporting Context & Metrics
The Financial Scale of ShinyHunters Operations
According to threat intelligence estimates from Mandiant, ShinyHunters’ extortion apparatus evolved significantly throughout 2026, shifting from simple database sales to aggressive enterprise ransomware and data-extortion tactics.

| Metric | Details / Value |
|---|---|
| Projected 2026 Revenue | Estimated $100 million in extortion payouts |
| Van der Stap Historical Earnings | €1.5M – €2.7M (2021–2023 cybercrime convictions) |
| Odido Breach Impact | 6.2 million records stolen |
| FBI Portal Compromise Impact | 5,000+ federal agents/officials exposed |
| Software Flaw Targeted | CVE-2026-35273 (Oracle PeopleSoft) |
[Extortion Revenue Disparity (2026)]
ShinyHunters (Projected) : $100,000,000 =====================================>
Van der Stap (Historical) : $2,900,000 ===>
TeamPCP Affiliates : $20,000 =>
The Merging Syndicates: SLSH and Internal Friction
The structural drift of ShinyHunters toward hyper-aggressive targets is attributed to its operational merger with ScatteredLapsussHunters (SLSH). SLSH represents an amalgamation of three prolific cybercrime syndicates:
- Scattered Spider: Renowned for sophisticated social engineering, SIM-swapping, and helpdesk manipulation.
- LAPSUS$: Infamous for destructive extortion campaigns, insider recruitment, and public spectacle.
- ShinyHunters: Historically focused on massive database exfiltration and cloud infrastructure compromise.
+-----------------------+ +-----------------------+ +-----------------------+
| Scattered Spider | | LAPSUS$ | | ShinyHunters |
| (Social Engineering) | | (Destructive Tactics) | | (Cloud & DB Leaks) |
+-----------+-----------+ +-----------+-----------+ +-----------+-----------+
| | |
+------------------------------+------------------------------+
|
v
+-------------------------------------+
| ScatteredLapsussHunters (SLSH) |
| Led by "Rey" (Amman, Jordan) |
+-------------------------------------+
At the epicenter of SLSH is "Rey," a teenage cybercriminal operating out of Amman, Jordan, whose father is employed by Royal Jordanian Airlines. First identified by security firm KELA in early 2025, Rey assumed primary operational control over the ShinyHunters infrastructure, pushing the group toward high-risk targets like federal agencies and rival cybercrime syndicates like Cl0p.
Supply Chain Double-Crosses: The TeamPCP Fallout
The tactical partnership between SLSH, ShinyHunters, and an upstart supply-chain threat group known as TeamPCP illustrates the volatile nature of these underground alliances. Earlier in 2026, TeamPCP achieved massive technical access to global software supply chains but struggled to monetize the compromised keys.
Mandiant security researchers infiltrated TeamPCP’s communications channels, secretly passing exfiltrated access tokens to cloud infrastructure providers like Amazon Web Services and Microsoft Azure to neutralize them before exploitation.
Believing the access keys were still viable, ShinyHunters unilaterally used TeamPCP’s credentials to execute corporate extortions while withholding TeamPCP’s financial cut. This double-cross created intense friction across the ecosystem, leaving TeamPCP operators with less than $20,000 before their primary leaders were arrested in Australia.
4. Official Statements
Dutch Law Enforcement & Prosecution
Following confirmation of van der Stap’s arrest, the Dutch Public Prosecution Service released a brief statement confirming his custody status:
"A 24-year-old man from Lelystad has been detained in connection with an ongoing international cybercrime investigation. The suspect will appear before the council chamber of the Rotterdam District Court as investigations continue."
Addressing separate media queries regarding the murder-for-hire claims, judicial authorities declined to provide specifics on target identities, citing active cross-border operations.

ShinyHunters Gang Defiance
In a public statement issued to media outlets following the release of the Odido wiretap audio, ShinyHunters expressed complete indifference toward law enforcement efforts:
"Our team member has our full support—emotionally, mentally, and financially. Everything has been arranged, including a criminal defense lawyer. We do not look down on our staff and members; we take excellent care of them.
The Dutch police will need all the luck in the world—and everyone’s prayers—if they want to catch him before we carry out another large-scale data theft in the Netherlands. Frankly, the Dutch police are a big joke; they are incapable of doing anything. Incompetent. Irrelevant. Unimportant. Useless."
Federal Bureau of Investigation (FBI)
In response to the compromise of apply.fbijobs.gov, Brett Leatherman, Assistant Director of the FBI’s Cyber Division, delivered an unequivocal video address directed at the remaining members of ShinyHunters and SLSH:
========================================================================================
"Arrests have a way of changing who is willing to talk, and seized infrastructure has
a way of showing us who’s left. The longer you stay in this, the more we learn about
you. You know how to find us, and we know how to find you. I suggest you reach out
to us while the choice is still yours."
— Brett Leatherman, Assistant Director, FBI Cyber Division
========================================================================================
5. Future Outlook
The arrest of Pepijn van der Stap marks a significant operational hit for European cybercrime tracking, but it highlights the growing volatility within international hacking syndicates.
[FUTURE OUTLOOK]
|
+----------------------------+----------------------------+
| |
[Legal Reckoning] [Syndicate Fragmentation]
- van der Stap faces life imprisonment - Extradition pressure on "Rey" (Jordan)
- Dual prosecution: Extortion + Murder-for-Hire - Potential collapse of SLSH alliance
- Unprecedented overlap of cyber and physical violence - Increased FBI pressure on remaining infrastructure
1. Legal Implications for van der Stap
Van der Stap faces unprecedented legal exposure. While his 2023 conviction resulted in a relatively light four-year sentence, his alleged recidivism—combined with the Odido breach and contract murder charges—likely guarantees decades of imprisonment if convicted in Dutch courts. Extradition requests from U.S. authorities over the FBI portal breach could also follow.
2. The Fall of "Rey" and SLSH Leadership
With van der Stap in custody and his digital infrastructure seized, law enforcement pressure is converging on Amman, Jordan. Historical precedent suggests that teenage cybercriminals operating under aliases like "Rey" face immense exposure once their immediate operational proxies are dismantled. As seized servers reveal access logs and internal chat histories, the structural immunity previously enjoyed by SLSH leadership is eroding rapidly.
3. Enterprise Infrastructure Vulnerabilities
The mass exploitation of Oracle PeopleSoft systems (CVE-2026-35273) underscores a systemic vulnerability in legacy Human Resources platforms. Organizations relying solely on basic Web Application Firewalls remain vulnerable to URL-encoding bypass techniques. Cybersecurity agencies advise immediate patch application and zero-trust credential rotation across all administrative portals.
