Shadows of Umbreon: The Arrest of a Reformed Cybercriminal and the Escalating Reign of ShinyHunters

THE HAGUE — In the murky underworld of international cybercrime, aliases often outlive the men behind them, morphing into legendary digital phantoms that defy borders, jurisdictions, and even the law itself. For years, the moniker "Umbreon"—named after the glowing Pokémon character—was synonymous with vast repositories of stolen data traded on clandestine English-language hacker forums like RaidForums and Breached. By September 2026, that alias would once again sit at the epicenter of a geopolitical cyberstorm, dragged into the limelight by the dramatic arrest of a 24-year-old Dutch citizen in the Netherlands and a ferocious, retaliatory rampage by the prolific cybercrime collective known as ShinyHunters.
The unfolding saga paints a dizzying picture of modern digital espionage: a tale of split identities featuring a former software engineer working for cybersecurity startups by day and extorting corporations by night, a teenage kingpin in Jordan orchestrating global supply chain hacks, a high-profile breach of the FBI, and an unprecedented war of attrition between law enforcement, ransomware syndicates, and decentralized cybercriminal cartels.
Main Facts: The Arrest and the Escalation
Authorities in the Netherlands officially confirmed the arrest of a 24-year-old male suspect in mid-September 2026, linking him directly to a sweeping investigation into the infrastructure and data extortion operations of ShinyHunters. Multiple familiar sources identified the detained individual as Pepijn van der Stap, a convicted cybercriminal from the Dutch cities of Almere and Lelystad.
Van der Stap’s arrest did not quell the digital storm; rather, it served as a catalyst. In the immediate aftermath of his detention, remaining members of ShinyHunters dramatically escalated their global campaign. The syndicate carried out an unusually brazen breach against the Federal Bureau of Investigation (FBI), compromising the agency’s job application portal (apply.fbijobs.gov) and extracting sensitive personal identifiable information (PII) on thousands of federal personnel, alongside launching aggressive extortion campaigns targeting the notorious Russian-speaking ransomware syndicate Cl0p.
According to security researchers from Mandiant and the Google Threat Intelligence Group (GTIG), the group’s sudden pivot to high-risk targets followed a hostile internal takeover. Leadership of ShinyHunters was reportedly seized by a teenage hacker operating out of Amman, Jordan, known by the alias "Rey." Rey operates under the umbrella of ScatteredLapsussHunters (SLSH)—an aggressive amalgam of three notorious cybercrime factions: Scattered Spider, LAPSUS$, and ShinyHunters.

The inclusion of van der Stap’s old Pokémon persona, "Umbreon," plastered across the defacement pages left behind on compromised systems, suggests that Rey’s power play was not merely tactical, but designed to frame and deflect heat directly onto the beleaguered Dutch hacker.
Chronology: From Dr. Jekyll and Mr. Hyde to the FBI Breach
To understand how a young Dutch software developer became entangled in a planetary cybersecurity crisis, one must trace a timeline of clinical precision, legal reckoning, and underground betrayal.
2021–2023: The Rise of Umbreon
During the early 2020s, Pepijn van der Stap cultivated a double life that would later become a textbook case study in insider threat dynamics. While ostensibly maintaining a respectable career as a software engineer at Amsterdam-based cybersecurity startup Hadrian and volunteering for the Dutch Institute for Vulnerability Disclosure (DIVD), van der Stap operated in the shadows as "Umbreon." Prosecutors later revealed that this persona specialized in compiling, organizing, and leaking massive databases, amassing an illicit fortune estimated between €1.5 million and €2.7 million through data thefts and corporate extortions.
Late 2023: Conviction and Confession
Apprehended and brought to trial in late 2023, van der Stap confessed to his crimes. He famously described his existence as a "Dr. Jekyll and Mr. Hyde" reality driven not primarily by monetary greed, but by an obsessive compulsion to collect, organize, and archive stolen data. Handed a four-year prison sentence (with one year suspended), van der Stap elected to remain incarcerated longer than necessary to seek treatment for severe psychological challenges, including PTSD stemming from childhood trauma. He was ultimately released in December 2025.
September 9, 2026: The Reformed Hacker Interview
In an interview with security journalist Brian Krebs, van der Stap cast himself as a thoroughly reformed individual trying to make amends. Juggling civil lawsuits and restitution payments, he had recently secured a position as an offensive security lead at Dutch firm Neo Security. He expressed a desire to contribute positively to society. However, shortly after this interview, van der Stap abruptly ceased all communication.

