// 1 ZERO-DAY · 5 CVE · 5 EXPLOIT IN THE LAST 24H→
Pepijn van der Stap, 23, arrested in the Netherlands on or around September 16, 2026. The case reveals a suspected succession war within the criminal group and an escalation of attacks by ShinyHunters, now led by Jordanian teenager Rey, including the breach of the FBI recruiting portal and a mass exploitation campaign against Oracle PeopleSoft systems.

Editorial note on sources and limits: Information on the arrest of Pepijn van der Stap relies on a single structured primary source (KrebsOnSecurity) citing anonymous sources that cannot be independently verified. No official confirmation from Dutch police or judicial authorities exists at this time. The arrest date is indicated by sources as "on or around September 16" 2026.

Pepijn van der Stap, 23, known as Umbreon, was arrested by Dutch authorities on or around September 16, 2026. The individual, previously convicted in 2023 for data theft and extortion totaling 1.5–2.7 million euros and publicly presented as a reformed hacker in a September 9, 2026 KrebsOnSecurity interview, now sits at the center of a European cybercrime investigation. The arrest coincided with an intensification of attacks by the ShinyHunters collective, now led by the Jordanian teenager Rey, who executed the breach of the FBI recruiting portal and a mass exploitation campaign against Oracle PeopleSoft systems.

Key Takeaways
  • Pepijn van der Stap (alias Umbreon) was arrested on or around September 16, 2026, according to anonymous sources cited by KrebsOnSecurity; no official confirmation available
  • The ShinyHunters group intensified attacks immediately after the arrest, breaching apply.fbijobs.gov and exposing data of over 5,000 FBI personnel
  • The technical chain relies on CVE-2026-35273 in Oracle PeopleSoft, a zero-day exploited from June 2026 with a subsequent bypass of Mandiant WAF rules via URL-encoding
  • The FBI defacement included Umbreon ASCII art identical to the 2020 Hackforums version; sources close to the investigation indicate a suspected framing attempt by Rey, the new ShinyHunters leader, in a conflict over control of the brand

From Convicted Criminal to Offensive Security Lead: Verified Facts

Van der Stap served part of a 4-year prison sentence (1 year suspended) and was released in December 2025. Just nine months later, he was working as an offensive security lead at Neo Security, with prior experience at Hadrian and volunteer work for the Dutch Institute for Vulnerability Disclosure (DIVD). On September 9, 2026, he gave an interview to KrebsOnSecurity presenting himself as a redeemed figure.

The sources do not indicate whether Neo Security was aware of the criminal past at the time of hiring. The brief contains no information on any background check processes or the company's selection criteria.

The PeopleSoft Campaign: From Zero-Day to Industrial-Scale WAF Bypass

The technical core of the escalation is CVE-2026-35273, a vulnerability in Oracle PeopleSoft. ShinyHunters stated it began exploitation in June 2026, when the vulnerability was still a zero-day. Oracle subsequently released patches, and Mandiant issued mitigation rules for Web Application Firewalls.

ShinyHunters bypassed Mandiant's WAF rules using a URL-encoding technique, as documented by BleepingComputer and confirmed in the joint Mandiant/Google Threat Intelligence Group report of September 25, 2026. The result was mass exploitation against dozens of enterprise systems. Mandiant and GTIG confirmed the large-scale activity.

The most striking impact was the breach of the apply.fbijobs.gov portal. Over 5,000 FBI personnel had SSNs, personal information, and psychiatric and medical files exposed, according to 404 Media and Reuters, which examined the documents. The FBI issued a confirmation statement.

"This site has been seized by ShinyHunters. rooting your systems since '19 ;)" — Defacement message on the FBI jobs site, with Umbreon ASCII art

Rey vs. Umbreon: The Suspected Succession of a Criminal Group

The Umbreon ASCII art in the FBI defacement is not necessarily proof of van der Stap's involvement. Sources close to the investigation report an "ongoing beef" between van der Stap and the Jordanian teenager known as Rey, leader of the ScatteredLapsusHunters collective. According to these anonymous sources, Rey took control of ShinyHunters and the use of the Umbreon image would be an attempt to frame the Dutchman, diverting investigative attention onto him. The brief explicitly warns against presenting this framing by Rey as certain.

Rey was publicly identified by KELA in March 2025 as Saif Al-Din Khader, a resident of Amman. KrebsOnSecurity confirmed the real identity by contacting the father, Zaid Khader, directly; the teenager then responded via Signal with the message: "I saw your email, unfortunately I don't think my dad would respond to this because they think its some 'scam email'. So I decided to talk to you directly." The identification relies on SpyCloud infostealer data and analysis by Intel 471 and Flashpoint.

ShinyHunters responded to the arrest with threatening statements distributed to NL Times: "The Dutch police will need all the luck in the world – and everyone's prayers – if they want to catch him before we carry out another large-scale data theft in the Netherlands." And: "Frankly, the Dutch police are a big joke; they are incapable of doing anything."

The Dual Extortion Layer and the Limits of Estimates

ShinyHunters' economic mechanism operates on two simultaneous planes: data theft with subsequent sale, and direct extortion of victims. An estimate of nearly $100 million in 2026 proceeds circulates in secondary sources (daily.dev citing Mandiant), but is not confirmed in the primary sources available for this piece.

The group claimed the February 2026 Odido attack, which affected 6.2 million Dutch citizens, and confirmed that the suspect in the audio recording is a member of the collective. Dutch police requested public assistance to identify the voice; van der Stap has not been officially recognized as that voice.

What to Do Now

For organizations using Oracle PeopleSoft, the priority is verifying application of the patch for CVE-2026-35273 and assessing WAF rules in use, given that URL-encoding techniques have demonstrated the ability to bypass specific configurations. The Mandiant/GTIG report of September 25, 2026 provides consultable indicators of compromise.

For industry professionals, the case documents how criminal groups can react to arrests with attack escalation rather than reduced activity. ShinyHunters' statements to NL Times explicitly indicate the intention to continue operations in the Netherlands.

For media and analysts, the case presents significant limits: it is unclear whether van der Stap is technically still an active ShinyHunters member or whether the arrest is based on historical activities; specific charges from the Dutch prosecutor are not available; the exact arrest date and the modalities of the control transfer to Rey remain unconfirmed.

Closing

The arrest of Pepijn van der Stap on or around September 16, 2026, if confirmed by authorities, marks a turning point in the investigation into ShinyHunters. What the sources document with the greatest clarity is the technical escalation: a zero-day in PeopleSoft, a WAF bypass, an FBI breach with over 5,000 personnel exposed. The human context — the alleged feud between Rey and Umbreon, the defacement framing, van der Stap's actual role in the group — remains built on anonymous sources and investigative hypotheses that the brief requires not be presented as certainties.

The collective responded to the arrest with explicit threats and new attacks. The speed of this reaction, documented in the sources, is the most solid data point for reflection: for ShinyHunters, the arrest of a member was not a deterrent.

Information has been verified against cited sources and updated at time of publication.

Sources


Sources and references
  1. krebsonsecurity.com
  2. daily.dev
  3. radar.offseq.com
  4. malware.news