Shadow Operations and Cyber Warfare: The Fall of ‘Umbreon,’ the Rise of ‘Rey,’ and the Relentless Escalation of ShinyHunters

Share
Shadow Operations and Cyber Warfare: The Fall of ‘Umbreon,’ the Rise of ‘Rey,’ and the Relentless Escalation of ShinyHunters

Executive Overview

In the high-stakes, shadow-laden world of international cybercrime, the boundaries between rehabilitation and recidivism are frequently blurred. Recent developments in the Netherlands and the United States have laid bare a complex web of high-profile data thefts, international extortion rackets, and bitter turf wars involving one of the world’s most notorious threat actors: the ShinyHunters cybercrime collective.

The arrest of 24-year-old Dutch national Pepijn van der Stap—better known by his former hacker alias "Umbreon"—has sent shockwaves through the global cybersecurity community. Van der Stap, a convicted cybercriminal who had ostensibly transitioned into a legitimate career as an offensive security lead and researcher, was detained by Dutch authorities on suspicion of continuing to aid ShinyHunters in systematic data thefts and corporate extortions.

His arrest acted as a catalyst, sparking a violent, high-risk operational pivot by the remaining members of ShinyHunters. In the immediate aftermath, the group engaged in an unprecedented escalation of cyber warfare, executing a brazen breach of the FBI’s job application portal (apply.fbijobs.gov) and audaciously targeting the Russian ransomware syndicate Cl0p.

This investigative report synthesizes the chronology of these unprecedented events, detailing the complex internal power struggles that led to the group’s radicalization under a teenage Jordanian administrator known as "Rey," the exploitation of Oracle PeopleSoft vulnerabilities, and the broader implications for international cybersecurity.


Detailed Chronology: From ‘Umbreon’ to the FBI Breach

The Jekyll and Hyde Reality of Pepijn van der Stap

The saga of Pepijn van der Stap is a textbook case of dual identity in the digital age. In late 2023, van der Stap was convicted in the Netherlands for a sweeping string of data thefts and extortion schemes that netted prosecutors-estimated illicit revenues between €1.5 million and €2.7 million. During his trial, van der Stap admitted to living a "Dr. Jekyll and Mr. Hyde" existence. By day, he operated as a software engineer for the Amsterdam-based cybersecurity startup Hadrian and volunteered for the Dutch Institute for Vulnerability Disclosure (DIVD). By night, operating under the handle "Umbreon," he extorted high-value corporate targets and traded pilfered databases on illicit, English-language cybercrime forums such as RaidForums and Breached.

Sentenced to four years in prison—with one year suspended—van der Stap served his time and was released in December 2025. In subsequent interviews, including a September 9, 2026 discussion with KrebsOnSecurity, van der Stap cast himself as a thoroughly reformed individual trying to make amends. At the time of his arrest, he was employed as an offensive security lead at the Dutch firm Neo Security.

However, this facade of rehabilitation crumbled rapidly. On or around September 16, 2026, Dutch law enforcement, acting on intelligence surrounding a high-profile telecommunications breach, closed in on van der Stap. Colleagues witnessed authorities carting evidence out of his residence. By September 29, Dutch news outlet RTL reported that investigators had uncovered an even darker layer to the case: authorities suspect van der Stap attempted to orchestrate at least two contract murders abroad.

The Odido Intrusion and Defiant Retaliation

Dutch authorities had spent months hunting the voice behind a February 2026 social engineering attack against Odido, the Netherlands’ largest mobile telecommunications provider. Using a sophisticated vishing (voice phishing) attack, a native Dutch-speaking ShinyHunters operative tricked an Odido employee into authenticating against a spoofed portal, enabling the theft of sensitive records belonging to over 6.2 million Dutch citizens.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

When Dutch police released audio clips of the suspect to the public, ShinyHunters aggressively confirmed the caller’s identity within their ranks. In a public statement issued to the NL Times, the collective took an aggressively dismissive stance toward law enforcement:

"Our team member has our full support — emotionally, mentally, and financially. Everything has been arranged… The Dutch police will need all the luck in the world — and everyone’s prayers — if they want to catch him before we carry out another large-scale data theft in the Netherlands. Frankly, the Dutch police are a big joke; they are incapable of doing anything."

Despite this bravado, the net tightened around the Dutch cell, culminating in van der Stap’s detention and an impending appearance before the Rotterdam District Court.

The FBI Portal Compromise and the Oracle PeopleSoft Zero-Day

The detention of van der Stap triggered a volatile retaliatory response from ShinyHunters. Days after the arrest, the collective claimed responsibility for an astonishingly brazen cyberattack against the United States Federal Bureau of Investigation.

Targeting the bureau’s recruitment portal (apply.fbijobs.gov), the hackers exfiltrated highly sensitive personnel data affecting more than 5,000 individuals. According to investigative reports by 404 Media and Reuters, the compromised records included Social Security numbers, detailed job titles, assignments within specialized counterintelligence and cyber threat units (including teams investigating foreign state-sponsored cyber espionage), and, most alarmingly, confidential psychiatric and medical evaluations of FBI personnel.

The vector for this intrusion—and a broader mass-exploitation campaign spanning global industries—was a vulnerability (CVE-2026-35273) in Oracle PeopleSoft, a widely deployed human resources and payroll platform. Although Oracle quickly patched the zero-day vulnerability initially exploited by ShinyHunters in June, the group demonstrated remarkable technical agility. When security firms like Mandiant issued web application firewall (WAF) mitigation rules, ShinyHunters bypassed them using advanced URL-encoding tricks.

In a joint threat intelligence report released on September 25, 2026, Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had leveraged this bypass to harvest data from dozens of organizations across higher education, healthcare, transportation, technology, and government sectors.

