Dutch Cybercriminal Arrest Unravels High-Stakes Global Extortion Web: From the Odido Telecom Breach to the FBI Job Portal Compromise

Executive Overview

In a dramatic escalation of international cyber conflict, Dutch law enforcement authorities have arrested 24-year-old convicted cybercriminal Pepijn van der Stap on suspicion of aiding high-profile data thefts and extortion campaigns spearheaded by the prolific hacker collective known as ShinyHunters. Operating under the online handle "Umbreon," van der Stap has a complex criminal history balanced against a career in legitimate cybersecurity. His detention in mid-September 2026 triggered an immediate, aggressive response from allied threat actors, unleashing a series of high-stakes attacks against global targets.

In the days following van der Stap’s arrest, remaining members of ShinyHunters retaliated by breaching the Federal Bureau of Investigation’s (FBI) career portal, apply.fbijobs.gov. The intrusion compromised sensitive personal, medical, and psychiatric records belonging to thousands of federal agents and cyber investigators. Concurrently, the group turned its extortion apparatus against Cl0p, one of Eastern Europe’s most feared ransomware operations, marking an unprecedented shift in cybercrime dynamics.

Investigators believe the sudden pivot toward high-risk targets reflects internal leadership restructuring within ShinyHunters, orchestrated by a Jordanian teenage cybercriminal known as "Rey." Rey, a dominant figure in the hybrid cybercrime coalition ScatteredLapsussHunters (SLSH), allegedly utilized van der Stap’s distinct persona to distract law enforcement and frame his former associate.

This complex nexus of enterprise zero-day exploitation, multi-group cyber coalitions, and retaliatory breach campaigns highlights the systemic vulnerabilities facing public and private infrastructure, while revealing deep-seated internal feuds within the global cybercrime underground.


Detailed Chronology

[2021–2023] -------------------------------------------------------------------
 • Van der Stap operates double life as "Umbreon" on RaidForums/Breached.
 • Arrested & convicted in late 2023 for €1.5M–€2.7M in extortion schemes.
 • Sentenced to 4 years imprisonment (1 year suspended).

[December 2025] ---------------------------------------------------------------
 • Released from prison; later employed at Neo Security as Offensive Lead.

[February 2026] ---------------------------------------------------------------
 • Voice-engineering attack hits Odido; 6.2M Dutch citizens' records stolen.

[June–August 2026] ------------------------------------------------------------
 • Zero-day exploitation of Oracle PeopleSoft (CVE-2026-35273) begins.

[September 9, 2026] -----------------------------------------------------------
 • Van der Stap interviews with KrebsOnSecurity, claiming reformation.

[Mid-September 2026] ----------------------------------------------------------
 • ~Sept 16: Dutch authorities arrest van der Stap at his residence.
 • ShinyHunters retaliates: Breaches FBI job portal & extorts Cl0p ransomware group.
 • Sept 25: Mandiant/GTIG disclose mass exploitation of PeopleSoft flaw.
 • Sept 29: Van der Stap scheduled to appear in Rotterdam District Court.

The Dual Life of "Umbreon" (2021–2023)

Between 2021 and 2023, Pepijn van der Stap maintained a striking dual existence. By day, the Almere and Lelystad native worked as a software engineer at the Amsterdam cybersecurity startup Hadrian and volunteered as a security researcher for the Dutch Institute for Vulnerability Disclosure (DIVD). By night, operating under the alias "Umbreon"—a reference to the dark-type Pokémon character—he systematically breached corporate databases, extorted victims, and leaked stolen data across illicit cybercrime forums like RaidForums and Breached.

Prosecutors established that van der Stap’s illicit operations generated between €1.5 million and €2.7 million. At his late-2023 trial, van der Stap admitted to his crimes, describing his conduct as a "Dr. Jekyll and Mr. Hyde" existence. He was sentenced to four years in prison, with one year suspended, and chose to remain in custody for an extended period to receive psychological treatment for post-traumatic stress disorder (PTSD) stemming from childhood trauma.

