ShinyHunters Probe Reaches the Netherlands as Attacks Shift Toward Higher-Risk Targets

Dutch police detained convicted hacker Pepijn van der Stap in ShinyHunters probe amid Odido theft, FBI portal breach and PeopleSoft flaw exploitation.

ShinyHunters Probe Reaches the Netherlands as Attacks Shift Toward Higher-Risk Targets
Data Breaches

Illustrative image generated with AI

Listen to this articleAudio edition · 11 min

Dutch authorities detain a previously convicted hacker

Dutch authorities have arrested a 23-year-old convicted cybercriminal suspected of helping ShinyHunters steal data and extort victims.

Three people familiar with the investigation identified the suspect as Pepijn van der Stap, from Almere and Lelystad in the Netherlands. Two said he was detained on or around September 16 and subsequently held for questioning. Another person reportedly witnessed authorities removing items from his residence.

Police have not publicly confirmed the suspect’s identity. They have also not said whether he is the Dutch-speaking ShinyHunters member sought in connection with a separate attack against mobile operator Odido.

Van der Stap previously used the alias “Umbreon,” according to reporting on the investigation. In 2023, he was convicted over data theft and extortion operations that prosecutors estimated had generated between €1.5 million and €2.7 million.

He admitted stealing information and pressuring victims, including through posts on the now-closed RaidForums and Breached cybercrime forums. He received a four-year prison sentence, with one year suspended, and was released in December 2025.

An image documented by threat-intelligence company KELA showed the Umbreon account advertising a database containing information on 2.3 million people in the Netherlands on RaidForums in September 2021.

On September 9, 2026, van der Stap said in an interview that he was rebuilding his life, addressing civil claims and trying to compensate former victims. He was working as offensive security lead at Dutch company Neo Security, which has not commented publicly.

His earlier roles included software engineering work at Amsterdam security startup Hadrian and volunteering for the Dutch Institute for Vulnerability Disclosure, or DIVD. After the interview, he stopped responding to messages. People close to him reportedly could not reach him during the following two weeks.

Police have not connected the arrest to the Odido caller

The unresolved question is whether the detained suspect participated in the ShinyHunters intrusion at Odido, the Netherlands’ largest mobile telecommunications provider.

In February 2026, a native Dutch speaker allegedly persuaded an Odido employee to enter credentials into a fraudulent website. That social-engineering operation enabled the theft of data associated with more than 6.2 million people in the Netherlands.

Dutch authorities later asked the public to help identify the caller from a recording. ShinyHunters told Dutch media that the speaker belonged to the group and said it was providing the individual with emotional, financial and legal assistance, including a defense lawyer.

Investigators have not announced a confirmed real-world identity for that caller. The police unit handling the Odido case also declined to address the reported arrest.

ShinyHunters has since directed threats and insults at Dutch police and warned of another major data theft in the country. Those statements do not establish who conducted the Odido operation or whether it is connected to van der Stap.

FBI breach marks an escalation in the group’s targeting

In the days following the reported arrest, ShinyHunters claimed responsibility for compromising the FBI’s recruitment portal, apply.fbijobs.gov, and for extorting the Russian ransomware group Cl0p.

The FBI confirmed the website intrusion. Reports on the stolen material said it included Social Security numbers and other personal information belonging to more than 5,000 officials, together with job titles or team assignments.

The affected records reportedly referenced special agents, threat intake examiners, members of a major cybercrime unit and personnel investigating foreign state-backed cyber operations. Sensitive psychiatric and medical documents were also found among files shared by ShinyHunters.

The compromised FBI site displayed an ASCII-art image of Umbreon and a message claiming ShinyHunters had seized it. The image matched artwork used during the group’s 2020 compromise of the Hackforums cybercrime forum.

People close to the investigation characterized the attacks against the FBI and Cl0p as a move toward more dangerous targets. However, the meaning of the Umbreon image remains disputed. It may represent branding, a reference to van der Stap’s former alias, or an attempt by another actor to implicate him.

No public evidence resolves that question.

PeopleSoft flaw gave attackers unauthenticated access

ShinyHunters said it used CVE-2026-35273 against the FBI portal and other organizations. The group reportedly began exploiting the vulnerability as a zero-day in June.

