Arrest, Then Escalation: Dutch Police Detain Suspected ShinyHunters Member as FBI and Cl0p Attacks Follow
On 28 September 2026 Dutch police confirmed the arrest of a 24-year-old man from Amsterdam in the investigation into ShinyHunters, the extortion collective behind 2026's most aggressive enterprise data-theft campaign. The suspect, due before the Rotterdam District Court on 29 September, was identified by KrebsOnSecurity's sources and DataBreaches.Net as Pepijn van der Stap — the convicted cybercriminal behind the "Umbreon" handle, now employed as offensive security lead at Dutch firm Neo Security. Van der Stap was reportedly detained on or around 15–16 September and held in custody for questioning since. What happened next is the story: in the days after the arrest, the remaining ShinyHunters members escalated dramatically — breaching the FBI's job application portal and extorting the Russian ransomware group Cl0p.
This is a direct sequel to this site's coverage of ShinyHunters' mass PeopleSoft exploitation: the FBI breach itself was carried out through CVE-2026-35273, the same flaw, with the group's defacement image featuring an ASCII-art Umbreon — Van der Stap's old alias — hidden in plain sight.
From reformed hacker to suspect again
Van der Stap's history is extensively documented. Convicted in 2023 over data thefts and extortions prosecutors said earned €1.5–2.7 million, he admitted living a double life: software engineer at Amsterdam security startup Hadrian and volunteer at the Dutch Institute for Vulnerability Disclosure by day, extortionist posting victim data on RaidForums and Breached by night. He drew a four-year sentence with one year suspended, chose to remain in custody for a time citing psychological treatment needs, and was released in December 2025. On 9 September 2026 he gave KrebsOnSecurity an interview casting himself as reformed — then went silent roughly two weeks ago, at the same time sources say Dutch authorities took him in and removed items from his residence.
The underlying probe centers on the Odido intrusion: Dutch police circulated a voice-identification appeal over a February 2026 call in which a native Dutch-speaking ShinyHunters member socially engineered an employee of Odido, the country's largest mobile carrier, through a spoofed login page — then stole data on more than 6.2 million Dutch people. ShinyHunters confirmed to Dutch media that the voice in the clip is a team member, pledged full legal and financial support, and taunted police as incapable of catching them before the next large-scale Dutch data theft. Whether investigators have matched the caller to Van der Stap remains unconfirmed; police disclosed no details beyond age, city, and court date.
The escalation: FBI portal, then Cl0p
Days after the detention, ShinyHunters claimed the brazen breach of apply.fbijobs.gov, the FBI's job application site. Reporting from 404 Media and Reuters, corroborated by an FBI statement confirming the hack, says the stolen data includes Social Security numbers and personal details on more than 5,000 officials — job titles and teams spanning special agents, threat-intake examiners, major-cybercrimes units, and investigators of foreign state-backed threats — plus sensitive psychiatric and medical files of FBI staff. The group framed the attack as a publicity operation rather than extortion, telling 404 Media it was "a marketing campaign" to force attention onto its statements.
Alongside the FBI hit, the group moved against Cl0p itself — extorting a Russian ransomware operation, a rare case of one major cybercrime brand shaking down another. Sources close to the investigation described both moves as retaliation-adjacent escalation timed to the arrest. For defenders, the pattern is the point: law-enforcement pressure on extortion groups does not reliably pause operations; it can accelerate them, as remaining members demonstrate continued capability and punish cooperation narratives.
What to do
- Patch Oracle PeopleSoft CVE-2026-35273 and treat WAF rules as already bypassed. The FBI breach ran through the same flaw and the same
/%50SEMHUB/encoding trick detailed in the Mandiant/GTIG analysis. Disable or remove EMHub where possible. - Harden helpdesk and employee authentication against vishing. The 6.2M-record Odido intrusion started with one employee at one spoofed login page. Phishing-resistant MFA and out-of-band verification for access grants are the controls that break this chain.
- Plan for post-arrest escalation, not relief. If your sector or data overlaps an arrested affiliate's targets, raise monitoring rather than lowering it: retaliatory or demonstrative attacks commonly follow high-profile detentions.
- Treat hiring and HR portals as high-value targets. apply.fbijobs.gov held SSNs, team assignments, and medical files — exactly the data useful for follow-on targeting of investigators. Segment HR systems and minimize retained sensitive fields.
- Watch for alias signaling in defacements and leaks. The Umbreon ASCII art was both a taunt and an attribution breadcrumb. Threat-intel teams should mine incident imagery and leak-site rhetoric, not just IOCs.
Sources:
- Krebs on Security — "Dutch Police Arrest 'Reformed' Hacker in Shiny Hunters Investigation" (28 September 2026; Van der Stap identification, September 16 detention, Odido vishing and 6.2M records, FBI and Cl0p escalation)
- The Hacker News — "Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation" (29 September 2026; police confirmation, Rotterdam court date, FBI breach statement)
- Reuters via Yahoo — "'Reformed hacker' arrested in probe of ShinyHunters, group who hacked FBI" (28 September 2026; arrest confirmation and FBI-hack context)
- Cybernews — "ShinyHunters hacker arrest tied to alleged FBI framing" (28 September 2026; Odido breach context and group statements)