Release and Re-entry into Security (December 2025–September 2026)

Following his release from custody in December 2025, van der Stap attempted to re-establish himself within the legitimate technology sector, securing a role as the offensive security lead at the Dutch firm Neo Security. In an interview on September 9, 2026, van der Stap portrayed himself as a reformed hacker working to resolve outstanding civil restitution claims.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

However, behind the scenes, law enforcement agencies were actively investigating a major security incident from February 2026 involving Odido, the largest mobile telecommunications provider in the Netherlands. During that attack, a native Dutch-speaking operative associated with ShinyHunters used voice social engineering to trick an Odido employee into logging into a credential-harvesting site, leading to the theft of records belonging to over 6.2 million subscribers.

Arrest and Immediate Retaliation (Mid-September 2026)

On or around September 16, 2026, Dutch authorities executed a warrant at van der Stap’s residence, seizing electronic equipment and taking him into custody. Within days of his detention, ShinyHunters escalated its operational posture significantly:

  1. The FBI Job Portal Intrusion: Exploiting a critical vulnerability in Oracle PeopleSoft, ShinyHunters breached apply.fbijobs.gov. They exfiltrated personally identifiable information (PII), Social Security numbers, and sensitive psychiatric and medical records for more than 5,000 federal employees, including personnel assigned to foreign counterintelligence and cybercrime units.
  2. Defacement and Framing: On the compromised FBI page, the attackers left an ASCII-art rendering of the Pokémon character Umbreon, alongside the message: "This site has been seized by ShinyHunters. rooting your systems since ’19 ;)"
  3. Targeting Ransomware Competitors: ShinyHunters launched an extortion campaign against Cl0p, a major Russian-speaking ransomware group, demanding payments under threat of leaking internal operations data.

Supporting Context & Metrics

Technical Analysis: CVE-2026-35273 and WAF Bypasses

The primary attack vector utilized in ShinyHunters’ recent campaign was a critical vulnerability in Oracle PeopleSoft (tracked as CVE-2026-35273), an enterprise platform heavily used across public and private sectors for human resources, payroll, and recruitment management.

                                  [ Attack Vector Anatomy ]

  +-----------------------+      +-----------------------+      +-----------------------+
  |  ShinyHunters Attack  | ---> |   Obfuscated Payload  | ---> |  Mandiant WAF Rule    |
  | (URL-Encoding Trick)  |      | (%252e%252e%252f etc) |      | (Bypassed / Evaded)   |
  +-----------------------+      +-----------------------+      +-----------------------+
                                                                            |
                                                                            v
  +-----------------------+      +-----------------------+      +-----------------------+
  | Exfiltrated Data: PII,| <--- | Oracle PeopleSoft     | <--- | CVE-2026-35273        |
  | Medical/Psych Files   |      | Backend Server        |      | (Zero-Day Exploitation)|
  +-----------------------+      +-----------------------+      +-----------------------+

Threat intelligence reports from Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters began leveraging the flaw as a zero-day as early as June 2026. Although Oracle published an emergency patch and security firms distributed Web Application Firewall (WAF) mitigation rules, ShinyHunters bypassed these protections using advanced URL-encoding techniques. By double-encoding payload strings, the group successfully evaded pattern-matching security filters to execute arbitrary code on vulnerable PeopleSoft deployments worldwide.

Financial Impacts and Operational Metrics

ShinyHunters has established itself as one of the most lucrative cybercrime collectives operating in 2026. Intelligence estimates highlight the scale of their operations:

  • Projected 2026 Extortion Revenue: ~$100 Million (Source: Mandiant)
  • Odido Breach Impact: 6.2 Million subscriber records exfiltrated
  • FBI Compromise Scope: 5,000+ federal personnel files, including cyber agents and threat examiners
  • Targeted Sectors: Government, Higher Education, Healthcare, Technology, Transportation, and Agriculture

Underground Dynamics: The SLSH Alliance and Internal Feuds

The dramatic escalation in ShinyHunters’ operations coincides with internal restructuring. Sources close to the investigation indicate that effective control of the group shifted to a Jordanian teenager known as "Rey." Rey operates as a core figure within ScatteredLapsussHunters (SLSH)—an umbrella entity merging elements of three notorious threat groups:

Cybercrime Faction Core Specialization Primary Tactics
Scattered Spider Social Engineering & Helpdesk Takeovers Voice Phishing, SIM-Swapping, MFA Fatigue
LAPSUS$ Corporate Data Exfiltration & Extortion Insider Threats, Credential Theft, Public Leaks
ShinyHunters Mass Cloud & Enterprise Data Theft Zero-Day Exploitation, SQL Injection, Database Theft

Tensions between Rey and van der Stap reportedly flared over the monetization of stolen credentials obtained during a joint operation with TeamPCP, a supply-chain hacking group targeting code repositories. After security researchers at Mandiant secretly shared TeamPCP’s compromised credentials with cloud providers to invalidate them, the criminal factions turned on one another.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

ShinyHunters subsequently broke off to execute unauthorized extortions using the remaining data. Investigators believe Rey intentionally incorporated van der Stap’s signature "Umbreon" identity into the FBI breach defacement to pin law enforcement attention directly on the Dutch hacker following his arrest.


