Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

Dutch authorities arrest former cybersecurity professional linked to notorious ShinyHunters hacking collective

Cahyo Dewo, September 29, 2026

Dutch law enforcement authorities have officially confirmed the apprehension of a 24-year-old Amsterdam resident in connection with an ongoing, high-profile investigation into the prolific cyber-criminal syndicate known as ShinyHunters. The arrest, announced by the Politie Landelijke Opsporing en Interventies (National Police of the Netherlands) via official social media channels, marks a significant development in the international effort to dismantle a group responsible for some of the most disruptive data breaches in recent history. The suspect, identified by investigative journalists and security researchers as Pepijn van der Stap—also known in underground circles by the alias "Umbreon"—is scheduled to appear before the Rotterdam District Court on September 29, 2026, to address charges stemming from his alleged involvement with the group.

A Pattern of Recidivism in the Digital Underground

The arrest of van der Stap on September 15, 2026, represents a complex intersection between legitimate cybersecurity expertise and illicit activity. This is not the suspect’s first encounter with the Dutch judicial system; in 2023, he was apprehended and prosecuted for a series of data thefts and extortion schemes. At the time of his 2023 arrest, the investigation revealed a dual life that had surprised many in the security community. Van der Stap had been employed at the cybersecurity firm Hadrian and was a recognized volunteer for the Dutch Institute for Vulnerability Disclosure (DIVD), a highly respected non-profit organization dedicated to scanning the internet for vulnerabilities to protect the public.

In a candid interview following his 2023 legal proceedings, van der Stap described the psychological toll of balancing a white-hat career with black-hat operations. He spoke of a "paranoia" that intensified as his professional responsibilities grew, noting that the constant pressure of maintaining a facade of legitimacy while secretly engaging in criminal hacking created a volatile environment. Despite these experiences, his career trajectory remained unconventional; at the time of his most recent arrest in September 2026, he was serving as the offensive security lead at Neo Security, a Dutch enterprise. His professional profile on LinkedIn included a public acknowledgment of his checkered past, characterizing his journey as one that provided him with a unique, albeit hard-learned, perspective on the binary nature of security—emphasizing that his experiences had ultimately convinced him that technical knowledge should be used for defense rather than exploitation.

The ShinyHunters Shadow: A Recent Breach of the FBI

The timing of this arrest is particularly significant, occurring amidst a wave of intense scrutiny regarding the activities of ShinyHunters. The group recently claimed responsibility for a sophisticated infiltration of the Federal Bureau of Investigation’s (FBI) recruitment portal, apply.fbijobs.gov. The breach, which resulted in the alleged theft of terabytes of sensitive data, was framed by the attackers not as a traditional criminal extortion attempt, but as an unconventional "marketing campaign."

In communications with 404 Media and other outlets, a representative for ShinyHunters asserted that the attack on the FBI was an effort to combat what they described as "disinformation" and to capture public attention for their own narrative. The group claimed that standard communication channels would have been ignored, necessitating a high-profile breach to ensure their message was heard. This assertion has been met with skepticism by cybersecurity analysts and government officials alike, who note that the group’s history of monetizing stolen data makes their claims of altruism or political signaling difficult to verify.

Technical Analysis: Bypassing the Firewall

The recent FBI intrusion has provided researchers with a window into the evolving technical capabilities of the ShinyHunters collective. While the group initially claimed that the breach was facilitated by a zero-day vulnerability in Oracle PeopleSoft, further forensic analysis by the security community indicates a more targeted approach. Investigators have determined that the attackers successfully employed a URL-encoding technique designed to bypass Web Application Firewall (WAF) rules. Specifically, the attackers exploited a workaround for CVE-2026-35273, a flaw that security teams had assumed was adequately mitigated by existing WAF configurations.

This development highlights a persistent trend in the threat landscape: the ability of sophisticated actors to weaponize minor configuration oversights to bypass perimeter defenses. By manipulating the way incoming web requests are parsed, the attackers were able to slip past security filters that would have otherwise blocked the exploit payload. This specific tactic underscores the necessity for more robust, deep-packet inspection and a shift toward zero-trust architectures that do not rely solely on WAF-based perimeter defense.

Chronology of Events

  • 2023: Pepijn van der Stap is arrested for the first time regarding his involvement in various data theft and extortion activities. At the time, he is revealed to have been working for Hadrian and volunteering with the DIVD.
  • June 2023: In a series of public statements, van der Stap discusses the mental health struggles and the extreme paranoia resulting from his dual involvement in white-hat and black-hat security.
  • September 15, 2026: Dutch authorities conduct a follow-up operation, resulting in the arrest of van der Stap in Amsterdam on allegations related to the ShinyHunters group.
  • Late September 2026: ShinyHunters claims a massive data breach involving the FBI’s job application portal, citing a "marketing campaign" as the motive.
  • September 28, 2026: Investigative outlets like DataBreaches.Net and Krebs on Security identify the arrested individual as the same person involved in the 2023 legal proceedings.
  • September 29, 2026: The scheduled court appearance for van der Stap at the Rotterdam District Court to address the new allegations.

Broader Implications and Institutional Impact

The arrest of a high-level offensive security professional for involvement in a criminal syndicate raises profound questions about the vetting and ethics within the cybersecurity industry. Organizations are increasingly forced to grapple with the "insider threat" model, where individuals with deep knowledge of defensive infrastructure may possess the technical acumen to bypass those very systems.

Furthermore, the ShinyHunters’ bold claim that their breach of a federal entity was a "marketing campaign" represents a disturbing shift in the motivation of threat actors. If hacker groups begin to view high-profile government breaches as legitimate tools for public relations or narrative control, the geopolitical implications could be severe. The assertion that they do not intend to sell or publish the stolen FBI data—even if true—does not mitigate the catastrophic security failure represented by the breach itself.

The incident has prompted a renewed call for increased cooperation between private cybersecurity firms and law enforcement agencies. As the lines between legitimate offensive research and criminal hacking continue to blur, the industry faces pressure to implement more rigorous background checks and ethical monitoring for employees who hold high-level access to sensitive security systems. For the Dutch police, the successful identification and arrest of a suspect linked to such a high-profile group serves as a testament to the efficacy of international intelligence sharing, even as the global community remains concerned about the increasing sophistication and audacity of groups like ShinyHunters.

As of the current reporting, the FBI has not provided a detailed public response regarding the extent of the data compromised in their portal breach, nor have they commented on the specific technical details of the WAF bypass. However, the arrest in Amsterdam suggests that the investigation is far from over, and law enforcement agencies worldwide are likely to continue scrutinizing the digital footprints left by those involved in the ShinyHunters operations. The case of van der Stap remains a cautionary tale of how the pursuit of technical excellence, when divorced from ethical constraints, can lead to devastating consequences for both the individual and the global digital infrastructure.

Cybersecurity & Digital Privacy arrestauthoritiescollectiveCybercrimecybersecuritydutchformerHackinglinkednotoriousPrivacyprofessionalSecurityshinyhunters

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes