Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.
“It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters,” the Politie Landelijke Opsporing en Interventies said in an X post Monday.
Police said the individual is expected to appear before the Rotterdam District Court on September 29, 2026.
Although law enforcement officials did not disclose any additional details, independent security journalist Brian Krebs and DataBreaches.Net identified the arrested man as Pepijn van der Stap (aka Umbreon), who was previously apprehended in 2023 for his role in a series of data thefts and extortions.
Per DataBreaches.Net, van der Stap was arrested on September 15, 2026. In 2023, it emerged that the individual worked at cybersecurity company Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD).
“Working at Hadrian and volunteering at DIVD made me more paranoid about keeping up appearances, and I actually felt more pressure and paranoia because I was working such long hours,” van der Stap told DataBreaches.Net in June 2023.
“So yes, I was doing more lawful work and much less illegal work but I became more paranoid about getting caught. The paranoia became so extreme that I was expecting a knock on the door at any time.”
He is presently employed as the offensive security lead at the Dutch company Neo Security, according to LinkedIn.
In his profile, van der Stap acknowledged his journey “hasn’t been a straight line” and that “I’ve seen security from both sides of the terminal, an experience that taught me hard lessons but ultimately gave me clarity: knowledge is for building and protecting, not breaking.”
The development comes as ShinyHunters claimed credit for its brazen hack of the U.S. Federal Bureau of Investigation’s (FBI) job application site apply.fbijobs.gov, stealing terabytes of sensitive data.
“This was all a marketing campaign to protect our business and actively combat disinformation,” a ShinyHunters representative told 404 Media. “If we made this statement normally then this much attention to our words and intentions would’ve never been this widespread.”
“We’d have been ignored and disregarded. However, now everyone knows what the issue is and what we are doing. Everyone is reading about it. We proved our points on several occasions. We do not care what the public says and we are not affected by it nor do we cloud our judgement by external opinions and thoughts.”
Although the group said it exploited a new zero-day flaw in Oracle PeopleSoft to gain unauthorized access and siphon the data, it’s now assessed that ShinyHunters employed a URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate CVE-2026-35273.


