Dutch Police Arrest Former Hacker in ShinyHunters Investigation

Summary
Dutch police confirmed the arrest of a 24-year-old in the ShinyHunters investigation as the group claimed responsibility for an FBI job-site breach affecting more than 5,000 officials and exploited a PeopleSoft vulnerability against dozens of organizations.
Key points
- Dutch police confirmed the arrest of a 24-year-old in connection with the ShinyHunters investigation; sources identified him as Pepijn van der Stap, previously convicted of data theft and extortion.
- Dutch authorities are investigating whether the arrested man was the Dutch-speaking caller who reportedly used a spoofed login page to access Odido and steal data on more than 6.2 million people.
- The FBI confirmed a breach of its job application site. Media reports said stolen data included personal information on more than 5,000 officials, including sensitive medical and psychiatric files.
- ShinyHunters said it exploited the PeopleSoft vulnerability CVE-2026-35273, reportedly using it as a zero-day from June. Oracle issued a fix, but attackers reportedly bypassed Mandiant's suggested WAF rules using URL encoding.
- Mandiant and Google Threat Intelligence Group reported mass exploitation of the vulnerability across dozens of systems in sectors including government, healthcare, technology and higher education.
- Sources described a power struggle over the ShinyHunters brand and attributed the group's recent escalation to a teenage cybercriminal known as Rey; these claims are not independently confirmed in the article.
Article Details
- Event Type
- Arrest in a cybercrime investigation, alongside reported data breaches and extortion
- Impact
- ShinyHunters stole data on more than 6.2 million people in the Odido intrusion. The FBI confirmed a breach of its job application site; reporting described stolen personal, medical, and psychiatric information concerning more than 5,000 officials. Mandiant and GTIG confirmed that ShinyHunters exploited the PeopleSoft vulnerability to steal data from dozens of systems.
MITRE ATT&CK
T1190 · Exploit Public-Facing ApplicationMandiant and GTIG confirmed that ShinyHunters mass-exploited a PeopleSoft vulnerability to steal data.T1491.001 · Internal DefacementShinyHunters left a defacement message on the hacked FBI jobs site.T1566.002 · Spearphishing LinkA ShinyHunters member reportedly tricked an Odido employee into logging in at a spoofed website.
CVE
Threat Actors
ClopRansomware group the article says ShinyHunters extorted.LAPSUS$Named as one of the three groups comprising ScatteredLapsussHunters.Pepijn van der StapPreviously convicted of data theft and extortion under the handle Umbreon; arrested in September 2026 in connection with the ShinyHunters investigation. His involvement in the group's recent activity is not established.ReyTeenage cybercriminal whom sources said took over ShinyHunters; those sources alleged he sought to implicate van der Stap in the FBI jobs-site hack.Scattered SpiderNamed as one of the three groups comprising ScatteredLapsussHunters.ScatteredLapsussHuntersCybercrime group also called SLSH, described as an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters; Rey was described as operating within it.ShinyHuntersHacker group implicated in the Odido intrusion and confirmed by Mandiant and GTIG to have mass-exploited the PeopleSoft vulnerability.SLSHAbbreviation used for ScatteredLapsussHunters.TeamPCPGroup reported to have compromised software supply chains and collected stolen credentials; ShinyHunters and SLSH members reportedly partnered with it.UmbreonHacker handle that Pepijn van der Stap admitted using in his earlier data theft and extortion activity.
Vendors
Products
Countries
Jordansaid the sudden shift came about after ShinyHunters was taken over by a teenage cybercriminal from Amman, Jordan who goes by the nickname Rey and operates as part of a cybercrime group called ScatteredLapsussHuntersNetherlandsAuthorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters.Russiaclose to the ShinyHunters investigation said the group’s recent risky attacks against the FBI and one of Russia’s most venerated ransomware groups amounted to a major pivot away from the more measured tenor of theUnited States
Industries
Agriculturedozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.Governmentof industries, including higher education, technology, healthcare, agriculture, transportation and government.Healthcaresteal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.Higher Educationvulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.Technologyto steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.TelecommunicationsShinyHunters member social engineered their way into Odido, the nation’s largest mobile telecommunications provider.Transportationacross a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.