ShinyHunters Escalates Attacks Following Key Arrest, Targets FBI and Cl0p
The notorious hacking collective **ShinyHunters** has dramatically intensified its operations, including a breach of the **FBI**'s job application site and an extortion attempt against the **Cl0p** ransomware group. This escalation follows the arrest of a 24-year-old Dutch cybercriminal, **Pepijn van der Stap**, suspected of aiding the group's data theft and extortion schemes.
Authorities in the Netherlands have apprehended **Pepijn van der Stap**, a convicted cybercriminal from Almere and Lelystad, on suspicion of collaborating with the prolific hacker group **ShinyHunters**. Van der Stap, previously sentenced in 2023 for data thefts and extortions totaling between β¬1.5 million and β¬2.7 million, was known by his hacker handle β**Umbreon**.β
### The Double Life of 'Umbreon'
At his 2023 trial, Van der Stap confessed to leading a double life. By night, he operated as **Umbreon**, extorting victims and posting their stolen data on English-language hacking communities like the now-defunct RaidForums and Breached. By day, however, he worked as a software engineer at the Amsterdam-based cybersecurity startup **Hadrian** and volunteered with the **Dutch Institute for Vulnerability Disclosure** (**DIVD**), a non-profit security research group.

Van der Stap received a four-year prison sentence, with one year suspended. He was released in December 2025 and, in a September 2026 interview, claimed to be a reformed individual seeking to contribute positively to society. At the time, he was employed as an offensive security lead at the Dutch company **Neo Security**.
### Arrest and Immediate Fallout
Van der Stap's communication abruptly ceased shortly after his interview. Sources indicate he was arrested by Dutch authorities around September 16, 2026, and has been held for questioning since. His arrest is believed to be linked to a February 2026 incident where a native Dutch-speaking **ShinyHunters** member social engineered an employee of **Odido**, the Netherlands' largest mobile telecommunications provider. This intrusion led to the theft of data on over 6.2 million Dutch citizens.
**ShinyHunters** publicly confirmed the suspect in the **Odido** audio clip is a member, stating, βOur team member has our full support β emotionally, mentally, and financially.β The group also openly mocked Dutch law enforcement, calling them βa big jokeβ and βincompetent.β

### FBI and Cl0p Targeted in Retaliation
Days after Van der Stap's detention, **ShinyHunters** claimed responsibility for a highly audacious breach of the **FBI**'s job application site, apply.fbijobs.gov. The stolen data reportedly includes Social Security numbers and personal information of over 5,000 officials, including sensitive psychiatric and medical files of **FBI** staff. The **FBI** confirmed the compromise in a brief statement.
**ShinyHunters** attributed this breach, and others, to exploiting **CVE-2026-35273**, a recently patched vulnerability in **Oracle**'s **PeopleSoft** software-as-a-service platform. This zero-day vulnerability was reportedly exploited by **ShinyHunters** since June.
Initially, **Oracle** issued a fix, and **Mandiant** released web application firewall (WAF) rules to mitigate the threat. However, **ShinyHunters** reportedly bypassed **Mandiant**'s WAF rules using a URL-encoding trick. A joint report by **Mandiant** and the **Google Threat Intelligence Group** (**GTIG**) confirmed **ShinyHunters**' mass exploitation of the **PeopleSoft** vulnerability, impacting dozens of systems across various sectors including higher education, technology, healthcare, agriculture, transportation, and government.
Intriguingly, the defacement image left by **ShinyHunters** on the hacked **FBI** jobs site featured an ASCII art design of the PokΓ©mon character **Umbreon**, a clear nod to Van der Stap's former hacker alias. This image is identical to one used in **ShinyHunters**' 2020 hack of Hackforums, an English-language cybercrime community.