Official Statements

Dutch Law Enforcement and Prosecution

Following days of media speculation, the Dutch National Police confirmed van der Stap’s detention regarding the ongoing ShinyHunters investigation:

"A 24-year-old man from Almere has been arrested in connection with an ongoing international cybercrime investigation. The suspect will appear before the chambers of the Rotterdam District Court on Tuesday, September 29, 2026. Further details regarding the specific charges will be made available following the preliminary hearing."
— National Cybercrime Unit, Dutch Police Service

ShinyHunters Collective

In a public statement distributed to European media outlets, ShinyHunters expressed support for their associate while issuing direct threats to Dutch law enforcement:

"Our team member has our full support—emotionally, mentally, and financially. Everything has been arranged, including a criminal defense lawyer. We do not look down on our staff and members; we take excellent care of them. The Dutch police will need all the luck in the world—and everyone’s prayers—if they want to catch him before we carry out another large-scale data theft in the Netherlands. Frankly, the Dutch police are a big joke; they are incapable of doing anything. Incompetent. Irrelevant. Unimportant. Useless."
— ShinyHunters Spokesperson

Federal Bureau of Investigation (FBI)

In response to inquiries regarding the compromise of apply.fbijobs.gov, the FBI acknowledged an unauthorized intrusion into its third-party hiring platform:

"The FBI is investigating a cyber incident involving an unclassified, third-party portal used to process employment applications. Upon identifying the unauthorized access, technical teams immediately isolated the affected system. We are directly notifying impacted individuals whose personally identifiable information may have been compromised and providing appropriate credit monitoring services. The FBI’s core operational networks remain fully secure."
— FBI National Press Office

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Security Research Community

The Dutch Institute for Vulnerability Disclosure (DIVD) addressed separate inquiries regarding internal security incidents and van der Stap’s historic involvement:

"DIVD recently detected and mitigated an internal security anomaly involving the misuse of automated script tools. This matter has been resolved and is completely unrelated to external cybercrime investigations or the activities of former volunteers. We maintain strict access controls and cooperate fully with law enforcement authorities."
— DIVD Public Affairs


Future Outlook

The arrest of Pepijn van der Stap and the subsequent retaliation by ShinyHunters represent a critical juncture in global cyber defense. Several key dynamics will shape the cybersecurity landscape in the near term:

1. Supply Chain & ERP System Vulnerabilities

The mass exploitation of Oracle PeopleSoft underscores the ongoing vulnerability of Enterprise Resource Planning (ERP) and Human Capital Management (HCM) platforms. Organizations relying solely on Web Application Firewalls (WAFs) without applying core security patches remain exposed to payload obfuscation techniques, such as double URL-encoding. Enterprise defenders must prioritize rapid patch cycles over perimeter-based mitigations.

2. Multi-Jurisdictional Cybercrime Coalitions

The formation of composite groups like ScatteredLapsussHunters (SLSH) poses severe challenges for international law enforcement. By combining Scattered Spider’s social engineering capabilities, LAPSUS$’s insider access methods, and ShinyHunters’ enterprise exploitation tools, these syndicates operate across multiple jurisdictions—including Jordan, Europe, and North America—complicating extradition and attribution efforts.

3. Legal and Judicial Precedents

Van der Stap’s upcoming proceedings at the Rotterdam District Court will test the judicial framework surrounding recidivist cybercriminals. His case highlights the challenges of monitoring high-risk individuals transitioning back into legitimate cybersecurity roles, particularly when they retain technical knowledge and connections to active threat groups.

As law enforcement agencies intensify coordination across borders, threat actors are adapting through aggressive counter-responses and inter-group feuds, signaling a volatile period ahead for international infrastructure security.

Leave a Reply

Your email address will not be published. Required fields are marked *