Significantly, the digital fingerprints left at the scene directly pointed back to the internal friction plaguing the group. On the defaced FBI jobs portal, ShinyHunters left behind an ASCII art rendition of the Pokémon character Umbreon—van der Stap’s historic moniker—accompanied by the taunting message: "This site has been seized by ShinyHunters. rooting your systems since ’19 ;)."

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Supporting Context & Metrics: The Rise of ‘Rey’ and ‘SLSH’

Security researchers emphasize that the decision to launch high-profile, high-risk attacks against the FBI and major ransomware syndicates like Cl0p marks a sharp departure from ShinyHunters’ historical modus operandi. This strategic pivot is directly attributed to an internal hostile takeover of the group by a teenage cybercriminal operating out of Amman, Jordan, known by the alias "Rey."

The Anatomy of ScatteredLapsussHunters (SLSH)

Rey, first unmasked by cybersecurity firm KELA in March 2025, operates as a core administrator for ScatteredLapsussHunters (SLSH)—an aggressive amalgam of three notorious cybercrime entities: Scattered Spider, LAPSUS$, and ShinyHunters.

Sources close to the investigations revealed that Rey harbored a deep-seated personal and operational vendetta against van der Stap for control over the ShinyHunters brand and its vast data repositories. Consequently, the inclusion of the oversized Umbreon Pokémon imagery in the FBI job portal defacement was not merely a signature, but a calculated "false flag" maneuver designed by Rey to pin the fallout of the FBI hack directly onto the incarcerated Dutchman.

The TeamPCP Supply-Chain Fallout

The bad blood between SLSH and traditional factions within the underground ecosystem was further exacerbated by a brief, volatile partnership earlier in the year with TeamPCP. TeamPCP had achieved notoriety by compromising global code supply chains, though they struggled to monetize their stolen access effectively.

According to investigative reporting by Andy Greenberg in Wired, ShinyHunters went rogue following this partnership, weaponizing credentials harvested by TeamPCP to execute independent multi-million-dollar extortions without sharing profits with the supply-chain hackers. Compounding this, Mandiant analysts had covertly infiltrated TeamPCP’s infrastructure, secretly feeding compromised credentials to major cloud providers like Amazon and Microsoft to invalidate them instantly. This triggered a paranoid cycle of mutual finger-pointing among the allied criminal factions.

Financial Scale of the Operations

Despite internal betrayals and law enforcement pressure, ShinyHunters has maintained an extraordinarily lucrative financial trajectory. According to Mandiant researcher Austin Larsen, the collective’s aggressive extortion spree positions them to pull in nearly $100 million in illicit extortion payments over the course of 2026. This financial cushion enables the group to maintain a resilient operational infrastructure, offering comprehensive emotional, mental, and financial support—including elite legal defense teams—to detained operatives.


Official Statements and Global Law Enforcement Response

The escalation of hostilities has prompted coordinated, high-level responses from international law enforcement agencies, moving beyond passive defense to active public appeals and direct warnings.

The FBI Weighs In

In an unprecedented direct video address released via social media, Brett Leatherman, Assistant Director of the FBI’s Cyber Division, acknowledged the gravity of the PeopleSoft compromise while directly addressing the remaining members of the ShinyHunters collective:

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left," Leatherman stated, issuing a stern warning to fugitive members like Rey. "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out to us while the choice is still yours."

Dutch Authorities and Judicial Proceedings

The Rotterdam District Court confirmed that Pepijn van der Stap is scheduled to face rigorous judicial scrutiny regarding his ongoing participation in international cybercrime networks, alongside widening inquiries into the shocking allegations connecting him to international murder-for-hire plots.

Meanwhile, organizations historically linked to van der Stap have moved quickly to distance themselves. DIVD issued a public statement clarifying that an internal security incident involving artificial intelligence tools discovered within their network bore no relation to ShinyHunters or the actions of their former volunteer.


Future Outlook: The Fractured Underground and Corporate Defense

The convergence of state-sponsored intelligence agencies, agile threat actors, and unstable youthful leadership marks a dangerous new era in cybersecurity. Several critical trends emerge as the fallout from the ShinyHunters-SLSH conflict continues to unfold:

  1. Internal Fractures as an Intelligence Asset: Law enforcement agencies are increasingly weaponizing the paranoia and internal betrayals inherent in hybrid cybercrime cartels (such as the friction between Rey and detained veterans like van der Stap). The arrest of key figures invariably triggers retaliatory exposure of infrastructure, accelerating the identification of remaining cell members.
  2. Zero-Day Resilience and Supply Chain Vulnerabilities: The rapid exploitation of enterprise software platforms like Oracle PeopleSoft demonstrates that threat actors can quickly operationalize vulnerabilities faster than standard patching cycles can keep pace. Organizations must move beyond static perimeter defense toward continuous behavioral monitoring and robust credential hygiene.
  3. The Weaponization of Geopolitical Targets: By striking federal agencies (the FBI) and major competing ransomware cartels (Cl0p), factions like ShinyHunters under Rey have crossed a threshold from financially motivated cyber extortion into the realm of high-risk geopolitical disruption. This escalation guarantees that Western intelligence agencies will prioritize the dismantling of these networks with unprecedented resources.

Ultimately, while the arrest of Pepijn van der Stap represents a tactical victory for European law enforcement, the broader ecosystem engineered by modern cyber syndicates remains fluid, volatile, and profoundly dangerous. As international authorities close the net around fugitive administrators in the Middle East and Europe, the digital battlefield bracing for the next wave of reprisals will require unprecedented cross-border cooperation between the private security sector and sovereign intelligence apparatuses.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *