Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.
“It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters,” the Politie Landelijke Opsporing en Interventies said in an X post Monday.
Police said the individual is expected to appear before the Rotterdam District Court on September 29, 2026.
Although law enforcement officials did not disclose any additional details, independent security journalist Brian Krebs and DataBreaches.Net identified the arrested man as Pepijn van der Stap (aka Umbreon), who was previously apprehended in 2023 for his role in a series of data thefts and extortions.
Per DataBreaches.Net, van der Stap was arrested on September 15, 2026. In 2023, it emerged that the individual worked at cybersecurity company Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD).
“Working at Hadrian and volunteering at DIVD made me more paranoid about keeping up appearances, and I actually felt more pressure and paranoia because I was working such long hours,” van der Stap told DataBreaches.Net in June 2023.
“So yes, I was doing more lawful work and much less illegal work but I became more paranoid about getting caught. The paranoia became so extreme that I was expecting a knock on the door at any time.”
He is presently employed as the offensive security lead at the Dutch company Neo Security, according to LinkedIn.
In his profile, van der Stap acknowledged his journey “hasn’t been a straight line” and that “I’ve seen security from both sides of the terminal, an experience that taught me hard lessons but ultimately gave me clarity: knowledge is for building and protecting, not breaking.”
The development comes as ShinyHunters claimed credit for its brazen hack of the U.S. Federal Bureau of Investigation’s (FBI) job application site apply.fbijobs.gov, stealing terabytes of sensitive data.
“This was all a marketing campaign to protect our business and actively combat disinformation,” a ShinyHunters representative told 404 Media. “If we made this statement normally then this much attention to our words and intentions would’ve never been this widespread.”
“We’d have been ignored and disregarded. However, now everyone knows what the issue is and what we are doing. Everyone is reading about it. We proved our points on several occasions. We do not care what the public says and we are not affected by it nor do we cloud our judgement by external opinions and thoughts.”
In a statement shared with The Hacker News, the group reiterated again that the attack on the FBI’s systems was not extortion and that it’s not financially motivated.
“We understand why many misinterpreted this as extortion and are convinced we would publish this data and/or misuse it such as selling to third parties due to our history in past operations which has never involved a government entity of prominence,” the spokesperson said.
“We again want to emphasise that this is not extortion, it was never one to begin with, not a threat, not a ransom, and not financially motivated. Nothing will happen. We are way past this situation in our business operations and we confidently believe we have been successful due to seeing a recent influx of success in our operations.”
Although the group said it exploited a new zero-day flaw in Oracle PeopleSoft to gain unauthorized access and siphon the data, it’s now assessed that ShinyHunters employed a URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate CVE-2026-35273.