The flaw affects the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools. An unauthenticated attacker with HTTP network access can exploit it without user interaction and potentially take over the PeopleTools environment.

Its NVD CVSS v3.1 score is 9.8, with the vector:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The vulnerability is categorized as CWE-306, indicating that authentication is missing for a critical function. Successful exploitation can have high confidentiality, integrity and availability consequences.

There is a discrepancy in the published version information. The NVD description identifies PeopleTools 8.61 and 8.62 as affected, while a separate NVD product-and-version field lists only 8.61. Organizations running either branch should verify their exposure against Oracle’s update documentation rather than treating 8.62 as unaffected.

Mandiant and the Google Threat Intelligence Group reported on September 25 that ShinyHunters had exploited the flaw at scale. The campaign affected dozens of systems across government, healthcare, higher education, technology, agriculture and transportation.

Oracle has released a fix. Mandiant also supplied web application firewall rules for environments unable to patch immediately, but ShinyHunters reportedly bypassed those rules using URL encoding. The WAF configuration therefore cannot be considered an adequate substitute for remediation.

CISA treats the vulnerability as an active operational threat

CISA added CVE-2026-35273 to its Known Exploited Vulnerabilities catalog on 2026-06-12. The remediation deadline for U.S. federal civilian agencies was 2026-06-15, and CISA records the flaw as having been used in ransomware campaigns.

The required action is to apply vendor mitigations while complying with BOD 26-04, Prioritizing Security Updates Based on Risk, and CISA’s Forensics Triage Requirements. Organizations must also evaluate each asset’s internet exposure and follow the applicable BOD 26-04 patching guidance.

For cloud services, agencies must apply the relevant BOD 26-04 measures. If effective mitigations are unavailable, CISA directs them to discontinue use of the product.

CVE-2026-35273 is not Oracle’s only recent KEV entry. Three other vulnerabilities associated with the vendor entered the catalog within the last 90 days: CVE-2015-5287 on 2026-08-26, CVE-2026-21962 on 2026-08-24, and CVE-2026-46817 on 2026-07-15.

For PeopleSoft operators, the immediate priorities are clear:

  • Apply Oracle’s security update rather than relying solely on WAF filtering.
  • Identify internet-exposed PeopleTools systems, including versions 8.61 and 8.62.
  • Conduct forensic triage in line with CISA requirements.
  • Investigate systems that remained exposed after exploitation began in June.
  • Do not assume Mandiant’s original WAF rules block URL-encoded attack variants.

No specific compromise indicators were disclosed beyond the reported exploitation method and affected product.

Rivalries complicate attribution inside ShinyHunters

Sources familiar with the criminal ecosystem attributed ShinyHunters’ recent escalation to an alleged takeover by Rey, a teenage cybercriminal from Amman, Jordan. Rey has been associated with ScatteredLapsussHunters, or SLSH, a label combining Scattered Spider, LAPSUS$ and ShinyHunters.

Those sources claimed Rey and van der Stap had disputed control of the ShinyHunters name and stolen data. They also suggested the Umbreon artwork on the FBI site may have been selected to direct suspicion toward van der Stap. These allegations have not been independently established.

KELA publicly identified Rey in March 2025. An account attributed to him, Ryan Moran/@rmoskovy, posted an image on September 22 depicting the FBI and Cl0p as attack targets, with a large Umbreon figure in the foreground. After an interview request on September 24, the long-running account was deleted.

The tensions also extend to TeamPCP, a group linked to malicious software-supply-chain compromises. ShinyHunters and SLSH members reportedly worked with TeamPCP to monetize stolen credentials before the participants began blaming one another when cloud providers invalidated them. Two alleged TeamPCP leaders were arrested in Australia last month.

Meanwhile, a Mandiant researcher estimated earlier this month that ShinyHunters was on course to receive nearly $100 million in extortion payments during 2026.

DIVD separately disclosed last week that it was investigating an internal security incident that appeared to involve malicious use of artificial intelligence. A spokesperson said there was no apparent connection to ShinyHunters and no indication that a former volunteer’s work was involved. No further technical details or mitigations have been released.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →