Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.

ET: The Dutch police have confirmed the arrest of a 24-year-old in connection with the ShinyHunters investigation.
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.
In his profile, van der Stap acknowledged his journey "hasn't been a straight line" and that "I've seen security from both sides of the terminal, an experience that taught me hard lessons but ultimately gave me clarity: knowledge is for building and protecting, not breaking." When ShinyHunters was contacted by The Hacker News about the arrest, the group denied having any connection with van der Stap.
Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters .
Useless.” Just days after sources say Van der Stap was detained by Dutch authorities, ShinyHunters claimed credit for an unusually brazen breach at the FBI’s job application site apply.fbijobs.gov.
We do not care what the public says and we are not affected by it nor do we cloud our judgement by external opinions and thoughts." In a statement shared with The Hacker News, the group reiterated again that the attack on the FBI's systems was not extortion and that it's not financially motivated.
According to a story in Wired this month, ShinyHunters and SLSH members briefly partnered earlier this year to help better monetize important stolen credentials collected by TeamPCP , an upstart group that was having great success compromising global code supply chains with malicious software but hadn’t been able to profit much from their stolen data (two alleged leaders of TeamPCP were arrested last month in Australia , and in an interview the TeamPCP leader claimed they made just $20,000).
We are way past this situation in our business operations and we confidently believe we have been successful due to seeing a recent influx of success in our operations." Although the group said it exploited a new zero-day flaw in Oracle PeopleSoft to gain unauthorized access and siphon the data, it's now assessed that ShinyHunters employed a URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate CVE-2026-35273.
25, security experts at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
The Wired story noted how Mandiant had infiltrated TeamPCP and was secretly responsible for having the crime group’s stolen credentials burned so quickly: Mandiant was secretly feeding those credentials to the major cloud providers like Amazon and Microsoft, who quickly invalidated the stolen keys.
What happened
ET: The Dutch police have confirmed the arrest of a 24-year-old in connection with the ShinyHunters investigation.
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.
What changed
In his profile, van der Stap acknowledged his journey "hasn't been a straight line" and that "I've seen security from both sides of the terminal, an experience that taught me hard lessons but ultimately gave me clarity: knowledge is for building and protecting, not breaking." When ShinyHunters was contacted by The Hacker News about the arrest, the group denied having any connection with van der Stap.
Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters .
Who is affected
Useless.” Just days after sources say Van der Stap was detained by Dutch authorities, ShinyHunters claimed credit for an unusually brazen breach at the FBI’s job application site apply.fbijobs.gov.
We do not care what the public says and we are not affected by it nor do we cloud our judgement by external opinions and thoughts." In a statement shared with The Hacker News, the group reiterated again that the attack on the FBI's systems was not extortion and that it's not financially motivated.
Why it matters
According to a story in Wired this month, ShinyHunters and SLSH members briefly partnered earlier this year to help better monetize important stolen credentials collected by TeamPCP , an upstart group that was having great success compromising global code supply chains with malicious software but hadn’t been able to profit much from their stolen data (two alleged leaders of TeamPCP were arrested last month in Australia , and in an interview the TeamPCP leader claimed they made just $20,000).
We are way past this situation in our business operations and we confidently believe we have been successful due to seeing a recent influx of success in our operations." Although the group said it exploited a new zero-day flaw in Oracle PeopleSoft to gain unauthorized access and siphon the data, it's now assessed that ShinyHunters employed a URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate CVE-2026-35273.
Technical details
25, security experts at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
The Wired story noted how Mandiant had infiltrated TeamPCP and was secretly responsible for having the crime group’s stolen credentials burned so quickly: Mandiant was secretly feeding those credentials to the major cloud providers like Amazon and Microsoft, who quickly invalidated the stolen keys.
Wired’s Andy Greenberg reported that a few weeks after partnering with TeamPCP, “ShinyHunters went rogue, carrying out its own extortions with TeamPCP’s credentials but without giving the supply-chain hackers their cut.” Mandiant researcher Austin Larsen told KrebsOnSecurity earlier this month that ShinyHunters has been enjoying a successful extortion spree so far this year, and is on track to pull in nearly $100 million in extortion payments from cybercrime victims in 2026.
Response
Although law enforcement officials did not disclose any more details, independent security journalist Brian Krebs and DataBreaches.Net identified the arrested man as Pepijn van der Stap (aka Umbreon), who was previously apprehended in 2023 for his role in a series of data thefts and extortions.
Multiple sources close to the ShinyHunters investigation said the group’s recent risky attacks against the FBI and one of Russia’s most venerated ransomware groups amounted to a major pivot away from the more measured tenor of the hacking gang’s operations.
What security teams should do
Federal Bureau of Investigation's (FBI) job application site apply.fbijobs.gov, stealing terabytes of sensitive data.
ShinyHunters said it gained access to the FBI site and other victims by exploiting a recently patched vulnerability (CVE-2026-35273) in PeopleSoft , a software-as-a-service platform from the software giant Oracle that is broadly used by companies to manage hiring and human resources, benefits and payroll.
What remains unknown
It remains unclear if the Dutch police have matched the Odido caller to a confirmed real-life identity.
Attribution
The Hacker News: Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.
KrebsOnSecurity: Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters .
What to watch next
Watch for new exploitation reports and updated indicators of compromise.