[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fF7LeTOuTHVAxOlBjCpe4VwQmOXMHK0SWabB598OT2aI":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"3bb77f1e-a35a-4bb9-8c54-defedcc74915","Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation","dutch-police-arrest-24-year-old-amsterdam-man-in-shinyhunters-investigation-b8f949","Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. \"It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters,\" the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the","Dutch authorities arrested a 24-year-old Amsterdam resident identified as Pepijn van der Stap (aka Umbreon) in connection with the ShinyHunters hacking group. Van der Stap, previously arrested in 2023 for data theft and extortion, was working as an offensive security lead at Neo Security while allegedly conducting illicit activities. The arrest comes as ShinyHunters claimed responsibility for breaching the FBI's job application portal and stealing terabytes of sensitive data, claiming the attack was a marketing campaign rather than extortion.","Dutch police arrest 24-year-old Amsterdam man linked to ShinyHunters hacker group.","Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation Ravie LakshmananSep 29, 2026United States Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. \"It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters,\" the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the Rotterdam District Court on September 29, 2026. Although law enforcement officials did not disclose any additional details, independent security journalist Brian Krebs and DataBreaches.Net identified the arrested man as Pepijn van der Stap (aka Umbreon), who was previously apprehended in 2023 for his role in a series of data thefts and extortions. Per DataBreaches.Net, van der Stap was arrested on September 15, 2026. In 2023, it emerged that the individual worked at cybersecurity company Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD). \"Working at Hadrian and volunteering at DIVD made me more paranoid about keeping up appearances, and I actually felt more pressure and paranoia because I was working such long hours,\" van der Stap told DataBreaches.Net in June 2023. \"So yes, I was doing more lawful work and much less illegal work but I became more paranoid about getting caught. The paranoia became so extreme that I was expecting a knock on the door at any time.\" He is presently employed as the offensive security lead at the Dutch company Neo Security, according to LinkedIn. In his profile, van der Stap acknowledged his journey \"hasn't been a straight line\" and that \"I've seen security from both sides of the terminal, an experience that taught me hard lessons but ultimately gave me clarity: knowledge is for building and protecting, not breaking.\" The development comes as ShinyHunters claimed credit for its brazen hack of the U.S. Federal Bureau of Investigation's (FBI) job application site apply.fbijobs.gov, stealing terabytes of sensitive data. \"This was all a marketing campaign to protect our business and actively combat disinformation,\" a ShinyHunters representative told 404 Media. \"If we made this statement normally then this much attention to our words and intentions would’ve never been this widespread.\" \"We'd have been ignored and disregarded. However, now everyone knows what the issue is and what we are doing. Everyone is reading about it. We proved our points on several occasions. We do not care what the public says and we are not affected by it nor do we cloud our judgement by external opinions and thoughts.\" In a statement shared with The Hacker News, the group reiterated again that the attack on the FBI's systems was not extortion and that it's not financially motivated. \"We understand why many misinterpreted this as extortion and are convinced we would publish this data and\u002For misuse it such as selling to third parties due to our history in past operations which has never involved a government entity of prominence,\" the spokesperson said. \"We again want to emphasise that this is not extortion, it was never one to begin with, not a threat, not a ransom, and not financially motivated. Nothing will happen. We are way past this situation in our business operations and we confidently believe we have been successful due to seeing a recent influx of success in our operations.\" Although the group said it exploited a new zero-day flaw in Oracle PeopleSoft to gain unauthorized access and siphon the data, it's now assessed that ShinyHunters employed a URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate CVE-2026-35273. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Cybercrime, data breach, ShinyHunters, Vulnerability, Web Security ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fdutch-police-arrest-24-year-old.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgWsGNpV8Y5_YLcyxRYju8E3caiN3I3Zttrlvxhz5iXfzVIR_Ayp_d_Zn2Wk12ZBkz5nW4eYfKeEs-xxs9kYuS_paAwO3wJleeUxdMRbrbU_lXwWVuG7ajiFH0UOEcoj3almps5b54DXt-mGy73GhXjCQzGsNNDJkhdfJXRI9XWeFF5hfsr4zjQty-Wued5\u002Fs1600\u002F1000111943.jpg","2026-09-29T08:35:10+00:00","2026-09-29T10:00:21.544059+00:00",8,[18,21,23,26,29,31],{"name":19,"type":20},"ShinyHunters","threat_actor",{"name":22,"type":20},"Pepijn van der Stap (aka Umbreon)",{"name":24,"type":25},"Oracle","vendor",{"name":27,"type":28},"Oracle PeopleSoft","product",{"name":30,"type":25},"Neo Security",{"name":32,"type":25},"Hadrian","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":33,"icon":35,"name":36,"slug":37},null,"Breaches","breaches",[39,44,49],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":50},{"id":51,"icon":35,"name":52,"slug":53},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[55],{"type":56,"value":57,"context":58},"cve","CVE-2026-35273","Oracle PeopleSoft vulnerability allegedly exploited by ShinyHunters; bypassed via URL-encoding trick"]