Executive Overview
In a dramatic escalation of geopolitical cyber conflict, the arrest of a 24-year-old Dutch cybercriminal in mid-September 2026 has sent shockwaves through the underground ecosystem. The suspect—identified by multiple sources as Pepijn van der Stap, a previously convicted hacker who operated under the alias “Umbreon”—was detained by Dutch authorities on suspicion of orchestrating data thefts and extortion campaigns on behalf of the prolific, high-profile extortion collective known as ShinyHunters.
Van der Stap’s apprehension disrupted more than just a domestic criminal enterprise. In the immediate aftermath of his arrest, remaining factions of ShinyHunters retaliated with a series of shockingly brazen cyberattacks. The group launched an unprecedented assault on United States national security infrastructure, breaching the FBI’s job application portal (apply.fbijobs.gov) and extracting sensitive personal, medical, and psychological files of thousands of federal personnel. Simultaneously, the collective targeted the infamous Russian-speaking ransomware operation Cl0p, plunging the cyber underworld into internal chaos.
Behind these high-stakes digital incursions lies a toxic mix of internal gang rivalries, geopolitical proxy warfare, infiltrated supply chains, and the rise of a teenage Jordanian hacker known as “Rey,” who allegedly weaponized the arrest to pin global cyber attacks directly on Van der Stap. With the FBI, Mandiant, Google Threat Intelligence Group (GTIG), and European law enforcement agencies closing in, this digital saga underscores the volatile, fragile alliances governing modern cybercrime.
Detailed Chronology: From Dr. Jekyll and Mr. Hyde to Global Chaos
The Rise and Fall of Pepijn van der Stap
Pepijn van der Stap’s digital footprint spans years of dual-identity living. In late 2023, Dutch prosecutors tried van der Stap for a sweeping series of corporate data thefts and extortions that yielded between €1.5 million and €2.7 million. During his trial, van der Stap admitted to leading a Dr. Jekyll and Mr. Hyde existence. By day, he worked as a legitimate software engineer for Amsterdam-based cybersecurity startup Hadrian and volunteered for the Dutch Institute for Vulnerability Disclosure (DIVD). By night, operating as the hacker "Umbreon," he extorted multinational corporations and hawked stolen databases on English-language underground forums like RaidForums and Breached.
Van der Stap confessed to his crimes and was handed a four-year prison sentence, with one year suspended. Choosing to remain incarcerated temporarily to seek treatment for childhood trauma-related PTSD, he was eventually released in December 2025.
In a September 9, 2026 interview with security journalist Brian Krebs, van der Stap cast himself as a thoroughly reformed individual trying to make amends. At the time of the interview, he was employed as an offensive security lead at the Dutch firm Neo Security and was struggling to handle civil restitution claims. However, within days of this conversation, van der Stap abruptly ceased all communication.
On or around September 16, 2026, Dutch authorities swooped in, arresting van der Stap at his residence and hauling away crates of physical evidence. On September 29, Dutch outlet RTL reported an even more sinister twist: investigators began examining whether van der Stap attempted to orchestrate at least two murders abroad.

The Odido Intrusion and Law Enforcement Escalation
Dutch law enforcement’s closing net on ShinyHunters was accelerated by a high-profile telecommunications breach earlier in the year. In February 2026, a native Dutch-speaking member of ShinyHunters successfully social-engineered their way into Odido, the Netherlands’ largest mobile network provider. By tricking an employee into authenticating through a spoofed landing page, the hackers harvested personal records belonging to over 6.2 million Dutch citizens.
Desperate for public assistance, the Dutch National Police released an intercepted phone call in September 2026, inviting citizens to identify the voice of the Odido intruder. ShinyHunters brazenly responded to local media outlets, confirming the audio belonged to their associate and vowing full financial, emotional, and legal support. The group also issued a blistering, derisive statement attacking Dutch authorities as "incompetent, irrelevant, and useless."
The FBI and Cl0p Breaches
Just days after van der Stap’s detention, ShinyHunters executed a retaliatory campaign targeting the highest tiers of American law enforcement.
The collective breached the FBI’s recruitment gateway, apply.fbijobs.gov. According to joint investigations by 404 Media and Reuters, the exfiltrated dataset exposed Social Security numbers, job classifications, and operational assignments of over 5,000 personnel—including special agents assigned to major cybercrimes and foreign counterintelligence units. Shockingly, the leaked dossiers also contained sensitive psychiatric and psychological evaluations of federal employees.
The intrusion vector leveraged a recently patched, critical vulnerability (CVE-2026-35273) within Oracle PeopleSoft, an enterprise resource planning platform widely deployed across government and private sectors. Although Oracle issued timely patches in mid-2026, and firms like Mandiant rushed out protective web application firewall (WAF) rules, BleepingComputer reported that ShinyHunters easily bypassed these mitigations via sophisticated URL-encoding tricks. Google Threat Intelligence Group (GTIG) and Mandiant confirmed that the collective conducted a mass-exploitation campaign across higher education, healthcare, technology, and government verticals.
In a brazen mocking gesture, the defacement page left on the FBI’s portal featured an ASCII art rendering of Umbreon, the Pokémon character matching van der Stap’s historical hacker alias, alongside the taunting text: "This site has been seized by ShinyHunters. Rooting your systems since ’19 ;)."
Supporting Context & Metrics: Gang Wars, Supply Chains, and Financials
The Rise of “Rey” and ScatteredLapsussHunters (SLSH)
According to intelligence sources close to the investigation, the aggressive shift toward targeting the FBI and rival ransomware groups marked a sharp departure from ShinyHunters’ traditional modus operandi. This pivot followed a hostile internal takeover of the group by “Rey,” a teenage cybercriminal operating out of Amman, Jordan.

