Inside the FBI Hack: ShinyHunters Claimed It as Their Top Suspect Sat in Dutch Jail | #cybercrime | #infosec


A view of the J. Edgar Hoover Building, which served as the headquarters building for the Federal Bureau of Investigation (FBI) since 1975, in Washington, DC, on February 6, 2026. FBI Director Kash Patel announced on December 26, 2025, that the FBI has finalized a plan to permanently close the building and move the FBI workforce to a new facility.
Photo by Alex WROBLEWSKI / AFP via Getty Images

The Briefing:

  • Dutch police arrested Pepijn van der Stap, 24, from Almere, on or around September 16, on suspicion of involvement with ShinyHunters; Dutch media separately report he is under investigation for allegedly commissioning two murders to be carried out abroad.
  • ShinyHunters announced on September 22 that it had defaced the FBI’s jobs portal at apply.fbijobs.gov and extracted between 2 and 3 terabytes of data — including Social Security numbers, agent role assignments and medical records. The attack was driven by the group’s demand that the FBI retract a May advisory, not by a financial ransom.
  • A September 25 report from Mandiant and Google’s Threat Intelligence Group confirmed a second wave of Oracle PeopleSoft exploitation across higher education, healthcare, agriculture, transportation and government sectors globally; Mandiant estimates the group is on pace to collect nearly $100 million in extortion payments during 2026.

A 24-year-old Dutch national with a prior cybercrime conviction was taken into custody by Dutch authorities on or around September 16 — just days before the hacker collective ShinyHunters publicly claimed to have broken into the FBI’s personnel hiring portal and walked away with data covering thousands of federal agents and job applicants. The sequence of events is now raising a question that investigators are actively pursuing: did a rival faction within the group use the Dutchman’s arrest as cover to carry out a brazen government hack and direct the blame in his direction?

The arrest is pulling back the curtain on a story far more layered than a single data breach — one involving internal power struggles, a Pokémon-linked identity dispute, alleged murder plots, and a cybercrime group that Mandiant researcher Austin Larsen told Krebs on Security is on pace to collect nearly $100 million in extortion payments in 2026 alone.

The Suspect Nobody Named

Dutch police declined to publicly identify the man they had taken into custody. Three independent sources subsequently confirmed to Krebs on Security that he is Pepijn van der Stap, a convicted cybercriminal from Almere who was sentenced to four years in prison — one suspended — in November 2023 for a campaign of corporate network intrusions, database theft and extortion that prosecutors calculated had funneled between €1.5 million and €2.7 million through criminal channels. Dutch National Police formally confirmed on September 29 that a 24-year-old had been arrested in connection with the ShinyHunters investigation and would appear before the Rotterdam District Court.

Van der Stap’s story had long cut between two simultaneous careers. By day, he held a position as a software engineer at Hadrian, an Amsterdam-based cybersecurity startup, and contributed as a volunteer researcher to the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit that flags dangerous software weaknesses to organizations worldwide. After hours, operating under the alias “Umbreon” — a name taken from a dark-type character in the Pokémon franchise — he sold stolen databases on hacking forums including the now-defunct RaidForums and ran extortion demands against corporate victims. At trial, he admitted to this double life. Both Hadrian and DIVD conducted independent forensic reviews and found no evidence he had abused his access in either role.

After serving his sentence, van der Stap was released from prison in December 2025. In a September 9 interview with Krebs on Security, he described himself as someone working to rebuild his professional reputation and resolve outstanding civil claims from past victims. He was employed at the time as offensive security lead at Dutch firm Neo Security. Shortly after that interview, he stopped replying to all messages — and sources say Dutch authorities showed up at his residence not long after.

A Breach Timed to Destabilize — or to Frame?

The timing matters. Van der Stap was detained around September 16. On September 22, ShinyHunters announced on its dark web platform — first reported by 404 Media — that it had defaced the FBI jobs site at apply.fbijobs.gov and extracted between 2 and 3 terabytes of sensitive data. The group claimed access to records from the bureau’s criminal justice, human resources and medical systems, covering what it described as nearly all active FBI agents and applicants. It distributed samples of 5,000 agent records to multiple news organizations, which found them to contain valid-looking names, home addresses, phone numbers and job designations.

