---
title: "Dutch court orders hacker held in ShinyHunters FBI breach probe"
description: "Investigators say evidence on the suspect’s laptop points to two murders ordered abroad, as the group escalated attacks after his arrest"
author: "rews desk"
published: 2026-09-29T09:30:30Z
modified: 2026-09-29T17:05:48Z
url: https://rews.cc/a/shinyhunters-hacked-the-fbi-s-files-and-asked-only-for-a-ret-e4de3a
language: en
tags: ["cybersecurity", "fbi", "data-breach", "ransomware", "shinyhunters", "us", "tech"]
publisher: "Rews (https://rews.cc)"
---

# Dutch court orders hacker held in ShinyHunters FBI breach probe

*Investigators say evidence on the suspect’s laptop points to two murders ordered abroad, as the group escalated attacks after his arrest*

By rews desk · September 29, 2026 · https://rews.cc/a/shinyhunters-hacked-the-fbi-s-files-and-asked-only-for-a-ret-e4de3a

## In brief

- Dutch court orders 24-year-old suspect held 90 days in ShinyHunters investigation
- Police say his laptop held evidence of two murders he allegedly ordered abroad
- Sources identify suspect as Pepijn van der Stap, previously convicted hacker “Umbreon”
- FBI says data on 5,000+ officials, including medical and psychiatric records, was stolen
- ShinyHunters says it will not publish the FBI data but cannot guarantee shared samples

A court in Rotterdam ordered a 24-year-old Dutch man held for at least 90 days pending trial on Tuesday, as authorities investigate his suspected role in data thefts and extortion by the hacking group ShinyHunters.

Dutch police identified evidence on the suspect’s laptop including details of two murders he allegedly ordered abroad, the Dutch National Police said, cited by CyberScoop. Days after his arrest, remaining ShinyHunters members stole sensitive data from the FBI and tried to extort the Russian ransomware gang Cl0p, according to security researcher Brian Krebs.

Dutch police confirmed only that “a 24-year-old man from Amsterdam” was arrested this month. Three sources told Krebs the suspect is Pepijn van der Stap, a convicted cybercriminal who was working as offensive security lead at the Dutch firm Neo Security.

Van der Stap was convicted in 2023 for data thefts and extortions that prosecutors said earned between 1.5 million and 2.7 million euros under the alias “Umbreon,” according to Krebs. Sentenced to four years in prison, one suspended, he was released in December 2025.

Two sources told Krebs authorities arrested Van der Stap on or around Sept. 16. The [Dutch police statement, reported by BleepingComputer](https://www.bleepingcomputer.com/news/security/dutch-police-confirm-arrest-in-shinyhunters-hacking-investigation/), said the suspect was due before the Rotterdam District Court on Tuesday.

FBI Director Kash Patel wrote that “FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest,” according to CyberScoop. FBI cyber division assistant director Brett Leatherman said the group and its associates have breached more than 140 organizations and taken at least $70 million in extortion payments since the previous year, urging remaining members to “reach out first while the choice is still yours.”

Dutch investigators have separately asked the public to identify the voice on a February 2026 recorded call in which a Dutch-speaking ShinyHunters member tricked an Odido employee into logging into a spoofed website, leading to the theft of data on more than 6.2 million people. ShinyHunters told NL Times the man on the recording is a member and that “our team member has our full support – emotionally, mentally, and financially.”

## FBI breach

Days after the arrest, ShinyHunters claimed credit for breaching apply.fbijobs.gov, the FBI’s job application site, stealing Social Security numbers and personal data on more than 5,000 officials, according to 404 Media. Reuters reported the files included job titles or teams, such as special agent or major cybercrimes unit, along with sensitive psychiatric and medical records.

