<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation-krebs-on-security-ch7sexabs" -->

---
title: Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters...
description: Dutch authorities arrested Pepijn van der Stap, a 23-year-old convicted cybercriminal known as &#x27;Umbreon,&#x27; on suspicion of aiding the ShinyHunters hacking...
canonical: https://daily.dev/posts/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation-krebs-on-security-ch7sexabs
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security | daily.dev
og:description: Dutch authorities arrested Pepijn van der Stap, a 23-year-old convicted cybercriminal known as &#x27;Umbreon,&#x27; on suspicion of aiding the ShinyHunters hacking...
og:url: https://daily.dev/posts/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation-krebs-on-security-ch7sexabs
og:image: https://api.daily.dev/og/posts/cH7SExabS.png
og:image:alt: Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

**[Krebs on Security](https://daily.dev/sources/krebsonsecurity)** · 9 min read · 0 upvotes · 0 comments

## Summary

Dutch authorities arrested Pepijn van der Stap, a 23-year-old convicted cybercriminal known as 'Umbreon,' on suspicion of aiding the ShinyHunters hacking collective, just weeks after he portrayed himself to KrebsOnSecurity as a reformed hacker working in offensive security. Following his arrest, ShinyHunters escalated its activity dramatically, breaching the FBI's job application site (exposing SSNs and psychiatric records of over 5,000 officials) and extorting the Russian ransomware group Cl0p, exploiting a patched Oracle PeopleSoft vulnerability (CVE-2026-35273) via a WAF bypass trick. Sources say the group is now led by a Jordanian teenager known as Rey, who runs ScatteredLapsussHunters and may have used Umbreon imagery to frame the arrested Dutchman. Mandiant estimates ShinyHunters is on track for nearly $100 million in extortion payments in 2026.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation>

## Questions this post answers

### How did ShinyHunters breach the FBI's job application site?

ShinyHunters exploited CVE-2026-35273, a vulnerability in Oracle's PeopleSoft platform, to compromise the FBI's apply.fbijobs.gov portal. The group then used a URL-encoding trick to bypass web application firewall rules that Mandiant had recommended as a mitigation. Stolen data included Social Security numbers, job titles, and psychiatric and medical files for more than 5,000 FBI officials.

_Security teams tracking PeopleSoft exploitation and WAF bypass techniques can follow the developing coverage on daily.dev._

### Who is Pepijn van der Stap and why was he arrested in the Netherlands?

Pepijn van der Stap is a 23-year-old Dutch man, previously convicted in 2023 for data theft and extortion under the hacker alias Umbreon, who was arrested again around September 16 on suspicion of aiding ShinyHunters. He had recently described himself to a security journalist as reformed and was working as an offensive security lead at Neo Security before going silent and being detained.

_Anyone following the ShinyHunters investigation can track updates on the case through daily.dev._

### Who is Rey and what is his connection to ShinyHunters and ScatteredLapsussHunters?

Rey is a teenage cybercriminal from Amman, Jordan, first publicly identified by security firm KELA in March 2025, who reportedly took over leadership of ShinyHunters. He operates within ScatteredLapsussHunters (SLSH), a group described as an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters, and sources say he had a dispute with van der Stap over control of the ShinyHunters brand.

_Developers and defenders mapping threat actor groups can keep up with cybercrime attribution stories on daily.dev._

## Similar posts on daily.dev

- [ShinyHunters Wage Broad Corporate Extortion Spree – Krebs on Security](https://daily.dev/posts/shinyhunters-wage-broad-corporate-extortion-spree-krebs-on-security-w8mqeq1jg) · Krebs on Security · 1 upvotes · 0 comments
- [Police suspects Dutch hackers were involved in Odido breach](https://daily.dev/posts/police-suspects-dutch-hackers-were-involved-in-odido-breach-uhz9jdbvp) · BleepingComputer · 0 upvotes · 0 comments
- [Dutch cops back Odido as ShinyHunters leaks continue](https://daily.dev/posts/dutch-cops-back-odido-as-shinyhunters-leaks-continue-iruploltq) · The Register · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#data-breach](https://daily.dev/tags/data-breach)

[View this post on daily.dev](https://daily.dev/posts/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation-krebs-on-security-ch7sexabs)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security","url":"https://daily.dev/posts/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation-krebs-on-security-ch7sexabs","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation-krebs-on-security-ch7sexabs"},"datePublished":"2026-09-28T15:14:41.250Z","dateModified":"2026-09-28T15:17:25.604Z","description":"Dutch authorities arrested Pepijn van der Stap, a 23-year-old convicted cybercriminal known as 'Umbreon,' on suspicion of aiding the ShinyHunters hacking...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9fd274140e490b4e3a6bc2f3218f4ae5?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9fd274140e490b4e3a6bc2f3218f4ae5?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Krebs on Security","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Krebs on Security","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/deb3e417ddef4d0e8cc4d704becf6004","url":"https://daily.dev/sources/krebsonsecurity"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation-krebs-on-security-ch7sexabs","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,data-breach","timeRequired":"PT9M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Krebs on Security","item":"https://daily.dev/sources/krebsonsecurity"},{"@type":"ListItem","position":3,"name":"Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation-krebs-on-security-ch7sexabs#faq","mainEntity":[{"@type":"Question","name":"How did ShinyHunters breach the FBI's job application site?","acceptedAnswer":{"@type":"Answer","text":"ShinyHunters exploited CVE-2026-35273, a vulnerability in Oracle's PeopleSoft platform, to compromise the FBI's apply.fbijobs.gov portal. The group then used a URL-encoding trick to bypass web application firewall rules that Mandiant had recommended as a mitigation. Stolen data included Social Security numbers, job titles, and psychiatric and medical files for more than 5,000 FBI officials. Security teams tracking PeopleSoft exploitation and WAF bypass techniques can follow the developing coverage on daily.dev."}},{"@type":"Question","name":"Who is Pepijn van der Stap and why was he arrested in the Netherlands?","acceptedAnswer":{"@type":"Answer","text":"Pepijn van der Stap is a 23-year-old Dutch man, previously convicted in 2023 for data theft and extortion under the hacker alias Umbreon, who was arrested again around September 16 on suspicion of aiding ShinyHunters. He had recently described himself to a security journalist as reformed and was working as an offensive security lead at Neo Security before going silent and being detained. Anyone following the ShinyHunters investigation can track updates on the case through daily.dev."}},{"@type":"Question","name":"Who is Rey and what is his connection to ShinyHunters and ScatteredLapsussHunters?","acceptedAnswer":{"@type":"Answer","text":"Rey is a teenage cybercriminal from Amman, Jordan, first publicly identified by security firm KELA in March 2025, who reportedly took over leadership of ShinyHunters. He operates within ScatteredLapsussHunters (SLSH), a group described as an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters, and sources say he had a dispute with van der Stap over control of the ShinyHunters brand. Developers and defenders mapping threat actor groups can keep up with cybercrime attribution stories on daily.dev."}}]}
```

