The digital underworld is currently reeling from a volatile power struggle that has blurred the lines between state-sponsored intelligence operations, organized cybercrime, and the personal vendettas of young, brilliant, and deeply troubled individuals. At the center of this firestorm is Pepijn van der Stap, a 24-year-old Dutch software engineer whose double life—oscillating between legitimate cybersecurity research and the destructive activities of the infamous hacker group ShinyHunters—has culminated in his recent arrest by Dutch authorities.
The apprehension of Van der Stap, known in underground forums by the handle "Umbreon," has not led to a cooling of hostilities. Instead, it has triggered an unprecedented surge in brazen, high-stakes attacks by the remaining members of ShinyHunters. In a display of tactical defiance, the group has targeted the United States Federal Bureau of Investigation (FBI) and launched aggressive extortion campaigns against the Russian-linked ransomware syndicate Cl0p, signaling a shift in the global threat landscape.
The Double Life of Pepijn van der Stap
To those who worked with him at the Amsterdam-based cybersecurity startup Hadrian, or at the Dutch Institute for Vulnerability Disclosure (DIVD), Pepijn van der Stap was a talented, if enigmatic, colleague. By day, he was a software engineer dedicated to defending digital infrastructure. By night, under the moniker "Umbreon," he was a prolific cybercriminal who weaponized his skills to pillage databases and extort victims across the globe.
Van der Stap’s criminal career is far from his first brush with the law. In 2023, he was convicted in the Netherlands for a series of data thefts and extortion schemes that netted between €1.5 million and €2.7 million. During his trial, he candidly described his existence as a "Dr. Jekyll and Mr. Hyde" scenario. He admitted to using his handle to leak sensitive data on platforms like RaidForums and Breached, while simultaneously presenting himself as a reformed security researcher.
Following his 2023 conviction, Van der Stap was sentenced to four years in prison, with one year suspended. His time behind bars was marked by a request to remain in custody rather than return home, citing a lack of access to specialized treatment for his psychological struggles, including PTSD stemming from childhood trauma. He was released in December 2025.
By September 2026, Van der Stap appeared to be attempting a genuine reintegration into society. In an interview with KrebsOnSecurity on September 9, he characterized himself as a man striving to make amends and contribute positively to the cybersecurity community. He had even secured a position as the offensive security lead at the Dutch firm Neo Security. However, the veneer of stability cracked quickly; within days of the interview, Van der Stap ceased all communication with associates, shortly before Dutch police executed a raid on his residence around September 16.

Chronology of an Escalation
The recent escalation of hostilities involving ShinyHunters can be traced back to the beginning of 2026, a year characterized by a chaotic realignment of cybercriminal factions.
- February 2026: A native Dutch-speaking member of ShinyHunters successfully social-engineered an employee at Odido, the Netherlands’ largest mobile telecommunications provider. By tricking the employee into accessing a spoofed login portal, the group exfiltrated the personal data of over 6.2 million Dutch citizens.
- September 7, 2026: Dutch police released an audio recording of the Odido attack, appealing to the public for help in identifying the suspect. ShinyHunters publicly confirmed the caller was a member of their collective.
- September 16, 2026: Dutch authorities arrest Van der Stap in connection with the ShinyHunters investigation. Reports indicate that police were seen removing significant hardware and assets from his residence.
- Late September 2026: Following the arrest, ShinyHunters launched a series of "revenge" attacks, most notably breaching the FBI’s job application portal (apply.fbijobs.gov).
- September 29, 2026: Van der Stap is scheduled to appear before the Rotterdam District Court as the investigation continues.
The "Rey" Factor: A New Guard in the Underworld
The erratic behavior of ShinyHunters—moving from data harvesting to direct confrontation with the FBI and the Russian ransomware gang Cl0p—has been attributed to a leadership transition. Sources close to the investigation point to a teenager from Amman, Jordan, known as "Rey," as the current architect of the group’s aggressive new strategy.
Rey is an operative within "ScatteredLapsussHunters" (SLSH), an amalgamation of the defunct LAPSUS$ group, Scattered Spider, and the remnants of ShinyHunters. Intelligence suggests that Rey has been locked in a bitter dispute with Van der Stap over the control of the ShinyHunters brand and its massive repository of stolen data.
Analysts believe that the inclusion of the "Umbreon" Pokémon imagery in the FBI job portal hack was not an homage, but a calculated "false flag" maneuver by Rey. By plastering the FBI site with the signature of the Dutch hacker, Rey was likely attempting to frame Van der Stap for the breach, effectively burning his rival’s bridges while solidifying his own control over the collective.
Rey’s own profile is one of youthful hubris. Despite being identified by cybersecurity firm KELA in 2025, he has remained active, even taunting the FBI and Cl0p on social media with memes depicting the destruction of New York’s Twin Towers, overlaid with references to his ongoing extortion operations.
The PeopleSoft Vulnerability: A Global Catalyst
The success of these recent breaches, including the FBI incident, rests on the exploitation of a critical vulnerability (CVE-2026-35273) in Oracle’s PeopleSoft software. This platform is the backbone of human resources and payroll operations for thousands of government agencies and private corporations.