Mid-September 2026: The Arrest and Retaliation
On or around September 16, 2026, Dutch authorities moved in, arresting van der Stap at his residence, where witnesses observed police carting away hardware and personal effects. Within days of his detention, ShinyHunters unleashed their coordinated assault on the FBI’s recruitment portal and initiated a public war of words against Dutch police, whom the group mockingly labeled "incompetent, irrelevant, and useless."
Supporting Data: Technical Vectors and the Oracle PeopleSoft Flaw
The mechanics behind ShinyHunters’ 2026 rampage rely heavily on the exploitation of foundational enterprise infrastructure, revealing vulnerabilities in supply chain defenses that security firms have scrambled to contain.
The PeopleSoft Zero-Day (CVE-2026-35273)
According to intelligence reports from Mandiant and Google Threat Intelligence Group, the backbone of ShinyHunters’ recent mass-exploitation campaign stems from a vulnerability in PeopleSoft, an enterprise resource planning and human capital management software suite owned by software giant Oracle.
Initially exploited as a zero-day vulnerability as early as June 2026, Oracle hurried out a security patch (CVE-2026-35273). When organizations struggled to deploy the updates immediately, security firm Mandiant issued web application firewall (WAF) mitigation rules. However, in a display of advanced technical adaptability, ShinyHunters bypassed these defensive rules using clever URL-encoding tricks, allowing them to infiltrate dozens of corporate, governmental, educational, and healthcare systems.
The FBI Portal Breach
Utilizing access gained via the PeopleSoft flaw, the group breached apply.fbijobs.gov. According to disclosures by 404 Media and Reuters, the stolen database compromised personal information of over 5,000 FBI personnel, including:

- Social Security numbers and detailed contact info.
- Specific operational team assignments (e.g., Special Agents, Threat Intake Examiners, Major Cybercrimes Units, and foreign state-backed actor investigators).
- Highly sensitive internal psychiatric and medical records of agency employees.
In a signature act of psychological warfare, the hackers defaced the FBI portal with an ASCII art rendering of the Pokémon character Umbreon, accompanied by the taunting banner: "This site has been seized by ShinyHunters. rooting your systems since ’19 ;)."
Official Responses: Law Enforcement and Corporate Silences
The fallout from the September 2026 escalations has prompted swift, albeit cautious, reactions from governmental bodies, corporate entities, and cybersecurity institutions.
- The Dutch Police & Authorities: The National Police of the Netherlands confirmed the arrest of a 24-year-old male in connection with the ongoing ShinyHunters probe. The suspect was scheduled to appear before the Rotterdam District Court to face preliminary detention extensions. This followed an earlier public appeal by Dutch law enforcement in February 2026, where police released a recorded telephone intercept of a native Dutch speaker social-engineering their way into Odido, the country’s largest mobile carrier, compromising data on over 6.2 million citizens.
- The FBI: The Bureau issued a concise statement acknowledging the compromise of its job application portal and confirming that personal identifiable information (PII) of applicants and employees had been illegally accessed.
- Corporate Entities: Oracle defended its software security posture by emphasizing rapid patch delivery for the PeopleSoft vulnerability, while targeted firms and organizations continue patching cycles. Meanwhile, Hadrian, Neo Security, and DIVD have largely navigated media inquiries carefully, distancing themselves from the fallout of their former employee and volunteer while grappling with internal security audits.
Implications: A New Era of Decentralized Gang Warfare
The intersection of van der Stap’s arrest and the rise of Rey’s ScatteredLapsussHunters (SLSH) syndicate highlights a dangerous evolutionary phase in global cybercrime.
- The Dissolution of Traditional Hierarchies: Cybercrime syndicates are increasingly operating as fluid, hyper-aggressive conglomerates. The friction between older, data-hoarding actors like van der Stap ("Umbreon") and radicalized, high-risk teenagers like Rey demonstrates how personal vendettas, brand hijacking, and ego can drive geopolitical targets like the FBI into the crosshairs.
- The Weaponization of Attribution: By deliberately embedding Umbreon’s imagery into high-profile attacks against American federal law enforcement, modern threat actors are attempting to throw investigators off scent, manipulate legal outcomes, and weaponize law enforcement arrests to spark infighting within rival factions.
- Escalating Extortion Economics: With security analysts predicting that ShinyHunters alone is on track to pull in nearly $100 million in illicit extortion payments over the course of 2026, traditional deterrence models are failing. As ransomware groups and data-theft cartels turn their guns on one another—as seen in ShinyHunters’ extortion of Cl0p—the cyber underground has transformed into an unregulated, cutthroat corporate battleground.
As Pepijn van der Stap faces the Rotterdam District Court and international law enforcement agencies intensify their pursuit of the fragmented leadership behind SLSH, the digital landscape remains on high alert. The shadows of Umbreon may be temporarily caged behind Dutch prison bars, but the cybercrime apparatus he once helped build has mutated into something far more volatile, unpredictable, and dangerous.