Rey is a prominent leader within ScatteredLapsussHunters (SLSH)—a dangerous hybrid syndicate forged from the remnants of Scattered Spider, LAPSUS$, and ShinyHunters. First unmasked by cybersecurity firm KELA in March 2025, Rey’s digital operations have consistently courted global attention.
Intelligence sources suggest Rey harbored a fierce personal grudge against van der Stap regarding control over the "ShinyHunters" brand equity and stolen data archives. The prominent placement of the Umbreon Pokémon branding on the defaced FBI portal was not an homage, but a calculated framing operation designed by Rey to direct federal retribution squarely onto the imprisoned Dutchman. Following media inquiries regarding his son’s leadership of ShinyHunters, Rey abruptly deleted his primary Twitter/X account (@rmoskovy), while his father—an employee of Royal Jordanian Airlines—refused to respond to media inquiries.
The TeamPCP Fallout and Infiltration
The bad blood between SLSH and traditional elements of the cyber underground traces back to earlier supply-chain operations involving TeamPCP, an aggressive upstart gang specializing in compromising software source code repositories.
As reported by Andy Greenberg in Wired, ShinyHunters and SLSH briefly partnered with TeamPCP to monetize stolen credentials. However, the operation was secretly compromised from within. Mandiant analysts had successfully infiltrated TeamPCP’s infrastructure and were covertly feeding stolen API keys and credentials directly to major cloud providers like Amazon and Microsoft, causing them to be instantly revoked.
As profits dried up—with TeamPCP leaders later claiming they netted a meager $20,000 before their arrest in Australia in August 2026—the allied gangs began turning on one another. ShinyHunters allegedly went rogue, executing independent extortion schemes using the compromised supply-chain credentials without cutting in their partners. Despite these disruptions, Mandiant researcher Austin Larsen noted that ShinyHunters remained on an unprecedented financial trajectory, pacing toward nearly $100 million in cumulative extortion collections for 2026.
Official Statements & Government Responses
The international fallout prompted rare, high-level public addresses from global cybersecurity authorities.
In a video message released via social media, Brett Leatherman, Assistant Director of the FBI’s Cyber Division, thanked Dutch law enforcement partners for their pivotal role in dismantling the infrastructure underpinning the attacks and issued a direct ultimatum to the remaining members of ShinyHunters:

"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left," Leatherman declared. "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out to us while the choice is still yours."
The Dutch National Police corroborated the arrest of the 24-year-old suspect, announcing that he would face formal extradition and remand proceedings before the chambers of the Rotterdam District Court. Meanwhile, the FBI formally acknowledged the breach of its recruitment gateway, reassuring affected personnel that remediation, identity protection, and psychological support services were being actively deployed.
Future Outlook: The Shifting Tides of Cyber Extortion
The collapse of Pepijn van der Stap’s double life and the subsequent implosion of the ShinyHunters leadership structure mark a watershed moment in contemporary cybercrime investigations.
- Law Enforcement Cohesion: The swift coordination between Dutch authorities, the FBI, Mandiant, and Google Threat Intelligence demonstrates that transnational cyber task forces are increasingly capable of penetrating decentralized, multi-tiered criminal syndicates.
- The Perils of Gang Fragmentation: With teenage ringleaders like Rey weaponizing internal conflicts and framing former associates, the criminal underworld is proving that its greatest vulnerability remains its internal distrust and ego-driven territorial wars.
- Institutional Resilience: While campaigns like the Oracle PeopleSoft exploitation wave highlight the persistent dangers of legacy enterprise software vulnerabilities, the rapid mobilization of global incident response teams ensures that high-profile threat actors face mounting friction in monetizing stolen data.
As Pepijn van der Stap faces trial in Rotterdam—now burdened not only with historic data theft charges but also alarming allegations of orchestrating physical violence—the remaining members of ShinyHunters find themselves backed into a tightening corner. With global intelligence agencies actively mapping their digital and physical footprints, the era of unbridled impunity for elite extortion syndicates is rapidly drawing to a close.
