The Shadow of Umbreon: Inside the Global Chaos of the ShinyHunters Syndicate

The arrest of 24-year-old Dutch national Pepijn van der Stap on September 16, 2026, has sent shockwaves through the global cybersecurity landscape. While the arrest of a convicted cybercriminal might typically signal a victory for law enforcement, in this instance, it acted as a catalyst for an unprecedented surge in digital aggression. Within days of van der Stap’s detention, the notorious hacker collective known as ShinyHunters—with whom the suspect is alleged to have collaborated—launched a series of brazen, high-profile attacks, targeting the Federal Bureau of Investigation (FBI) and the Russian ransomware syndicate Cl0p.

This escalating conflict reveals a volatile underworld where allegiances are temporary, branding is weaponized, and the line between "white-hat" security research and black-hat criminality is dangerously blurred.

A Double Life Exposed

Pepijn van der Stap, a resident of Almere and Lelystad, has long lived a life defined by contradiction. Known in dark-web forums by the handle "Umbreon"—a nod to the Pokémon character—van der Stap was a central figure in the breach of millions of records on platforms like RaidForums and Breached.

His history with the law is extensive. In 2023, he was convicted for a spree of data thefts and extortions that prosecutors valued between €1.5 million and €2.7 million. During his trial, he painted a portrait of a "Dr. Jekyll and Mr. Hyde" existence: by night, an extortionist; by day, a software engineer at the Amsterdam-based cybersecurity startup Hadrian and a volunteer at the Dutch Institute for Vulnerability Disclosure (DIVD).

Despite serving a four-year sentence, much of which involved self-imposed incarceration to manage psychological trauma, van der Stap’s release in December 2025 did not mark the end of his digital shadow. Following his recent arrest, reports from the Dutch news outlet RTL have added a grim layer to the investigation: authorities now suspect van der Stap of attempting to orchestrate at least two murders abroad, suggesting an evolution from data theft to violent, real-world criminal enterprise.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Chronology of a Digital Meltdown

The recent turmoil began in February 2026, when a native Dutch-speaking member of ShinyHunters successfully social-engineered their way into Odido, the Netherlands’ largest mobile telecommunications provider. Using a spoofed website, the attacker compromised the data of over 6.2 million Dutch citizens.

The Dutch police’s public appeal for help identifying the voice in the Odido recording inadvertently triggered a volatile response from ShinyHunters. In a statement to the NL Times, the group pledged their full support to the suspect, stating, "We do not look down on our staff and members; we take excellent care of them." They further mocked Dutch authorities, calling them "incompetent" and "irrelevant," and threatened further large-scale theft within the country.

The situation spiraled further following van der Stap’s September arrest. In a display of tactical bravado, ShinyHunters claimed responsibility for breaching apply.fbijobs.gov, the FBI’s recruitment portal. The data leak, which included sensitive personal information and psychiatric files of over 5,000 FBI personnel, was marked with the signature "Umbreon" ASCII art. This branding was widely interpreted by security analysts as a strategic move by the group’s new leadership to frame the imprisoned van der Stap for the breach.

Supporting Data: The PeopleSoft Exploitation

The breach of the FBI and numerous other global entities was facilitated by a sophisticated exploitation of a zero-day vulnerability (CVE-2026-35273) in Oracle’s PeopleSoft platform. While Oracle released a patch for the flaw, ShinyHunters demonstrated high technical proficiency by utilizing URL-encoding tricks to bypass web application firewall (WAF) mitigations suggested by Mandiant.

According to a September 25 report by Mandiant and the Google Threat Intelligence Group (GTIG), the group has conducted mass-exploitation across industries ranging from healthcare and agriculture to transportation and government. Experts estimate that ShinyHunters is currently on track to generate nearly $100 million in extortion revenue throughout 2026, a staggering sum that highlights the group’s transition from petty data collectors to a tier-one global cyber threat.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

The Rise of "Rey" and the SLSH Alliance

The shift in ShinyHunters’ operational tempo—moving from measured data theft to high-stakes, aggressive extortion—is attributed by investigators to the influence of a teenage cybercriminal based in Amman, Jordan, known as "Rey."

Rey operates as a pivotal figure within the "ScatteredLapsussHunters" (SLSH) alliance, a conglomerate formed from the remnants of the Scattered Spider, LAPSUS$, and ShinyHunters groups. Sources familiar with the internal dynamics of these gangs report a deep-seated rivalry between Rey and van der Stap over the control of the ShinyHunters brand. By utilizing the Umbreon moniker in the FBI attack, Rey appears to be conducting a "false flag" operation designed to alienate van der Stap from his past while asserting dominance over the collective.

Rey’s own profile, first identified by KELA in 2025, depicts a youth deeply entrenched in the ransomware economy. Despite attempts by his family and the media to engage with him, Rey has remained evasive, recently deleting his primary social media presence after being contacted by investigators.

Official Responses and Strategic Implications

The international response to this escalation has been swift. On the heels of the FBI breach, the bureau released a direct warning to the remaining members of the group. Brett Leatherman, Assistant Director of the FBI’s Cyber Division, stated: "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left… I suggest you reach out to us while the choice is still yours."

The Dutch authorities remain tight-lipped on the specifics of the ongoing investigation, though they have confirmed that van der Stap is scheduled for a court appearance in the Rotterdam District Court.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

The implications of this saga are profound. First, the incident illustrates the extreme risks posed by "professionalized" hacker collectives that operate with the financial and logistical support of a corporation. The ability of these groups to hire defense lawyers and provide "mental health support" to their members represents a terrifying new frontier in criminal enterprise.

Second, the case underscores the fragility of global supply chains. The reliance on platforms like Oracle’s PeopleSoft means that a single vulnerability can compromise the entire hiring and payroll infrastructure of the most sensitive national security organizations in the world.

Finally, the "Umbreon" saga is a cautionary tale for the cybersecurity industry. It reveals that even individuals working within the "defensive" sector—such as van der Stap’s roles at Hadrian and DIVD—may possess the technical skill sets to facilitate massive destruction if their underlying psychological compulsions remain unaddressed. As the investigation continues, the focus will likely shift toward dismantling the SLSH alliance and determining the extent of the collaboration between these fragmented, yet highly lethal, digital cartels.

For now, the cyber-underworld remains on edge. With the FBI actively hunting the remaining leadership and the Dutch police investigating allegations of murder, the "ShinyHunters" era appears to be reaching a violent and decisive crescendo.