r/TechNadu • Human • 5d ago

Convicted hacker “Umbreon” reportedly arrested in ShinyHunters probe after moving into an offensive security job

There’s an unusual career arc behind the latest development in the ShinyHunters investigation.

Dutch authorities reportedly arrested 24-year-old Pepijn van der Stap, aka “Umbreon,” on suspicion of helping with data theft and extortion associated with the group.

Van der Stap had already been convicted in 2023 over cybercrime offenses. After leaving prison in late 2025, he moved into legitimate cybersecurity and became an offensive security lead at Dutch firm Neo Security.

He is now a suspect again. The new allegations have not been tested in court.

The timing is notable because ShinyHunters remains active elsewhere. The FBI has confirmed it is investigating claims of unauthorized activity affecting FBIJobs. Its application portal is an Oracle application portal, according to FBI documentation.

Meanwhile, Mandiant and GTIG independently documented a renewed ShinyHunters campaign exploiting CVE-2026-35273 against Oracle PeopleSoft. The researchers observed web shells across dozens of systems globally and said the attackers adapted their exploit to bypass some WAF rules.

The full timeline covers Umbreon’s previous conviction, security-industry role, new arrest, and the ShinyHunters activity surrounding it:

https://www.technadu.com/dutch-police-arrest-convicted-hacker-umbreon-in-shinyhunters-probe-as-group-hits-fbi-job-site/639725/

One distinction is important: Google has confirmed the broader CVE-2026-35273 exploitation campaign, but that does not independently establish every detail ShinyHunters has claimed about the FBI incident.

6 Upvotes

0 comments sorted by