As cited
Copy frozen at (site build).
vulnerabilities
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Dutch authorities arrested 23-year-old Pepijn van der Stap in mid-September on suspicion of aiding the ShinyHunters hacking group; van der Stap had previously been convicted in 2023 for data thefts and extortions under the hacker alias Umbreon and was released from prison in December 2025. Following his arrest, ShinyHunters escalated operations, exploiting CVE-2026-35273 in Oracle PeopleSoft to breach the FBI's job application site and steal personal data on over 5,000 officials, including Social Security numbers and sensitive medical files, and also targeted the ransomware group Cl0p. Evidence suggests a younger hacker known as Rey, who leads a merged group called ScatteredLapsussHunters, has taken control of ShinyHunters and may have framed van der Stap for the FBI breach by embedding the Umbreon Pokemon character in the defacement message.
Why it matters: Organizations using Oracle PeopleSoft must verify patches for CVE-2026-35273 are applied; the vulnerability is actively exploited at scale across higher education, technology, healthcare, agriculture, transportation, and government sectors, and URL-encoding bypass techniques circumvent some web application firewall protections.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Dutch authorities arrested 23-year-old Pepijn van der Stap in mid-September on suspicion of aiding the ShinyHunters hacking group; van der Stap had previously been convicted in 2023 for data thefts and extortions under the hacker alias Umbreon and was released from prison in December 2025. Following his arrest, ShinyHunters escalated operations, exploiting CVE-2026-35273 in Oracle PeopleSoft to breach the FBI's job application site and steal personal data on over 5,000 officials, including Social Security numbers and sensitive medical files, and also targeted the ransomware group Cl0p. Evidence suggests a younger hacker known as Rey, who leads a merged group called ScatteredLapsussHunters, has taken control of ShinyHunters and may have framed van der Stap for the FBI breach by embedding the Umbreon Pokemon character in the defacement message.
Why it matters: Organizations using Oracle PeopleSoft must verify patches for CVE-2026-35273 are applied; the vulnerability is actively exploited at scale across higher education, technology, healthcare, agriculture, transportation, and government sectors, and URL-encoding bypass techniques circumvent some web application firewall protections.
- Source published
- First seen by Cybersecurity Tracker