The Shadow of Umbreon: Inside the Chaotic Collapse of the ShinyHunters Syndicate

The world of international cybercrime is rarely a theater of honor, but the recent unraveling of the notorious hacking collective ShinyHunters has devolved into something far more visceral: a high-stakes, cross-continental game of betrayal, framing, and geopolitical fallout. At the center of this maelstrom sits Pepijn van der Stap, a 24-year-old Dutch national whose digital double life has once again brought him to the precipice of a prison cell.

Authorities in the Netherlands confirmed this month that they have arrested van der Stap on suspicion of facilitating large-scale data thefts and extortion campaigns. Yet, his arrest has not signaled the end of the group’s reign. Instead, in the immediate wake of his detention, ShinyHunters launched an unprecedented offensive, targeting the U.S. Federal Bureau of Investigation (FBI) and even extorting the feared Russian ransomware cartel known as Cl0p.

The Dual Life of Pepijn van der Stap

To understand the current chaos, one must look at the paradoxical existence of Pepijn van der Stap. Based in the Dutch cities of Almere and Lelystad, van der Stap was already a known quantity to European law enforcement. In 2023, he was convicted for a massive string of data thefts and extortion schemes that prosecutors estimated generated between €1.5 million and €2.7 million in illicit proceeds.

During his 2023 trial, van der Stap provided a candid—and chilling—glimpse into his psychology. He described a "Dr. Jekyll and Mr. Hyde" existence. By day, he was a respected software engineer at Hadrian, an Amsterdam-based cybersecurity startup, and a dedicated volunteer for the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organization committed to identifying and patching critical security flaws. By night, he assumed the mantle of "Umbreon," an alias inspired by the Pokémon character, which he used to dump stolen corporate databases onto underground forums like RaidForums and Breached.

Van der Stap was sentenced to four years in prison, with one year suspended. Throughout the proceedings, he claimed to be suffering from PTSD stemming from childhood trauma, at one point requesting to remain in custody because he felt the prison environment provided better psychological support than the outside world. He was released in December 2025, attempting, by his own admission, to transition into a legitimate career. At the time of his September 2026 arrest, he was employed as an offensive security lead at the Dutch firm Neo Security.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

A Chronology of Escalation

The recent timeline of events suggests that the "Umbreon" identity never truly faded—or, at the very least, that others were more than willing to weaponize it.

  • February 2026: A native Dutch-speaking member of ShinyHunters successfully social-engineers an employee at Odido, the Netherlands’ largest telecommunications provider. Using a spoofed website, the hackers exfiltrate data belonging to 6.2 million Dutch citizens.
  • September 7, 2026: Dutch police release an audio clip from the Odido hack, asking for public assistance in identifying the perpetrator.
  • September 9, 2026: Van der Stap grants an interview to KrebsOnSecurity, portraying himself as a reformed hacker working to make amends for his past. Shortly thereafter, he goes completely dark.
  • September 16, 2026: Dutch authorities arrest van der Stap. Witnesses report police removing equipment from his home.
  • Late September 2026: ShinyHunters claims credit for breaching apply.fbijobs.gov, leaking sensitive psychiatric and medical records of over 5,000 FBI personnel.
  • September 29, 2026: Van der Stap is scheduled for a court appearance in Rotterdam.

The FBI Breach and the "PeopleSoft" Vulnerability

The most audacious act in this saga was the infiltration of the FBI’s job application portal. The breach was not a result of a sophisticated state-sponsored intrusion, but rather the exploitation of a software vulnerability in Oracle’s PeopleSoft platform.

ShinyHunters leveraged a zero-day vulnerability (CVE-2026-35273) to gain entry into the FBI’s systems. Despite security giant Mandiant issuing web application firewall (WAF) rules to mitigate the threat, ShinyHunters utilized a URL-encoding trick to bypass these defenses. This maneuver allowed the group to compromise dozens of systems across healthcare, agriculture, and government sectors.

The defacement of the FBI site was a deliberate, taunting message. The hackers left behind an ASCII art design of the Pokémon character "Umbreon," the same avatar used by van der Stap for years. The message read: "This site has been seized by ShinyHunters. Rooting your systems since ’19 ;)."

The Rise of "Rey" and the Internal Power Struggle

Security analysts are now convinced that the recent, erratic behavior of ShinyHunters is the result of a hostile takeover. The group has shifted from a data-collecting collective to a volatile, aggressive extortion ring under the influence of a teenage cybercriminal from Amman, Jordan, known as "Rey."

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Rey is a key operative in a group called ScatteredLapsussHunters (SLSH), an alliance formed from the remnants of the infamous LAPSUS$ and Scattered Spider groups. Sources indicate that Rey has harbored a long-standing grudge against van der Stap, likely rooted in a power struggle over control of the "ShinyHunters" brand.

By using the Umbreon image in the FBI breach, experts believe Rey was attempting a "false flag" operation, designed to ensure that when the FBI and international law enforcement agencies began their investigation, they would immediately point their fingers at the already-convicted van der Stap. This is a classic tactic in the digital underworld: burn the reputation of a rival while solidifying one’s own infamy.

Official Responses and Geopolitical Implications

The fallout from these attacks has drawn responses from the highest levels of law enforcement. The FBI confirmed the compromise of its portal, though they have kept the extent of the impact under tight wraps.

In the Netherlands, the police have been uncharacteristically vocal. In a statement following the arrest of the 24-year-old, the Dutch police emphasized their commitment to identifying all members of the collective, noting, "The Dutch police will need all the luck in the world—and everyone’s prayers—if they want to catch him before we carry out another large-scale data theft." This quote, famously issued by ShinyHunters themselves, has become the defining sentiment of their confrontation with the state.

The Dutch police unit handling the Odido case has faced intense scrutiny, especially after ShinyHunters publicly mocked them, calling the authorities "incompetent, irrelevant, and useless." This level of hubris is unprecedented, signaling a shift in the power dynamic between modern criminal syndicates and national security apparatuses.

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security

Implications for Global Cybersecurity

The implications of the ShinyHunters saga are profound. First, it highlights the catastrophic risks posed by supply-chain vulnerabilities in widely used SaaS platforms like PeopleSoft. Even when patches are released, the time-lag between disclosure and implementation provides a "golden window" for groups like SLSH to wreak havoc.

Second, the case of Pepijn van der Stap serves as a cautionary tale about the difficulty of rehabilitation in the cybersecurity industry. While many former hackers transition successfully into "white hat" roles, the digital breadcrumbs left by their past lives can make them convenient scapegoats for younger, more ruthless actors.

Finally, the shift toward aggressive, high-profile attacks—targeting entities like the FBI and other criminal groups like Cl0p—suggests that the barriers to entry for cyber-warfare are eroding. When criminal groups begin attacking one another, the potential for collateral damage against private citizens and public infrastructure increases exponentially.

As van der Stap faces the Rotterdam District Court, the digital world watches with bated breath. Whether he is a reformed man unfairly caught in a web of someone else’s making, or a recidivist playing a dangerous game, one thing is certain: the era of the "gentleman hacker" is over. In its place is a new generation of cyber-insurgents for whom nothing is sacred, and for whom the chaos of a breach is the only currency that matters.

Leave a Reply

Your email address will not be published. Required fields are marked *