While Oracle issued a patch for the flaw, ShinyHunters proved their technical sophistication by utilizing URL-encoding tricks to bypass the web application firewall (WAF) rules that had been recommended by security researchers at Mandiant. The result was a mass-exploitation campaign that breached systems across the healthcare, agriculture, technology, and government sectors.
The FBI has confirmed the breach, which exposed the sensitive psychiatric and medical records of over 5,000 employees, including special agents and personnel involved in high-level cybercrime investigations. This level of intrusion—targeting the personal lives of the very agents hunting them—represents a paradigm shift in how criminal hacking groups perceive their own immunity.
Official Responses and Implications
The Dutch police have been notably aggressive in their response to the Odido incident and the subsequent identification of the ShinyHunters collective. Their public appeal for information regarding the Odido caller demonstrates a willingness to engage in high-profile public investigations, even when dealing with sophisticated, distributed threats.
However, the response from the criminal underworld has been equally blunt. In a statement provided to the NL Times, ShinyHunters mocked the Dutch authorities, labeling them "incompetent" and "useless." They further claimed to be providing their arrested member with full legal and financial support, signaling that they intend to maintain their operations regardless of individual casualties.
The implications for international cybersecurity are severe. The partnership—and subsequent fallout—between ShinyHunters, SLSH, and the now-defunct TeamPCP suggests that the "gig economy" of cybercrime is increasingly volatile. When hackers stop cooperating and start burning each other’s credentials, the victims are often the ones caught in the crossfire.
As Mandiant researcher Austin Larsen noted, ShinyHunters is currently on a trajectory to generate nearly $100 million in extortion revenue for 2026. This massive influx of capital allows the group to act as a quasi-corporate entity, providing "employee benefits" like legal counsel, which in turn encourages more young, talented hackers—like Van der Stap and Rey—to enter the fray.

Conclusion: A Cycle of Hubris
Van der Stap’s own words in previous interviews offer a chilling insight into the mindset of these modern digital outlaws. He claimed that he was never truly motivated by money, but by the "collecting" of data—a compulsive need to organize and hoard information. This drive, untethered from ethical constraints, turned a gifted developer into a national security threat.
The case of the "Umbreon" hacker serves as a stark warning to the cybersecurity industry. It highlights the dangers posed by "insider-threat" actors who possess the skills to build defenses while simultaneously possessing the malice to dismantle them. As the Dutch courts prepare to hear the case against Van der Stap, the digital world watches with bated breath, knowing that the arrest of one individual has done little to stop the momentum of a machine fueled by global discord and teenage ego.
The battle between the law and the likes of ShinyHunters is no longer just about data; it is about the structural integrity of the institutions that rely on the very systems these hackers have learned to exploit. Whether the authorities can dismantle the collective, or if they are merely pruning the branches of a much deeper, more pervasive rot, remains the defining question of the year.
