Executive Overview
In a dramatic escalation of international cyber law enforcement and underworld retaliation, Dutch authorities have arrested 24-year-old convicted cybercriminal Pepijn van der Stap, suspected of playing a critical role in data thefts and extortions orchestrated by the notorious hacking collective ShinyHunters. Van der Stap, a dual-identity figure who previously operated under the hacker handle “Umbreon,” had seemingly transitioned into a legitimate security researcher and offensive security engineer before his recent detention.
However, his arrest has triggered immediate, volatile shockwaves across the global cybersecurity landscape. In the days following his capture, remaining members of ShinyHunters launched an aggressive, high-profile retribution campaign. This included a brazen breach of the FBI’s job application portal (apply.fbijobs.gov)—exposing sensitive personal and medical data of over 5,000 personnel—alongside the targeted extortion of the Russian ransomware syndicate Cl0p.
Investigative disclosures reveal that this chaos is further compounded by a violent internal power struggle. Leadership of the broader criminal ecosystem has allegedly been seized by a teenage Jordanian hacker known as “Rey,” the administrator of the hyper-aggressive syndicate ScatteredLapsussHunters (SLSH). Utilizing sophisticated zero-day exploits, URL-encoding evasion techniques, and psychological warfare tactics, this newly consolidated threat ecosystem has plunged global corporations, intelligence agencies, and international cyber gangs into a state of high alert.
Detailed Chronology: From the Double Life of "Umbreon" to the September Raids
The Jekyll and Hyde Routine
Pepijn van der Stap’s path through the annals of cybercrime is a textbook study of compartmentalized deviance. Prior to his initial legal downfall, van der Stap maintained a dual existence. By night, he weaponized his technical proficiency under the alias “Umbreon,” trading, extorting, and leaking proprietary databases on prominent English-language dark web forums such as the now-defunct RaidForums and Breached. By day, he occupied respectable positions within the Amsterdam tech community, working as a software engineer for cybersecurity startup Hadrian and volunteering with the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research collective.
During his late 2023 trial, van der Stap confessed to his crimes, which prosecutors estimated generated between €1.5 million and €2.7 million in illicit proceeds. Sentenced to four years in prison—with one year suspended—van der Stap opted to remain incarcerated longer than necessary, citing access to better mental health treatment for his childhood trauma and PTSD than he could find independently. He was ultimately released in December 2025.
The Attempted Rehabilitation
In an interview with cybersecurity journalist Brian Krebs on September 9, 2026, van der Stap painted a picture of a reformed individual desperately attempting to make amends. At the time of the interview, he was employed as the offensive security lead at Neo Security, a Dutch cybersecurity firm, and was actively dealing with civil lawsuits and victim restitution mandates.

However, this veneer of rehabilitation fractured rapidly. Shortly after the interview, van der Stap abruptly ceased all communication. Associates and close contacts reported complete radio silence for two weeks.
The September 16 Arrest and Police Confirmation
According to multiple independent sources, Dutch law enforcement moved in, arresting van der Stap at his residence on or around September 16, 2026. Witnesses reported federal agents hauling physical hardware and digital assets out of his home.
The Dutch police subsequently confirmed the arrest of a 24-year-old individual tied directly to the sprawling ShinyHunters investigation. Authorities announced that the suspect is scheduled to appear before the Rotterdam District Court to face formal charges, marking a critical milestone in a multi-jurisdictional manhunt.
Supporting Context & Metrics: The Anatomy of a Global Cyber Syndicate
The Odido Social Engineering Campaign
Dutch investigators had been turning up the heat on the ShinyHunters network for months. In February 2026, a native Dutch-speaking operative socially engineered their way into Odido, the Netherlands’ largest mobile telecommunications provider. By tricking an employee into authenticating credentials on a spoofed phishing domain, the intruders exfiltrated sensitive data belonging to more than 6.2 million Dutch citizens.
In early September 2026, Dutch police released a public audio recording of the phone call used in the Odido social engineering attack, appealing to citizens for help in identifying the voice. ShinyHunters brazenly responded through regional media outlets, confirming that the voice belonged to one of their core members and vowing financial, emotional, and legal protection for the operative.
Financial Projections and the Extortion Spree
While van der Stap famously told Bloomberg in 2024 that his primary motivation was never financial gain—describing his compulsion simply as a pathological need to "collect data, organize data, download data, and create folders"—the broader ShinyHunters organization operates as a ruthless, highly optimized extortion machine.

