
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
Dutch police confirmed they arrested a 24-year-old man from Amsterdam over the ShinyHunters hacking group. Media reports identify him as Pepijn van der Stap, previously arrested in 2023 for data theft and extortion.
Dutch police have confirmed the arrest of a 24-year-old man from Amsterdam in connection with the ShinyHunters hacking group.
The arrest in Amsterdam
In a post on X on Monday, the national investigations and interventions unit, Politie Landelijke Opsporing en Interventies, said: "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters." Police said he is expected to appear before the Rotterdam District Court on September 29, 2026.
Who the suspect is
Independent security journalist Brian Krebs and the breach-tracking site DataBreaches.Net identified him as Pepijn van der Stap, who also uses the alias Umbreon. He was arrested once before, in 2023, over a series of data thefts and extortion cases. DataBreaches.Net reported that the latest arrest took place on September 15, 2026.
Reporting from 2023 showed that van der Stap worked at the cybersecurity firm Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD). "Working at Hadrian and volunteering at DIVD made me more paranoid about keeping up appearances," he told DataBreaches.Net in June 2023. His LinkedIn profile lists him as the offensive security lead at the Dutch company Neo Security.
The wider campaign
The arrest comes as ShinyHunters claimed responsibility for breaching apply.fbijobs.gov, the U.S. Federal Bureau of Investigation's job application site, in an intrusion that reportedly involved terabytes of sensitive data. A representative told 404 Media that the operation was "a marketing campaign" rather than extortion, and insisted to The Hacker News that the FBI attack was "not extortion, not a threat, not a ransom, and not financially motivated".
The group said it exploited a previously unknown Oracle PeopleSoft flaw. Investigators now assess that it instead used a URL-encoding trick to slip past web application firewall rules protecting the vulnerable PSEMHUB endpoint, tied to CVE-2026-35273, a critical flaw with a CVSS score of 9.8. Google says the activity has targeted higher education, technology, healthcare and government organizations.
PeopleSoft is the latest chapter in a broader extortion drive. Since 2025, attackers linked to ShinyHunters have used voice phishing and stolen OAuth tokens, including through the Salesloft and Drift integrations, to reach corporate Salesforce environments. Researchers at Google and Microsoft track the activity as UNC6040 and UNC6240, and the group claims more than 1.5 billion stolen Salesforce records from over 1,000 organizations.
For defenders the pattern is consistent: the entry point is rarely a flaw in the core platform, but a trusted connection or a compromised token.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.