ShinyHunters: Dutch detain Pepijn van der Stap (Umbreon); FBI urges members to surrender after arrest (29 Sep)
Dutch police (Politie Landelijke Opsporing en Interventies, 28 September 2026) confirmed a 24-year-old Amsterdam man arrested earlier in September was detained in an investigation into the ShinyHunters hacking group. UPDATE 28–29 Sep wires (KrebsOnSecurity; Reuters / CBC): employer Neo Security offensive-security lead Benjamin Korper identified the detainee as Pepijn van der Stap; Krebs sources place the arrest around 15–16 September. Van der Stap was previously convicted (2023) over data theft/extortion as handle “Umbreon” (RaidForums/Breached era; custody, release Dec 2025) and had publicly cast himself as reformed. Krebs links the Dutch probe to the Odido (Netherlands telecom) social-engineering intrusion (~6.2M people). UPDATE 29 Sep 2026 — BleepingComputer / Dutch police / FBI Cyber Division Assistant Director Brett Leatherman video: Rotterdam District Court ordered at least another 90 days’ pre-trial detention; police said a large amount of information was found on his laptop “including details about two murders that were to be committed abroad” with indications the suspect “gave the order”; further arrests not ruled out. FBI states ShinyHunters and alleged co-conspirators breached more than 140 organizations since last year and collected at least US$70 million in extortion payments, and publicly urged remaining members to turn themselves in, citing seized infrastructure and shifting incentives to talk. Context: group’s prior FBI PeopleSoft breach claim remains on desk (shinyhunters-fbi-peoplesoft-20260922). Distinct from PeopleSoft mass exploitation (cve-2026-35273) and Clop DLS defacement (shinyhunters-clop-dls-20260919). Primary wire: BleepingComputer FBI/Dutch update 29 Sep; naming: Krebs + Reuters.
- Product
- ShinyHunters / related extortion activity (law-enforcement action; not a product CVE)
- Versions
- n/a
- Exploited in Australia?
- unknown
- Patch to
- No patch from arrest/FBI messaging alone. Continue PeopleSoft EMHub patching/disablement (CVE-2026-35273), WAF encoding bypass hunts, SaaS/SSO vendor hardening, and monitoring of ShinyHunters leak/extortion channels. Watch Dutch OM/Politie charging detail and any further arrests.
Primary: BleepingComputer — FBI tells ShinyHunters members to turn themselves in (29 Sep 2026) · Vendor: KrebsOnSecurity — Pepijn van der Stap / Umbreon naming + Odido context (28 Sep 2026) · CVE: CVE-2026-35273 · BleepingComputer — Dutch police confirm arrest (28 Sep 2026; earlier wire)
