DKDKCISSPSearch
Threat ResearchDEVELOPING

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.

DKCISSP News DeskThe Hacker News29 Sept 2026, 6:56 pm
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

ET: The Dutch police have confirmed the arrest of a 24-year-old in connection with the ShinyHunters investigation.

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.

In his profile, van der Stap acknowledged his journey "hasn't been a straight line" and that "I've seen security from both sides of the terminal, an experience that taught me hard lessons but ultimately gave me clarity: knowledge is for building and protecting, not breaking." When ShinyHunters was contacted by The Hacker News about the arrest, the group denied having any connection with van der Stap.

Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters .

Useless.” Just days after sources say Van der Stap was detained by Dutch authorities, ShinyHunters claimed credit for an unusually brazen breach at the FBI’s job application site apply.fbijobs.gov.

We do not care what the public says and we are not affected by it nor do we cloud our judgement by external opinions and thoughts." In a statement shared with The Hacker News, the group reiterated again that the attack on the FBI's systems was not extortion and that it's not financially motivated.

According to a story in Wired this month, ShinyHunters and SLSH members briefly partnered earlier this year to help better monetize important stolen credentials collected by TeamPCP , an upstart group that was having great success compromising global code supply chains with malicious software but hadn’t been able to profit much from their stolen data (two alleged leaders of TeamPCP were arrested last month in Australia , and in an interview the TeamPCP leader claimed they made just $20,000).

We are way past this situation in our business operations and we confidently believe we have been successful due to seeing a recent influx of success in our operations." Although the group said it exploited a new zero-day flaw in Oracle PeopleSoft to gain unauthorized access and siphon the data, it's now assessed that ShinyHunters employed a URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate CVE-2026-35273.

25, security experts at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.

The Wired story noted how Mandiant had infiltrated TeamPCP and was secretly responsible for having the crime group’s stolen credentials burned so quickly: Mandiant was secretly feeding those credentials to the major cloud providers like Amazon and Microsoft, who quickly invalidated the stolen keys.

What happened

ET: The Dutch police have confirmed the arrest of a 24-year-old in connection with the ShinyHunters investigation.

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.

What changed

In his profile, van der Stap acknowledged his journey "hasn't been a straight line" and that "I've seen security from both sides of the terminal, an experience that taught me hard lessons but ultimately gave me clarity: knowledge is for building and protecting, not breaking." When ShinyHunters was contacted by The Hacker News about the arrest, the group denied having any connection with van der Stap.

Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters .

Who is affected

Useless.” Just days after sources say Van der Stap was detained by Dutch authorities, ShinyHunters claimed credit for an unusually brazen breach at the FBI’s job application site apply.fbijobs.gov.

We do not care what the public says and we are not affected by it nor do we cloud our judgement by external opinions and thoughts." In a statement shared with The Hacker News, the group reiterated again that the attack on the FBI's systems was not extortion and that it's not financially motivated.

Why it matters

According to a story in Wired this month, ShinyHunters and SLSH members briefly partnered earlier this year to help better monetize important stolen credentials collected by TeamPCP , an upstart group that was having great success compromising global code supply chains with malicious software but hadn’t been able to profit much from their stolen data (two alleged leaders of TeamPCP were arrested last month in Australia , and in an interview the TeamPCP leader claimed they made just $20,000).

We are way past this situation in our business operations and we confidently believe we have been successful due to seeing a recent influx of success in our operations." Although the group said it exploited a new zero-day flaw in Oracle PeopleSoft to gain unauthorized access and siphon the data, it's now assessed that ShinyHunters employed a URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate CVE-2026-35273.

Technical details

25, security experts at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.

The Wired story noted how Mandiant had infiltrated TeamPCP and was secretly responsible for having the crime group’s stolen credentials burned so quickly: Mandiant was secretly feeding those credentials to the major cloud providers like Amazon and Microsoft, who quickly invalidated the stolen keys.

Wired’s Andy Greenberg reported that a few weeks after partnering with TeamPCP, “ShinyHunters went rogue, carrying out its own extortions with TeamPCP’s credentials but without giving the supply-chain hackers their cut.” Mandiant researcher Austin Larsen told KrebsOnSecurity earlier this month that ShinyHunters has been enjoying a successful extortion spree so far this year, and is on track to pull in nearly $100 million in extortion payments from cybercrime victims in 2026.

Response

Although law enforcement officials did not disclose any more details, independent security journalist Brian Krebs and DataBreaches.Net identified the arrested man as Pepijn van der Stap (aka Umbreon), who was previously apprehended in 2023 for his role in a series of data thefts and extortions.

Multiple sources close to the ShinyHunters investigation said the group’s recent risky attacks against the FBI and one of Russia’s most venerated ransomware groups amounted to a major pivot away from the more measured tenor of the hacking gang’s operations.

What security teams should do

Federal Bureau of Investigation's (FBI) job application site apply.fbijobs.gov, stealing terabytes of sensitive data.

ShinyHunters said it gained access to the FBI site and other victims by exploiting a recently patched vulnerability (CVE-2026-35273) in PeopleSoft , a software-as-a-service platform from the software giant Oracle that is broadly used by companies to manage hiring and human resources, benefits and payroll.

What remains unknown

It remains unclear if the Dutch police have matched the Odido caller to a confirmed real-life identity.

Attribution

The Hacker News: Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.

KrebsOnSecurity: Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters .

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility ToolsThe Hacker News · 2 Oct 2026, 4:45 pmMicrosoft is rolling out Linux container support to WSLBleepingComputer · 30 Sept 2026, 6:10 am57% of security execs report challenges with onboarding entry-level staffSC Media · 30 Sept 2026, 12:49 amEx-US soldier gets 70 months for role in AT&T, Snowflake data thefts - Help Net SecurityHelp Net Security · 28 Sept 2026, 2:15 pm