What distinguished this attack from the group’s standard extortion playbook was the stated motive. ShinyHunters was not demanding money. It was demanding that the FBI retract a public advisory published in May 2026 — a document the group insisted contained false allegations about its tactics, including accusations of swatting and sextortion. The Record reported that the group threatened to publish everything if the advisory was not removed within a week.

The FBI’s public statement confirmed that the bureau is “actively and aggressively investigating” unauthorized activity affecting FBIjobs.gov, but stopped short of confirming what was taken or confirming how the intrusion occurred. Reuters reviewed documents shared by the hackers and reported that they appeared to contain sensitive psychiatric and medical files tied to bureau personnel, though it could not independently confirm where the files came from. Axios noted that cybersecurity researchers who reviewed the incident found the intrusion itself credible.

The Oracle Flaw That Opened the Door

ShinyHunters claims it entered FBI systems through CVE-2026-35273, a critical remote code execution vulnerability in Oracle’s PeopleSoft enterprise platform. The flaw, rated 9.8 out of 10 in severity, requires no user credentials and no interaction from anyone logged into the system — a network-facing PeopleSoft Environment Management Hub is all an attacker needs to take over the server entirely. Oracle first disclosed the vulnerability on June 10, 2026, one day after Mandiant and Google’s Threat Intelligence Group published research documenting that ShinyHunters had already been exploiting it as a zero-day since May 27 against more than 100 organizations, mostly universities.

After Oracle issued its patch, some organizations opted to deploy web application firewall rules as an interim measure rather than apply the update immediately. That stopgap was short-lived: BleepingComputer reported that ShinyHunters began using a URL-encoding variation that caused the firewall rules to fail, effectively reopening the attack surface for any organization that had not installed the actual patch. A report published September 25 by Mandiant and Google’s Threat Intelligence Group confirmed this second wave had hit dozens of additional systems across higher education, technology, healthcare, agriculture, transportation and government sectors worldwide.

Umbreon in the Room — and the Question of Who Put It There

The defacement ShinyHunters left on the FBI jobs site carried a pointed visual signature: an ASCII art rendering of the Pokémon character Umbreon — the exact character van der Stap had used as his criminal persona for years. Sources close to the investigation told Krebs on Security they do not believe the placement was accidental.

The current de facto leadership of ShinyHunters has consolidated around a teenage cybercriminal from Amman, Jordan, who operates under the alias Rey and is one of three administrators of the Scattered Lapsus$ Hunters (SLSH) Telegram channel — a collective that cyber researchers describe as an amalgam of Scattered Spider, Lapsus$ and ShinyHunters members. Sources said Rey had a protracted dispute with van der Stap over control of the ShinyHunters brand. The Umbreon embedding, those sources said, appeared calibrated to direct law enforcement scrutiny at the Dutchman already in Dutch custody.

Rey’s main Twitter/X account posted a taunting meme immediately after the breach made headlines. Hours after Krebs on Security contacted Rey’s father — who works for Royal Jordanian Airlines — to request an interview, that account was deleted. Multiple follow-up messages to the father went unanswered.

FBI Issues a Warning; Dutch Probe Expands

Brett Leatherman, assistant director of the FBI Cyber Division, released a video statement crediting Dutch law enforcement for the arrest and addressing ShinyHunters members still operating. According to The Record, Leatherman had also spoken about the group at a press roundtable roughly two weeks before the breach, calling ShinyHunters “a big problem when it comes to data exfiltration and extortion attacks.”

Mandiant analyst Austin Larsen separately estimated to Krebs on Security that ShinyHunters is on track to pull in nearly $100 million from extortion victims in 2026 — a figure that reflects the breadth of a campaign extending well beyond the FBI and across dozens of sectors and countries.

The Dutch investigation has moved on parallel tracks. In early September, before van der Stap’s arrest, Dutch police had already asked the public to identify a voice on an audio recording from February 2026, in which a native Dutch speaker social-engineered an employee of Odido — the country’s largest mobile carrier — into logging into a spoofed website. ShinyHunters confirmed the voice belongs to a member of the group and pledged to cover the individual’s legal and financial costs. On September 29, Dutch outlet RTL reported that investigators also suspect van der Stap of ordering at least two murders to be committed abroad — a development that emerged during the broader probe. Dutch authorities have seized multiple data storage devices and say further arrests remain possible.

© {{Year}} Latin Times. All rights reserved. Do not reproduce without permission.



Click Here For The Original Source.

——————————————————–

..........

.

.