[![Notorious hacking group claims it breached FBI services](https://i.ytimg.com/vi/96YTa9QFzYc/hqdefault.jpg)](https://www.youtube.com/watch?v=96YTa9QFzYc)

CBS News reports on ShinyHunters’ claimed breach of the FBI’s job application portal. Video: CBS News · YouTube

ShinyHunters said it exploited a vulnerability in Oracle’s PeopleSoft platform, tracked as [CVE-2026-35273](https://www.oracle.com/security-alerts/alert-cve-2026-35273.html). Oracle patched the flaw in June after Mandiant found it had been exploited as a zero-day between May 27 and June 9. Mandiant and the Google Threat Intelligence Group said in a Sept. 25 report that the group had mass-exploited the flaw across dozens of organizations in higher education, technology, healthcare, agriculture, transportation and government.

The hackers gave the FBI one week to amend a May advisory describing ShinyHunters’ tactics. An FBI spokesperson told CNN that “FBI employees potentially impacted have received communication and notification multiple times within the last week.” A memo to staff, reported by the New York Times and cited by Gizmodo, said the FBI was “operating under the premise that the threat actor is also exfiltrating personally identifiable information of all FBI employees.”

As the deadline passed Monday, a ShinyHunters representative told CBC News the group “never planned to release the sensitive data,” calling reports of an extortion threat “false assumptions and wild speculations” and the episode “a marketing campaign to protect our business and actively combat disinformation.”

> There’s going to be people that are willing to pay a high price for this data.

The group told CBC News it could not guarantee the safety of a 5,000-line sample already shared with journalists, saying that was “out of our control.” Ian Lin, head of research and development at Toronto cybersecurity firm Packetlabs, told CBC News criminal hackers commonly reuse stolen data as leverage. “The FBI and law enforcement should all still remain vigilant,” Lin said.

An ASCII image of the Pokemon character Umbreon, Van der Stap’s former handle, appeared in the defacement ShinyHunters left on the FBI jobs site and on the leak site of the ransomware gang [Cl0p](https://rews.cc/a/clop-ransomware-gang-moves-dark-web-site-after-shinyhunters--9ac02f) after demanding an eight-figure ransom. Sources close to the investigation told Krebs the imagery was likely placed by a rival figure, a teenage hacker from Amman, Jordan known as Rey who leads a coalition called ScatteredLapsussHunters, to pin the FBI hack on Van der Stap amid a dispute over control of the ShinyHunters name.

Mandiant researcher Austin Larsen told Krebs the group is on track to collect nearly $100 million in extortion payments in 2026. A ShinyHunters representative told 404 Media that Van der Stap “has no association with us” and called Dutch police “incompetent.” Neo Security did not respond to requests for comment, according to Krebs.

## See also

- [Mandiant/GTIG report on ShinyHunters SaaS data-theft campaign](https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft) — cloud.google.com · Google threat intelligence writeup on the group's PeopleSoft exploitation
- [CyberScoop report on the Dutch arrest and murder evidence](https://cyberscoop.com/shinyhunters-alleged-leader-arrested-netherlands/) — cyberscoop.com · Details on the laptop evidence and FBI officials' statements

## Sources

- [Dutch Police Arrest 'Reformed' Hacker in ShinyHunters Investigation](https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/) — krebsonsecurity.com
- [FBI grapples with fallout from massive data breach](https://cnn.com/2026/09/28/politics/fbi-fallout-data-breach-hacking) — cnn.com
- [ShinyHunters says it won't leak stolen FBI data](https://cbc.ca/news/world/shinyhunters-say-they-wont-release-fbi-data-9.7361716) — cbc.ca
- [FBI Hackers Say They Won't Publish Massive Trove of Employee Data](https://404media.co/fbi-hackers-say-they-wont-publish-massive-trove-of-fbi-employee-data/) — 404media.co
- [FBI Memo Reportedly Assumes ShinyHunters Stole All Employees' Personal Data](https://gizmodo.com/fbi-staff-memo-reportedly-assumes-shinyhunters-stole-all-fbi-employees-personal-data-2000818601) — gizmodo.com
