FBI urges remaining ShinyHunters members to surrender after alleged leader arrested in Amsterdam
Dutch police, with FBI support, arrested 24-year-old Pepijn van der Stap in Amsterdam in the ShinyHunters investigation; a Rotterdam court ordered at least 90 days' detention, and his laptop triggered separate attempted-murder-incitement charges.
Dutch police, assisted by the FBI, arrested a 24-year-old Amsterdam man on September 15, 2026 (SecurityWeek alone reports September 16) on suspicion of participating in the ShinyHunters criminal organization. KrebsOnSecurity, DataBreaches.net and other media identified him as Pepijn van der Stap, alias Umbreon, who was sentenced in 2023 to four years, one suspended, for hacking and blackmailing more than a dozen companies and reportedly earning €1.5–2.7 million; he was later linked to Hadrian, DIVD, and Neo Security, described as either its offensive-security lead or its CTO while on supervised release. He appeared before Rotterdam District Court on September 29, which ordered at least 90 days of pretrial detention; he is reported held in isolation with storage devices seized. Prosecutors filed no specific breach charges; material on his laptop led to a separate case in which he is charged with attempted incitement to commit two murders abroad that he allegedly ordered. His role is disputed: the FBI calls him an alleged ShinyHunters leader, Dutch police describe only a suspected participant, and ShinyHunters denied any association. Other reporting says the group is led by a Jordanian teenager known as Rey or Ray, based in Amman, operating through ScatteredLapsussHunters (also written Scattered Lapsus$ Hunters) — an amalgamation of Scattered Spider, LAPSUS$ and ShinyHunters — who blamed van der Stap for the FBI jobs-site hack. Dutch police also linked the group to a vishing credential-theft call against telecom Odido that exposed data of over 6.2 million Dutch people, but DataBreaches and associates say the recorded voice is not van der Stap's. ShinyHunters recently claimed it breached FBIJobs.gov (apply.fbijobs.gov) using a modified exploit for Oracle PeopleSoft CVE-2026-35273, which the group exploited as a zero-day in June; analysts assess the access used a URL-encoding trick to bypass WAF rules. The group said it stole 2–3 terabytes including roughly 5,000 personnel records that exposed the FBI's Remote Operations Unit, plus personnel and applicant PII such as psychiatric reports and sample records referencing assignments on China, Russia, Iran, and Hezbollah. The claim is unverified, the FBI has not confirmed the breach, and the group said the intrusion was meant to force retractions rather than extract ransom and that it will not publish the data. The FBI says ShinyHunters and co-conspirators breached more than 140 organizations since last year —…
Coverage timelineoldest first · each row is one article
- · 1d agoDutch police confirm arrest in ShinyHunters hacking investigation
BleepingComputer· 62
Dutch police confirmed a 24-year-old Amsterdam man was arrested in a ShinyHunters hacking investigation.
- · 20h ago24-Year-Old Arrested in Dutch Investigation Into ShinyHunters
Security Affairs· 62
Dutch police arrested 24-year-old Pepijn van der Stap, alias Umbreon, in the ShinyHunters investigation; he appeared before Rotterdam District Court.
- · 19h agoDutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
The Hacker News· 66
Vulnerabilities in this storyAll →
- CVE-2026-352739.89%Unauthenticated Takeover Flaw in Oracle PeopleSoft Enterprise PeopleToolspublished · Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) KEV ransomware
| CVE | Vulnerability | CVSS | EPSS |
|---|