Dutch Arrest of ShinyHunters Member Triggers FBI Breach and Internal Power Struggle
Dutch authorities arrested 24-year-old Pepijn van der Stap, a former cybercriminal and ShinyHunters associate, on September 15, 2026. Days later, the hacker group claimed a massive breach of the FBI’s job application site, stealing data on over 5,000 officials. The arrest appears to have triggered a violent internal power struggle, with a Jordanian teenager named 'Rey' seizing control and escalating attacks against the FBI and the Cl0p ransomware group. Dutch police suspect van der Stap of inciting two murders abroad, while the FBI confirmed the breach and urged remaining hackers to surrender.
Key points
- Dutch police arrested Pepijn van der Stap, a 24-year-old former hacker known as 'Umbreon,' on September 15, 2026, on suspicion of aiding ShinyHunters.
- Van der Stap was previously convicted in 2023 for data theft and extortion, earning between €1.5 million and €2.7 million, and was released from prison in December 2025.
- Shortly after his arrest, ShinyHunters claimed a breach of the FBI’s apply.fbijobs.gov site, stealing 2-3 terabytes of data, including Social Security numbers and medical files of over 5,000 officials.
- The breach exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft, which ShinyHunters began exploiting in June 2026.
- Dutch authorities suspect van der Stap of inciting two murders to be committed abroad, based on data found on his laptop.
- ShinyHunters appears to have been taken over by a Jordanian teenager named 'Rey,' who is part of the ScatteredLapsussHunters (SLSH) group and has a conflict with van der Stap.
Background
This incident follows a period of increased cybercrime activity in 2026, including the arrest of TeamPCP leaders in Australia for supply-chain attacks. ShinyHunters had previously partnered with TeamPCP to monetize stolen credentials, but the collaboration ended after Mandiant secretly fed the credentials to cloud providers, rendering them worthless. Van der Stap had previously worked as a software engineer at Hadrian and volunteered for the Dutch Institute for Vulnerability Disclosure (DIVD) before his 2023 conviction. The current arrest and subsequent FBI breach mark a significant escalation in ShinyHunters' operations, moving from targeted extortions to high-profile government breaches.
How outlets are covering it
Krebs on Security emphasizes the internal power struggle within ShinyHunters, highlighting the conflict between van der Stap and 'Rey,' and notes the use of van der Stap's 'Umbreon' alias in the FBI defacement as a potential attempt to pin the hack on him. CBS News focuses on the official law enforcement response, detailing the Dutch police's confirmation of the arrest, the suspect's suspected involvement in inciting murders, and the FBI's ongoing investigation. AP News provides a broader overview, noting the FBI's internal communications to employees and the group's claims of compromising nearly all FBI agents. The outlets differ in their emphasis on the motive: Krebs highlights the 'Rey' takeover and the 'Umbreon' taunt, while CBS and AP focus on the legal and operational consequences of the arrest and breach.
Why it matters
The arrest of a high-profile ShinyHunters member and the subsequent breach of the FBI underscore the escalating threat posed by organized cybercrime groups. The exploitation of a zero-day vulnerability in widely used HR software like Oracle PeopleSoft highlights the risks to critical infrastructure and government agencies. The internal power struggle within ShinyHunters suggests a potential for more aggressive and less predictable attacks, as new leaders seek to assert control. The FBI's public response and the Dutch police's involvement in a cross-border investigation demonstrate the international coordination required to combat such threats. This incident also raises concerns about the potential for cybercriminals to leverage stolen data for extortion or political leverage, as seen in the group's taunts against the FBI and Cl0p.
What to watch
Dutch authorities are expected to provide more details on the investigation on September 30, 2026, following van der Stap's appearance before the Rotterdam District Court on September 29. The FBI is continuing its investigation into the breach and is urging remaining ShinyHunters members to turn themselves in. Oracle is expected to continue patching the PeopleSoft vulnerability, while Mandiant and other security firms are likely to release additional mitigation strategies. The internal power struggle within ShinyHunters may lead to further high-profile attacks or a fragmentation of the group. Dutch police may pursue additional arrests based on the data found on van der Stap's laptop, including the suspected incitement to murder.
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation Krebs on Security
- Dutch National Police arrest member of group that claimed to have hacked FBI CBS News
- Dutch police arrest a suspected ShinyHunters member; court orders 90-day detention AP News
- F.B.I. Vows to Pursue ShinyHunters Hackers After Personnel Data Theft The New York Times
- Dutch 'reformed hacker' arrested in ShinyHunters investigation, police and ex-boss say Reuters
Want the full story? Read the original reporting
Read on Krebs on Security