Dutch Cybercriminal Arrest Sparks Violent Retaliation and Global Security Crisis

The arrest of 24-year-old Pepijn van der Stap, a Dutch national previously convicted of major cybercrimes, has triggered a volatile escalation in international digital warfare. Following his apprehension by Dutch authorities on September 16, 2026, the prolific hacking collective known as ShinyHunters abandoned its previous operational norms, launching a series of high-profile, aggressive attacks against the Federal Bureau of Investigation (FBI) and the Russian ransomware syndicate Cl0p. This shift marks a dangerous inflection point in the landscape of global cybercrime, as the group appears to have been radicalized and reorganized under new, younger leadership.
The Rise and Fall of Umbreon
Pepijn van der Stap, known to the underground hacking community by the handle "Umbreon," has long been a figure of contradiction. A resident of Almere and Lelystad, Van der Stap’s criminal career was initially brought to light during a 2023 trial, where he was convicted of orchestrating a string of data thefts and extortion schemes that netted between €1.5 million and €2.7 million. During his legal proceedings, Van der Stap candidly described his life as a "Dr. Jekyll and Mr. Hyde" existence. While he spent his daylight hours employed as a software engineer at the Amsterdam-based cybersecurity startup Hadrian and volunteering for the Dutch Institute for Vulnerability Disclosure (DIVD), his nocturnal activities involved the systematic exploitation of victims and the sale of stolen databases on dark-web forums such as RaidForums and Breached.
Despite serving a four-year sentence, which included a period of voluntary custody to address psychological trauma, Van der Stap was released in December 2025. In an interview conducted on September 9, 2026—just one week before his most recent arrest—Van der Stap claimed to be a reformed individual, currently working as an offensive security lead at Neo Security. However, investigators now believe that his ties to the criminal underworld were never fully severed, and his recent detainment suggests that he continued to facilitate the illicit operations of the ShinyHunters collective.

The ShinyHunters Escalation: A Timeline of Chaos
The current instability began in February 2026, when a native Dutch-speaking member of ShinyHunters successfully social-engineered an employee at Odido, the Netherlands’ largest mobile telecommunications provider. By tricking the employee into accessing a spoofed website, the group gained unauthorized entry, resulting in the theft of sensitive data belonging to more than 6.2 million Dutch citizens.
Following Van der Stap’s arrest in mid-September, the collective’s demeanor shifted from calculated theft to open confrontation. Within days, the group claimed credit for a breach of the FBI’s recruitment portal, apply.fbijobs.gov. The breach exposed the personal identifiable information (PII) of over 5,000 FBI officials, including individuals working in sensitive units tasked with investigating foreign state-sponsored cyber threats. The leaked data, which reportedly included psychiatric and medical records, represented a significant intelligence failure and a direct challenge to United States law enforcement.
The group’s methodology relied on the exploitation of CVE-2026-35273, a critical vulnerability within Oracle’s PeopleSoft platform. While Oracle moved quickly to patch the flaw, ShinyHunters demonstrated a high degree of technical sophistication by utilizing a URL-encoding trick to bypass security mitigations suggested by Mandiant and other cybersecurity firms. This campaign was not limited to the FBI; researchers from Mandiant and the Google Threat Intelligence Group confirmed that the group had mass-exploited this vulnerability across various sectors, including healthcare, agriculture, and global transportation.
The Influence of "Rey" and the SLSH Merger
Analysts tracking the group have identified a significant change in the organizational hierarchy. Sources close to the investigation indicate that ShinyHunters is now heavily influenced, if not controlled, by a teenage cybercriminal based in Amman, Jordan, operating under the alias "Rey." Rey is a central figure in the ScatteredLapsussHunters (SLSH) group, an entity formed by the merger of three historically prominent criminal organizations: Scattered Spider, LAPSUS$, and ShinyHunters.

The internal power struggle between Rey and Van der Stap appears to have fueled the recent reckless behavior. Cybersecurity experts suggest that the inclusion of the "Umbreon" mascot in the FBI defacement image was a deliberate tactic by Rey to frame the Dutch hacker for the intrusion. This internal animosity, combined with the collapse of a prior, short-lived partnership with the supply-chain hacking group TeamPCP, has pushed the collective toward more desperate and high-stakes extortions. Estimates from Mandiant indicate that ShinyHunters is currently on a trajectory to generate nearly $100 million in illicit revenue throughout 2026.
Official Responses and Legal Complications
The Dutch authorities have maintained a firm stance, with the Dutch police confirming that Van der Stap will face court proceedings in the Rotterdam District Court. The legal situation has grown increasingly grave; recent reports from the news outlet RTL suggest that investigators are now probing allegations that Van der Stap attempted to orchestrate at least two murders abroad.
In a rare and direct public response, Brett Leatherman, assistant director of the FBI’s Cyber Division, released a video statement commending the Dutch police for their collaboration and issuing a stern warning to the remaining members of ShinyHunters. "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left," Leatherman stated. "The longer you stay in this, the more we learn about you."
Broader Implications for Global Security
The case of Pepijn van der Stap and the resurgence of ShinyHunters highlight a troubling trend in the cybercrime ecosystem: the professionalization of criminal gangs combined with the volatile input of ideologically or ego-driven youth. The shift from "data collection" for the sake of completionism—which Van der Stap previously claimed was his primary motivation—to the deliberate targeting of national intelligence agencies signals a move toward a more destabilizing form of cyber warfare.

The vulnerability of global supply chains, exemplified by the PeopleSoft incident, remains the most significant systemic risk. When organizations rely on monolithic SaaS platforms for payroll, HR, and hiring, a single exploit can provide a gateway into the most sensitive personnel records of a government agency. As the Dutch police continue their investigation and the FBI attempts to mitigate the fallout from the portal breach, the global security community remains on high alert. The "ShinyHunters" collective, once considered a group of opportunistic data thieves, has now solidified its position as a primary threat to international digital stability, forcing a rethink of how critical infrastructure protects itself from human-centric social engineering and zero-day exploits. The ongoing legal battle in Rotterdam will likely serve as a litmus test for how effectively international law enforcement can dismantle decentralized, tech-savvy criminal networks that possess the ability to operate across borders with near-total impunity.







