Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Dutch Police Arrest 'Reformed' Hacker in Shiny Hunters Investigation: A Tale of Betrayal, Extortion, and the Dark Side of Cybersecurity




Dutch Police Arrest 'Reformed' Hacker in Shiny Hunters Investigation: A Tale of Betrayal, Extortion, and the Dark Side of Cybersecurity

A 23-year-old Dutchman, who had previously claimed to have reformed, has been arrested by Dutch authorities in connection with ShinyHunters' recent attacks on the FBI and the Russian ransomware group Cl0p. The suspect, Pepijn van der Stap, had been using his alias "Umbreon" to extort victims and post their data on English language hacking communities. The investigation into ShinyHunters' recent attacks has raised concerns about the group's motivations and capabilities, with some speculating that the group's takeover by a teenage cybercriminal from Amman, Jordan, may be driven by a desire for control and profit. This article provides a detailed examination of the context surrounding van der Stap's arrest and the implications of ShinyHunters' recent attacks on the cybersecurity landscape.

  • Pepijn van der Stap, a 23-year-old Dutchman, was arrested by authorities in September 2023 for his role as the notorious hacker "Umbreon" who extorted victims and posted their data on hacking communities.
  • Van der Stap was found to be leading a double life, working as a software engineer at Hadrian and volunteering at a nonprofit security research group, while engaging in cybercrime activities.
  • ShinyHunters, a hacking group, was taken over by a teenage cybercriminal from Amman, Jordan, who operates as part of a cybercrime group called ScatteredLapsussHunters (SLSH).
  • The takeover led to a shift in ShinyHunters' tactics, resulting in the theft of highly sensitive data from the FBI and a Russian ransomware group, Cl0p.
  • The group's use of a URL-encoding trick and the Umbreon image has raised concerns about their technical capabilities and motivations.
  • The ShinyHunters group is reportedly on track to pull in nearly $100 million in extortion payments from cybercrime victims in 2026.



  • The world of cybersecurity is fraught with complexities, and the story of Pepijn van der Stap, a 23-year-old Dutchman arrested by authorities last month, serves as a stark reminder of the darker aspects of the industry. Van der Stap, who had previously claimed to have reformed and was working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian, was found to be leading a double life as the notorious hacker "Umbreon."

    According to sources familiar with the matter, van der Stap was arrested on or around September 16 and has been held in custody for questioning since. The Dutch police unit handling the investigation revealed that van der Stap had been using his alias "Umbreon" to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached. By day, van der Stap worked as a software engineer at Hadrian, a position he had held since 2023, while volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research group.

    Van der Stap's admission of his dual lives came during his trial in late 2023, where he confessed to his data theft and extortion activity, earning a four-year prison sentence, with one year suspended. During his trial, van der Stap opted to remain in custody for a time rather than at home, citing ongoing psychological issues related to childhood trauma. He was released from prison in December 2025, only to be re-arrested a few weeks later.

    The latest twist in the van der Stap saga comes in the wake of ShinyHunters' brazen attacks on the FBI and the Russian ransomware group Cl0p. According to sources close to the investigation, ShinyHunters was taken over by a teenage cybercriminal from Amman, Jordan, who operates as part of a cybercrime group called ScatteredLapsussHunters (SLSH). This group is an amalgamation of three hacking groups: Scattered Spider, LAPSUS$, and ShinyHunters.

    It appears that the takeover led to a dramatic shift in ShinyHunters' tactics, with the group carrying out more aggressive and extensive attacks. The group's recent attacks on the FBI and Cl0p have resulted in the theft of highly sensitive data, including Social Security numbers and personal information on more than 5,000 officials. The FBI issued a brief statement confirming the hack and revealed that ShinyHunters exploited a recently patched vulnerability in PeopleSoft, a software-as-a-service platform used by companies to manage hiring and human resources, benefits, and payroll.

    The ShinyHunters group's use of a URL-encoding trick to bypass Mandiant's suggested web application firewall rules designed to mitigate the threat from the PeopleSoft flaw has raised concerns about the group's technical capabilities. The group's use of the Umbreon image, a character from the Pokémon franchise, in their defacement messages has also sparked interest, with multiple sources suggesting that this image was likely used to pin the hack on van der Stap.

    The ShinyHunters group's sudden shift in tactics has left many in the cybersecurity community wondering about the motivations behind the group's actions. Some speculate that the group's takeover by SLSH may be driven by a desire for control and profit, with the group reportedly on track to pull in nearly $100 million in extortion payments from cybercrime victims in 2026.

    In a statement, ShinyHunters confirmed that the suspect in the audio clip is a member of the hacker collective, stating that the group's team member has their full support, emotionally, mentally, and financially. However, the Dutch police unit handling the investigation remains tight-lipped about the matter, with no confirmed real-life identity for the Odido caller.

    The story of Pepijn van der Stap serves as a cautionary tale about the dangers of the dark web and the ease with which individuals can hide their true identities. Van der Stap's journey from a reformed hacker to a convicted cybercriminal is a stark reminder of the complexities and nuances of the cybersecurity world. As the cybersecurity landscape continues to evolve, it is essential to remain vigilant and aware of the tactics and motivations of groups like ShinyHunters and SLSH.

    In conclusion, the arrest of Pepijn van der Stap by Dutch authorities marks a significant turning point in the investigation into ShinyHunters' recent attacks. As the cybersecurity community continues to grapple with the implications of these attacks, it is essential to examine the complex web of motivations and alliances that drive groups like ShinyHunters and SLSH.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Dutch-Police-Arrest-Reformed-Hacker-in-Shiny-Hunters-Investigation-A-Tale-of-Betrayal-Extortion-and-the-Dark-Side-of-Cybersecurity-ehn.shtml

  • https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/


  • Published: Mon Sep 28 12:03:16 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us