News / Cybersecurity
Arrest of a former Dutch hacker linked to ShinyHunters: a cyber threat still active Published on 28 September 2026 by Christ-loisele (3 min read)
Pepijn van der Stap, also known as Umbreon, was arrested in the Netherlands for his alleged involvement in the activities of the ShinyHunters group, which intensified its attacks after his release. His ties to forums like RaidForums and his criminal past reveal a cybercriminal organization still operational despite arrests.
A hybrid profile between professional legitimacy and illegal activities
Pepijn van der Stap, a 23-year-old Dutch national, was arrested on September 16, 2026, by Dutch authorities for his alleged involvement in the activities of the ShinyHunters group, specializing in data theft and extortion. According to Krebs on Security , Van der Stap had already been convicted in 2023 for data theft and extortion schemes generating between 1.5 and 2.7 million euros. He operated under the pseudonym Umbreon on forums like RaidForums and Breached, where he published stolen data.
Paradoxically, he worked simultaneously as a software engineer at Hadrian and as a volunteer at the Dutch Institute for Vulnerability Disclosure (DIVD) , an organization dedicated to responsible vulnerability disclosure. Released in December 2025 after serving a four-year sentence (including one year on probation), he had claimed to have rehabilitated himself before disappearing from the radar two weeks before his arrest.
Dutch authorities should have « all the luck in the world and everyone’s prayers » to prevent ShinyHunters from carrying out a new massive data breach.
Illustration: Lawing Tech
ShinyHunters strikes after arrest: FBI and Cl0p in the crosshairs
The arrest of Van der Stap did not slow down ShinyHunters’ activities, which instead escalated. The group claimed to have stolen sensitive FBI data, including information on over 5,000 agents, through a vulnerability in Oracle’s PeopleSoft system (CVE-2026-35273), as confirmed by OffSeq . Additionally, ShinyHunters extorted the Russian ransomware group Cl0p, demonstrating the ability to target both public institutions and criminal actors.
The group also exploited a vulnerability to attack Odido, a Dutch company, compromising the data of 6.2 million citizens. Dutch authorities identified a ShinyHunters member through a recorded phone call in February 2026, linked to this intrusion. Oracle has since released a patch for the exploited vulnerability (CVE-2026-35273), but threats persist.
Evasion techniques and challenges for authorities
ShinyHunters used sophisticated evasion techniques, such as URL encoding, to bypass web application firewalls, according to OffSeq . These methods highlight the group’s adaptability in the face of countermeasures. Dutch authorities, already criticized by ShinyHunters for their inefficiency, now urge the public to report any useful information to track down remaining members.
The group even threatened Dutch authorities with new large-scale attacks, stating: « The Dutch police will need all the luck in the world, and everyone’s prayers, if they want to catch him before we carry out another large-scale data theft. » This statement underscores the boldness of an organization that continues to strike despite arrests.
What this changes here: increased risks for African institutions
For businesses and administrations in Benin and West Africa, this case reveals several lessons. First, cybercriminal groups like ShinyHunters could exploit unpatched software vulnerabilities , such as Oracle’s, to target public institutions or sensitive data. Systems using solutions like PeopleSoft, popular in administrations, would become prime targets if patches are not applied quickly.
Next, the resilience of groups after arrests demonstrates that cyber threats operate as networks. An attack on a local business or administration could be orchestrated by distant actors, as shown by Van der Stap’s involvement in international forums. Beninese organizations should therefore strengthen their monitoring of specialized forums and collaboration with platforms like the DIVD to anticipate leaks.
Finally, the techniques of social engineering and evasion used by ShinyHunters could be replicated against African targets. Training employees in cybersecurity best practices, as well as regular firewall audits, would become priorities to prevent similar breaches like those suffered by Odido or the FBI.
Sources