Dutch authorities have arrested a 24-year-old man from Amsterdam as part of an investigation into the ShinyHunters hacking group.
The Dutch national police confirmed that the man was arrested earlier this month and is expected to appear before the Rotterdam District Court on September 29, 2026. Police have not disclosed further details about the investigation or the allegations against the suspect.
Security journalist Brian Krebs and DataBreaches.Net identified the arrested man as Pepijn van der Stap, also known online as Umbreon. He was previously arrested in 2023 in connection with a series of data theft and extortion cases.
According to DataBreaches.Net, van der Stap was arrested again on September 15, 2026. His background in cybersecurity has attracted attention because he previously worked for cybersecurity company Hadrian and volunteered with the Dutch Institute for Vulnerability Disclosure, or DIVD.
In a 2023 interview with DataBreaches.Net, van der Stap discussed his involvement in both legal and illegal cybersecurity activities. He said his work in cybersecurity had made him increasingly concerned about being caught and described experiencing intense paranoia at the time.
Van der Stap is currently listed on LinkedIn as the offensive security lead at Dutch cybersecurity company Neo Security. His profile describes his career as a journey that involved seeing cybersecurity from both sides, saying the experience taught him that security knowledge should be used to build and protect rather than break systems.
The arrest comes as ShinyHunters has claimed responsibility for a major breach of the U.S. Federal Bureau of Investigation’s job application website, apply.fbijobs.gov. The group claimed it had stolen terabytes of sensitive data from the site.
A ShinyHunters representative later told 404 Media that the FBI incident was part of a campaign intended to draw attention to the group’s claims and counter what it described as disinformation.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
ShinyHunters initially claimed that it had exploited a previously unknown zero-day vulnerability in Oracle PeopleSoft to gain unauthorized access to the system. However, security researchers later assessed that the attackers may have used a URL-encoding technique to bypass web application firewall protections designed to block exploitation of CVE-2026-35273.
Dutch Police Arrest 24-Year-Old in ShinyHunters Investigation