According to threat intelligence assessments provided by Mandiant researcher Austin Larsen, ShinyHunters is on track to rake in an astounding nearly $100 million in extortion payments throughout 2026 alone. This massive cash flow has empowered the syndicate to absorb operational losses, pay high-priced legal defense teams, and maintain a resilient operational infrastructure despite frequent law enforcement disruptions.
Official Statements and Underworld Geopolitics
The FBI Breach and Oracle PeopleSoft Exploitation
The geopolitical fallout of van der Stap’s arrest manifested almost immediately in cyberspace. Demonstrating an unprecedented escalation in targeting, ShinyHunters claimed responsibility for breaching apply.fbijobs.gov, the official job application portal of the Federal Bureau of Investigation.
Working in collaboration with reporting teams at 404 Media and Reuters, security researchers verified that the exfiltrated cache contained:
- Social Security Numbers (SSNs) and deeply personal identifying information (PII) of over 5,000 applicants and current officials.
- Specific operational team assignments, including details on special agents, threat intake examiners, and personnel assigned to major cybercrime and foreign state-backed threat units.
- Highly sensitive psychiatric and medical evaluation files belonging to FBI personnel.
The vector of compromise centered on CVE-2026-35273, a severe vulnerability in Oracle PeopleSoft, a widely deployed enterprise platform used for human resources, payroll, and recruitment. Although Oracle rushed out a security patch and Mandiant published web application firewall (WAF) mitigation rules in June, BleepingComputer reported that ShinyHunters bypassed these defenses using advanced URL-encoding tricks, allowing them to mass-exploit systems across global healthcare, technology, higher education, and government sectors.
The Rise of "Rey" and the SLSH Takeover
Sources close to the ongoing investigations note that the FBI breach and the aggressive extortion of the Russian ransomware group Cl0p signal a dangerous doctrinal shift for ShinyHunters. This pivot was driven by a hostile leadership takeover executed by “Rey,” a teenage cybercriminal based in Amman, Jordan.
Rey operates as a central figure within ScatteredLapsussHunters (SLSH)—a terrifying criminal conglomerate fusing elements of Scattered Spider, LAPSUS$, and ShinyHunters. Intelligence firm KELA first unmasked Rey in March 2025, revealing a young actor deeply entrenched in international ransomware operations.

Underworld friction began earlier this year when ShinyHunters briefly partnered with TeamPCP, a supply-chain hacking group that specialized in compromising codebases. When Mandiant infiltrated TeamPCP and covertly burned their stolen credentials by feeding them to cloud providers like Amazon and Microsoft, the allied criminal factions turned on each other. According to investigative reporting by Andy Greenberg for Wired, ShinyHunters went rogue, executing independent extortions using stolen credentials without sharing profits with TeamPCP—whose leaders were subsequently arrested in Australia in August 2026.
Psychological Warfare: Framing "Umbreon"
The inclusion of van der Stap’s former hacker alias in the FBI site defacement was not accidental. The defacement image left on the FBI portal featured an ASCII art rendition of the Pokémon character Umbreon—complete with the taunting message: "This site has been seized by ShinyHunters. rooting your systems since ’19 ;)."
Intelligence sources indicate that Rey maintained a bitter personal feud with van der Stap regarding control over the ShinyHunters brand assets. Plastering the giant Umbreon motif across the hacked federal website was calculated psychological warfare: an attempt by Rey to publicly pin the catastrophic FBI attack on the newly imprisoned Dutchman.
Rey’s volatile behavior continued on social media. Shortly after the FBI hack hit the news, an X (formerly Twitter) account operated by Rey (@rmoskovy) published a meme depicting the Twin Towers struck by planes labeled "cl0p drama" and "fbi breach claim," anchored by a giant floating Pokémon figure of Umbreon. Hours after KrebsOnSecurity reached out to Rey’s father—an employee of Royal Jordanian Airlines—for comment, the account was abruptly deleted.
Future Outlook: A Shifting Cyber Threat Horizon
The arrest of Pepijn van der Stap and the subsequent shockwaves generated by ShinyHunters under Rey’s leadership mark a watershed moment in modern cybersecurity. Several critical trends emerge from this convergence of events:
- Militarization of Extortion: The willingness of modern syndicates to directly target Western intelligence agencies like the FBI—while simultaneously shaking down notorious ransomware cartels like Cl0p—proves that top-tier cybercriminal groups no longer fear state-sponsored retaliation; they actively court it for notoriety and leverage.
- The Fragility of "Reformed" Hackers: Van der Stap’s journey underscores the enduring shadow of historical digital footprints. Even when individuals attempt to pivot toward legitimate defensive security roles, past associations and lingering technical attribution leave them perpetually vulnerable to state prosecution and underworld betrayal.
- The Evolution of Fragmented Coalitions: The rise of hybrid syndicates like SLSH demonstrates that threat actors are increasingly agile, forming fluid, cross-border coalitions that can rapidly weaponize zero-day vulnerabilities (such as the Oracle PeopleSoft flaw) and bypass enterprise-grade WAF protections within hours of disclosure.
As the Rotterdam District Court prepares to hear arguments in the case against van der Stap, law enforcement agencies across Europe and North America remain locked in a high-stakes race against an evolving generation of digital extortionists who view infrastructure collapse not as a barrier, but as a business model.
