Dutch authorities have detained a 24-year-old man suspected of assisting the ShinyHunters hacking group in data theft and extortion activity, according to reports citing people familiar with the investigation. The suspect was identified by those sources as Pepijn van der Stap, a Dutch national previously convicted over separate cybercrime offenses.
Van der Stap was convicted in 2023 in connection with a series of data breaches and extortion campaigns that prosecutors said generated between €1.5 million and €2.7 million. He admitted using the online alias “Umbreon” while selling or threatening to release stolen information on cybercrime forums. He received a four-year sentence, with one year suspended, and was released in December 2025.
Before his earlier conviction, van der Stap had worked in software and participated in vulnerability-disclosure activities. Earlier this month, he described himself publicly as seeking to rebuild his life and address outstanding claims from prior victims. He reportedly stopped responding to messages shortly afterward. Dutch police have not publicly confirmed his identity, the reported detention, or the scope of any allegations.
Odido social-engineering case
The reported arrest follows a Dutch police appeal for assistance identifying a Dutch-speaking caller linked to a February 2026 intrusion at telecommunications provider Odido. Investigators said the attacker used social engineering to persuade an employee to authenticate at a fraudulent website, enabling the theft of data concerning more than 6.2 million people.
ShinyHunters has said the person heard in the recording was one of its members and claimed to be arranging legal support. The group also issued threats of further attacks against organizations in the Netherlands. It remains unclear whether police have identified the caller.
Broader campaign against PeopleSoft users
In the days after the reported detention, ShinyHunters claimed responsibility for a breach of an FBI employment website. Media reports said the stolen records included personal, employment, medical and psychiatric information relating to thousands of people. The FBI acknowledged a cyber incident but released few details.
Security researchers at Mandiant and Google Threat Intelligence Group said ShinyHunters had exploited CVE-2026-35273, a recently patched Oracle PeopleSoft vulnerability, against organizations in multiple sectors. Oracle issued an update, while researchers warned that an encoding technique could bypass some published web application firewall mitigations. Organizations using affected PeopleSoft deployments should apply vendor patches, review exposed systems and investigate suspicious access activity.
