CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8702

As cited

Copy frozen at (site build).

vulnerabilities

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Dutch authorities arrested 23-year-old Pepijn van der Stap in mid-September on suspicion of aiding the ShinyHunters hacking group; van der Stap had previously been convicted in 2023 for data thefts and extortions under the hacker alias Umbreon and was released from prison in December 2025. Following his arrest, ShinyHunters escalated operations, exploiting CVE-2026-35273 in Oracle PeopleSoft to breach the FBI's job application site and steal personal data on over 5,000 officials, including Social Security numbers and sensitive medical files, and also targeted the ransomware group Cl0p. Evidence suggests a younger hacker known as Rey, who leads a merged group called ScatteredLapsussHunters, has taken control of ShinyHunters and may have framed van der Stap for the FBI breach by embedding the Umbreon Pokemon character in the defacement message.

Why it matters: Organizations using Oracle PeopleSoft must verify patches for CVE-2026-35273 are applied; the vulnerability is actively exploited at scale across higher education, technology, healthcare, agriculture, transportation, and government sectors, and URL-encoding bypass techniques circumvent some web application firewall protections.

VendorsMicrosoftGoogleOracle
Actorscl0pscattered spider
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Dutch authorities arrested 23-year-old Pepijn van der Stap in mid-September on suspicion of aiding the ShinyHunters hacking group; van der Stap had previously been convicted in 2023 for data thefts and extortions under the hacker alias Umbreon and was released from prison in December 2025. Following his arrest, ShinyHunters escalated operations, exploiting CVE-2026-35273 in Oracle PeopleSoft to breach the FBI's job application site and steal personal data on over 5,000 officials, including Social Security numbers and sensitive medical files, and also targeted the ransomware group Cl0p. Evidence suggests a younger hacker known as Rey, who leads a merged group called ScatteredLapsussHunters, has taken control of ShinyHunters and may have framed van der Stap for the FBI breach by embedding the Umbreon Pokemon character in the defacement message.

Why it matters: Organizations using Oracle PeopleSoft must verify patches for CVE-2026-35273 are applied; the vulnerability is actively exploited at scale across higher education, technology, healthcare, agriculture, transportation, and government sectors, and URL-encoding bypass techniques circumvent some web application firewall protections.

VendorsGoogleMicrosoftOracle
Actorscl0pscattered spider
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary