Shadow Operations and Cyber Warfare: Inside the Downfall of “Umbreon” and the Escalation of ShinyHunters

Share
Shadow Operations and Cyber Warfare: Inside the Downfall of “Umbreon” and the Escalation of ShinyHunters

Executive Overview

The global cybersecurity landscape was shaken by a high-stakes convergence of international law enforcement actions, internal cybercriminal betrayals, and unprecedented digital assaults. At the center of this storm is Pepijn van der Stap, a 24-year-old Dutch software engineer and convicted cybercriminal whose arrest by authorities in the Netherlands sparked a furious escalation of attacks by the notorious hacking collective ShinyHunters.

Operating under the digital alias “Umbreon,” van der Stap’s complex double life—balancing legitimate cybersecurity roles at prominent startups against underground extortion campaigns—came crashing down in mid-September 2026. His apprehension triggered a chaotic chain reaction across the digital underworld. Remaining members of ShinyHunters, allegedly steered by a teenage Jordanian cybercriminal known as “Rey,” launched brazen, retaliatory data-theft campaigns. These included a high-profile breach of the FBI’s job application portal and the targeted extortion of the Russian ransomware syndicate Cl0p.

This investigative report unpacks the dual narratives of van der Stap’s arrest and subsequent, chilling allegations of orchestrating murder-for-hire plots, alongside the chaotic geopolitical fallout of ShinyHunters’ mass-exploitation campaigns targeting global software infrastructure.


Detailed Chronology: From “Dr. Jekyll and Mr. Hyde” to Global Detention

The Rise of “Umbreon” and the 2023 Conviction

Pepijn van der Stap’s journey into the dark corners of cybercrime began years before his true identity was unmasked. Operating under the Pokémon-inspired handle “Umbreon,” van der Stap cultivated an infamous reputation on English-language underground hacking forums such as RaidForums and Breached. By day, he maintained a squeaky-clean professional image as a software engineer for the Amsterdam-based cybersecurity startup Hadrian and a volunteer for the Dutch Institute for Vulnerability Disclosure (DIVD). By night, he engineered massive data thefts and extortion campaigns.

In late 2023, van der Stap stood trial in the Netherlands for a string of cybercrimes that Dutch prosecutors estimated netted between €1.5 million and €2.7 million. During the proceedings, he confessed to living a "Dr. Jekyll and Mr. Hyde" existence. He was sentenced to four years in prison, with one year suspended. Preferring the controlled environment of a detention facility over the outside world due to ongoing psychological struggles—including post-traumatic stress disorder (PTSD) stemming from childhood trauma—he remained behind bars until his release in December 2025.

Rehabilitation Claims and Abrupt Silence

Following his release, van der Stap aggressively worked to rebrand himself. In an interview with KrebsOnSecurity on September 9, 2026, he cast himself as a reformed hacker eager to make a positive contribution to society. At the time of the interview, he was employed as the offensive security lead at the Dutch cybersecurity firm Neo Security, while simultaneously navigating civil lawsuits and restitution efforts for his past victims.

However, the redemption arc was short-lived. Shortly after his interview, van der Stap abruptly ceased all communications. Associates and journalists attempting to reach him were met with total silence.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Sources familiar with the matter confirmed that Dutch law enforcement swooped in on or around September 16, 2026, arresting van der Stap at his residence. Witnesses reported seeing authorities carting away physical evidence and electronic hardware from his home.

Escalation to Murder-For-Hire Allegations

The gravity of van der Stap’s legal jeopardy escalated dramatically on September 29, 2026, when Dutch news outlet RTL reported stunning new allegations from investigators. Beyond his established history of data theft, Dutch authorities now suspect that van der Stap attempted to orchestrate at least two murders abroad, allegedly acting as the mastermind behind paid assassination plots.

On September 29, the Dutch police confirmed that van der Stap would face the chambers of the Rotterdam District Court to address the expanding scope of charges against him, cementing his transition from a data-hoarding hacker into a subject of international homicide and organized crime investigations.


Supporting Context & Metrics: The Odido Breach and Software Supply Chain Vulnerabilities

The Odido Intrusion and Voice Identification

The dragnet closing in on the ShinyHunters ecosystem has been months in the making. Dutch police previously launched a public appeal seeking help to identify the voice of a native Dutch speaker who used advanced social engineering to infiltrate Odido, the Netherlands’ largest mobile telecommunications provider, in February 2026.

During the Odido incident, attackers tricked an employee into authenticating through a spoofed landing page, granting the threat actors unauthorized access to sensitive records belonging to more than 6.2 million Dutch citizens. When Dutch media pressed the collective, ShinyHunters openly confirmed that the voice in the audio clip belonged to one of their core members, vowing to cover all emotional, mental, and financial defense costs for their incarcerated comrade.

The Oracle PeopleSoft Zero-Day Campaign and WAF Bypasses

While Dutch authorities pursued individuals tied to the Odido breach, ShinyHunters weaponized zero-day and newly patched vulnerabilities across global enterprise infrastructure.

According to joint reports released in late September 2026 by Mandiant and the Google Threat Intelligence Group (GTIG), ShinyHunters executed a sweeping mass-exploitation campaign targeting Oracle PeopleSoft (tracked under CVE-2026-35273). The SaaS platform, broadly utilized for enterprise human resources, payroll, and benefits management, became a primary vector for exfiltrating sensitive data from dozens of organizations spanning higher education, technology, healthcare, transportation, and government sectors.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Despite Oracle issuing patches and security experts releasing web application firewall (WAF) mitigation rules, ShinyHunters demonstrated high technical adaptability. Researchers revealed that the group utilized advanced URL-encoding bypass tricks to circumvent Mandiant’s recommended firewall rules, ensuring uninterrupted access to corporate networks.

The FBI and Cl0p Retaliation

In the wake of van der Stap’s mid-September arrest, the remaining faction of ShinyHunters abandoned measured operations in favor of high-risk, attention-grabbing retaliation.

The group claimed credit for a brazen breach of apply.fbijobs.gov, the official job application portal of the U.S. Federal Bureau of Investigation. According to reporting from 404 Media and Reuters, the stolen data comprised Social Security numbers and deeply personal files—including psychiatric and medical evaluations—belonging to over 5,000 FBI personnel, special agents, and cyber threat analysts. Emblazoned across the defaced portal was an ASCII art rendering of the Pokémon character Umbreon, serving as a direct taunt to investigators and an apparent setup to frame van der Stap.

Concurrently, the syndicate targeted the Russian ransomware group Cl0p, launching extortion schemes against their rivals and signaling a fractured ecosystem governed by internal chaos rather than traditional cybercriminal code.


Official Statements and Inter-Group Warfare

The Leadership Struggle: Enter "Rey" and SLSH

Security researchers attribute ShinyHunters’ aggressive pivot to an internal hostile takeover orchestrated by a Jordanian teenager known as “Rey.” Operating as the administrator of ScatteredLapsussHunters (SLSH)—an amalgamation of notorious threat factions including Scattered Spider, LAPSUS$, and ShinyHunters—Rey reportedly harbored deep animosity toward van der Stap regarding control over the ShinyHunters brand and its vast repositories of stolen data.

Internal discord had already been brewing earlier in the year following a brief, disastrous partnership with TeamPCP, a supply-chain hacking collective whose leaders were arrested in Australia. Mandiant analysts secretly infiltrated TeamPCP’s credential supply chains, neutralizing stolen API keys by feeding them directly to cloud providers like Amazon and Microsoft. As the monetization schemes collapsed, the allied hacking factions turned on one another, with ShinyHunters allegedly going rogue to execute independent extortions using stolen credentials without sharing profits.

Following the FBI portal defacement, Rey taunted both the Bureau and Cl0p on social media platform X (formerly Twitter) using inflammatory memes before abruptly deleting his accounts after inquiries from investigative journalists.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Law Enforcement and Government Responses

International law enforcement agencies responded with unified force. Brett Leatherman, Assistant Director of the FBI’s Cyber Division, released a video message addressing the ShinyHunters collective directly:

"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out to us while the choice is still yours."

Meanwhile, Dutch law enforcement agencies have maintained operational security regarding ongoing interrogations, promising further transparency as van der Stap faces court proceedings in Rotterdam.


Future Outlook

The neutralization of Pepijn van der Stap and the severe disruption of the ShinyHunters infrastructure mark a watershed moment in contemporary cybersecurity enforcement. However, these events also underscore the volatile and decentralized nature of modern cybercriminal syndicates.

As teenage-led splinter factions like SLSH resort to erratic, high-consequence attacks on national security apparatuses, global law enforcement agencies face a mutating threat vector. The transition of cyber syndicates from purely financial extortionists into geopolitical disruptors—coupled with chilling allegations of violent offline crimes—signals that future task forces must integrate traditional homicide investigations with digital forensics.

Ultimately, while the takedown of key infrastructure and high-value operators like "Umbreon" deals a staggering blow to the underground economy, the fractured remnants of ShinyHunters and their associates prove that the war against borderless cybercrime remains an ongoing, high-stakes attrition battle.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *