Dutch Police Confirm Arrest in ShinyHunters Investigation

Dutch authorities have confirmed the arrest of a 24-year-old man from Amsterdam in an investigation into the ShinyHunters hacker group. The Politie Landelijke Opsporing en Interventies said the man is expected to appear before the Rotterdam District Court on September 29, 2026.
Police did not disclose further information about the allegations or evidence. Independent security journalist Brian Krebs and DataBreaches.Net identified the arrested individual as Pepijn van der Stap, also known as Umbreon. DataBreaches.Net reported that he was arrested on September 15, 2026.
Identity reports follow limited official disclosure
Van der Stap had previously been apprehended in 2023 in connection with a series of data thefts and extortions. At that time, reports said he had worked at the cybersecurity company Hadrian and volunteered with the Dutch Institute for Vulnerability Disclosure, or DIVD.
In comments published by DataBreaches.Net in June 2023, van der Stap said lawful work had reduced his illegal activity but also heightened his fear of being caught. His LinkedIn profile lists him as offensive security lead at Dutch company Neo Security and says his experience on both sides of security taught him that knowledge should be used to build and protect rather than break.
ShinyHunters’ FBI claim puts web controls in focus
The arrest comes as ShinyHunters claimed responsibility for compromising the U.S. Federal Bureau of Investigation job application site, apply.fbijobs.gov, and stealing terabytes of sensitive data. A representative told 404 Media that the intrusion was part of a campaign intended to draw attention to the group’s message.
ShinyHunters initially said it had used a new zero-day vulnerability in Oracle PeopleSoft to obtain unauthorized access and extract the data. The activity is now assessed to have involved a URL-encoding technique that bypassed web application firewall rules intended to mitigate CVE-2026-35273.
What organisations should examine
The reported bypass is a reminder that a WAF rule is not a substitute for applying vendor fixes and validating how applications handle encoded input. Security teams running exposed PeopleSoft services should review patch status, inspect logs for unusual encoded requests, and verify that filtering rules perform as intended across relevant request paths.
The Dutch case remains limited in its publicly disclosed details, while the court appearance will be a key procedural step. For businesses, the immediate implication is practical: prioritise remediation for affected Oracle PeopleSoft deployments and test web-facing defences against input-normalisation and URL-encoding bypasses.

