Dutch police arrested 23-year-old convicted cybercriminal Pepijn van der Stap, known as Umbreon, on suspicion of supporting ShinyHunters-linked data theft and extortion. The investigation follows a February social-engineering intrusion at Dutch telecom provider Odido, where attackers allegedly stole data belonging to more than 6.2 million people. Reporting attributes parts of the operation to a Jordanian teenager known as Rey, associated with the ScatteredLapsussHunters collective, who may have taken control of the ShinyHunters brand and used Umbreon imagery in an FBI job-application-site defacement to implicate or taunt van der Stap amid an internal dispute.
Following the reported arrest, ShinyHunters claimed compromises of the FBI recruitment portal and the Clop ransomware group's Tor leak site. The Clop intrusion was attributed to unauthenticated Grav CMS path traversal vulnerability CVE-2026-42608 in an outdated Grav 1.7.43 deployment; ShinyHunters claimed to have taken source code, plugins, logs, and Tor onion-service private keys, prompting Clop to move its leak site. The group has also allegedly mass-exploited Oracle PeopleSoft flaw CVE-2026-35273 against dozens of organizations, according to Mandiant and Google Threat Intelligence Group. Organizations using Grav 1.7 should upgrade to the patched 1.7.53.4 release, while PeopleSoft operators should urgently assess exposure to the Oracle vulnerability and investigate for compromise.
See which actors are running it and whether you're in range.
19 events from the most recent confirmed update back to the earliest known activity.
Pepijn van der Stap, reportedly arrested in the Dutch ShinyHunters investigation, appeared before Rotterdam District Court. Police had searched his Amsterdam home and seized electronic devices on September 15; public reporting stated that his connection to ShinyHunters and the Odido breach remained unproven.
Mandiant and Google Threat Intelligence Group reported that ShinyHunters had mass-exploited CVE-2026-35273 to steal data from dozens of organizations. Reported victims spanned education, technology, healthcare, agriculture, transportation, and government sectors.
Dutch authorities arrested van der Stap on suspicion of assisting ShinyHunters-linked data theft and extortion, and held him for questioning. At the time, he was reportedly employed as an offensive-security lead at Neo Security.
ShinyHunters breached Clop’s Tor data-leak site, first uploading a text file and later replacing it with an Umbreon-themed defacement. The group claimed to have stolen the site source code, Grav plugins, server logs, and Tor onion-service private keys, while Clop disputed that the server contained valuable operational or financial data.
ShinyHunters reportedly began exploiting CVE-2026-35273 in Oracle PeopleSoft as a zero-day. Oracle subsequently released a patch, while the group reportedly used URL encoding to bypass proposed Mandiant web-application-firewall mitigations.
Grav published an advisory for CVE-2026-42608, an unauthenticated path-traversal vulnerability in Grav core form-upload handling. The 2.x remediation added identifier validation through a sanitizeId() allowlist.
A Dutch-speaking ShinyHunters member allegedly directed an Odido employee to a spoofed website, obtained access, and stole data concerning more than 6.2 million people. Dutch police later sought help identifying the caller, and ShinyHunters confirmed the recorded caller was a group member.
Grav privately fixed CVE-2026-42608 in Grav 2.0.0-beta.2. The flaw allowed unauthenticated path traversal through form-upload handling and affected legacy Grav 1.7 deployments that had not received a backport.
Pepijn van der Stap was released from prison after serving part of his sentence for prior data theft and extortion activity.
Dutch cybercriminal Pepijn van der Stap, known online as “Umbreon,” was convicted of data theft and extortion offenses that prosecutors said generated €1.5 million to €2.7 million. He received a four-year prison sentence, with one year suspended.
Troy Hunt’s weekly update reported that Saif was arrested in Jordan in connection with ShinyHunters. The report did not specify charges, the arresting agency, or the arrest date.
Following the compromise and defacement of its prior server, Clop moved its leak site to a new Tor onion address. It said the old address would remain temporarily accessible before retirement.
Grav confirmed that ShinyHunters exploited CVE-2026-42608 against Clop’s outdated Grav 1.7.43 installation. After receiving exploitation details, Grav backported the fix to the legacy branch and released Grav 1.7.53.4, urging 1.7 users to upgrade.
Following the arrest of alleged leader Pepijn van der Stap and the FBI’s appeal for members to contact investigators, ShinyHunters said recent events had not affected its operations or infrastructure. The group continued to threaten victim organizations with publication of stolen data unless they negotiated payments.
The FBI publicly urged remaining ShinyHunters members to contact investigators following the Netherlands arrest of an alleged leader. FBI Cyber Division Assistant Director Brett Leatherman said the group and its alleged co-conspirators had breached more than 140 organizations since 2025 and collected at least $70 million in extortion payments.
A Rotterdam court ordered the ShinyHunters suspect identified by journalist Brian Krebs as Pepijn van der Stap to remain detained pending trial for at least 90 days. Dutch police also said forensic evidence from his laptop included information related to two murders he allegedly ordered abroad.
ShinyHunters said its reported intrusion against the FBI was intended to counter what it called misinformation after the FBI publicly associated it with The Com. The group said the operation was not an extortion attempt and that it did not intend to publish allegedly stolen data.
Reporting indicated that ShinyHunters likely used a modified exploit for Oracle PeopleSoft vulnerability CVE-2026-35273 to compromise the FBI job-application site. The site was also defaced with an oversized Umbreon image.
Soon after van der Stap’s reported detention, ShinyHunters claimed it compromised the FBI job-application website, apply.fbijobs.gov; the FBI confirmed the site was hacked. Reporting said the exposed material included Social Security numbers and other personal information for more than 5,000 officials, including psychiatric and medical records.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
28 references tracked. Mallory keeps watching after this page renders.
troyhunt.com
Open sourcexakep.ru
Open sourcebitdefender.com
Open sourcebitdefender.com
Open sourcekrebsonsecurity.com
Open sourcebleepingcomputer.com
Open sourcenltimes.nl
Open sourcepolitie.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.