INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

| 2026-09-28 15:55 CRITICAL HIGH LAW ENFORCEMENT
Executive Summary
AI-generated
A 24-year-old man from Amsterdam was arrested on September 29, 2026, in connection with the ShinyHunters group. The individual is expected to appear before the Rotterdam District Court on the same day. According to [IOC HIDDEN • LOGIN REQUIRED], Pepijn van der Stap (aka Umbreon), who worked at cybersecurity company Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD) in 2023, was previously apprehended for his role in a series of data thefts and extortions. The ShinyHunters group denied any connection with van der Stap after being contacted by The Hacker News about the arrest.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-35273 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ps•••••.war
da•••••.net
ap•••••.gov
fb•••••.gov
x•••••.jsp
Pl•••••.exe
tu•••••.jsp
u2•••••.jsp
162.219.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
LAPSUS$LAPSUS$TeamPCPTeamPCPShinyHuntersShinyHuntersScattered SpiderScattered Spider UmbreonUmbreonNeo-reGeorgNeo-reGeorg CVE-2026-35273CVE-2026-35273
Target & Sectors
BENELUX BENELUX NORTH_AMERICA NORTH_AMERICA educationeducation governmentgovernment healthhealth mediamedia technologytechnology transportationtransportation
Incident Timeline
‎September 2021
Threat actors using the alias "Umbreon" sold a database containing information on 2.3 million people from The Netherlands in September 2021.
target_region Netherlands
malware Umbreon
general_metric 2.3 people
‎June 2023
Threat actors used an unpatched Oracle PeopleSoft bug to launch a phishing attack in June 2023.
‎late 2023
Threat actors using the handle "Umbreon" associated with van der Stap, exploited a PeopleSoft bug to extort victims and post their data on English language hacking communities.
malware Umbreon
organisation Van der Stap
organisation RaidForums
‎March 2025
Rey was first publicly identified by the cybersecurity firm KELA in March 2025.
‎November 2025
KrebsOnSecurity messaged Rey's father in advance of a scheduled interview with his teenage son, Rey.
‎December 2025
Threat actors behind ShinyHunters exploited a PeopleSoft bug, which was released from prison in December 2025.
‎February 2026
ShinyHunters members used social engineering tactics to target Odido, the Netherlands' largest mobile telecommunications provider.
source_region Netherlands
threat_actor ShinyHunters
industry Telecommunications
‎May 2026
Threat actors, identified as the ShinyHunters group, exploited a PeopleSoft bug to target and steal sensitive data from the FBIJobs.gov portal.
threat_actor ShinyHunters
data_breach 2 TB
attribution FBI
attribution Learning Management System
attribution LMS
‎June 2026
ShinyHunters weaponized a similar flaw in CVE-2026-35273 to break into enterprise networks and extort victims.
threat_actor ShinyHunters
vulnerability CVE-2026-35273
‎June 9
ShinyHunters exploited a zero-day bug in Oracle PeopleSoft between May 27 and June 9.
threat_actor ShinyHunters
general_metric 27 May
‎June 10
Threat actors ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft to steal data from 100 global organizations.
threat_actor ShinyHunters
tactic Extortion
organisation BleepingComputer
victims 100 global organizations
‎2026/08/29
Threat actors TeamPCP exploited a PeopleSoft bug to compromise global code supply chains.
source_region Australia
‎September 9, 2026
Van der Stap, a self-proclaimed reformed hacker, appeared in an interview with KrebsOnSecurity on September 9, 2026.
organisation KrebsOnSecurity
‎September 15, 2026
Threat actors, identified as ShinyHunters, exploited a previously unknown vulnerability in Oracle PeopleSoft to carry out the attack that led to van der Stap's arrest on September 15, 2026.
‎September 16
Van der Stap was arrested by Dutch authorities on or around September 16.
target_region Netherlands
‎2026/09/21
ShinyHunters used artificial intelligence to target the FBI's jobs website and allegedly steal sensitive data on operations and agents.
threat_actor ShinyHunters
attribution FBI
general_metric 5,000 officials
‎Sept. 22
Threat actors used a taunting meme uploaded to Twitter by Rey's now-defunct account on September 22 as part of their ShinyHunters exploit against the Oracle PeopleSoft bug.
‎September 22
ShinyHunters claimed to have exploited an Oracle PeopleSoft bug allowing remote code execution, which they used to access the FBI Jobs platform and laterally spread into the FBI's AWS GovCloud infrastructure.
threat_actor ShinyHunters
attribution FBI
tactic Remote Code Execution
data_breach 23 September
‎September 23, 2026
ShinyHunters allegedly used a zero-day exploit in Oracle PeopleSoft to steal staff data, prompting the FBI to investigate.
threat_actor ShinyHunters
attribution FBI
‎Sep 23, 2026
Threat actors exploited a previously unknown vulnerability in Oracle PeopleSoft to gain unauthorized access to sensitive data.
‎Sept. 24
Threat actors used the Oracle PeopleSoft bug to target ShinyHunters.
threat_actor ShinyHunters
‎Sept. 25
ShinyHunters mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across various industries.
threat_actor ShinyHunters
industry Government
industry Education
industry Technology
industry Healthcare
industry Transportation
attribution Google Threat Intelligence Group
‎Sep 26, 2026
Threat actors exploited a previously unknown vulnerability in Oracle PeopleSoft to gain unauthorized access to sensitive data.
‎2026/09/28
ShinyHunters used a URL-encoding trick to bypass Mandiant's suggested web application firewall rules designed to mitigate the CVE-2026-35273 vulnerability in Oracle PeopleSoft.
threat_actor ShinyHunters
organisation Oracle PeopleSoft
organisation CVE-2026
organisation The Hacker News
threat_actor Scattered Spider
threat_actor LAPSUS$
organisation Wired
threat_actor TeamPCP
financial $100 track
organisation Odido
organisation NL Times
organisation Peoplesoft
organisation Mandiant
organisation BleepingComputer
organisation Wired’s
organisation The Register
organisation GnosticPlayers
organisation Google
infrastructure Windows
infrastructure Linux
organisation MeshAgent
organisation Data Breach / Cybercrime
organisation the U.S. Federal Bureau of Investigation
data_breach 2 TB
data_breach 3 TB
organisation Van der Stap
organisation Neo Security
organisation Reuters
organisation Oracle’s
organisation CVE-2026-35273
organisation DataBreaches
organisation Pepijn
organisation LinkedIn
organisation the Dutch company Neo Security
organisation Amazon
organisation Microsoft
financial $20,000 leader
financial €1.5 prosecutors
organisation MeshCentral
organisation SSH
organisation IP
victims 100 global organizations
organisation the Environment Management Hub
organisation JSP
organisation TCP
organisation RMM
organisation POST
organisation WebLogic
organisation Disable the Environment Management Hub
organisation Rotate
organisation Oracle WebLogic
organisation HTTPS
organisation NFL
organisation CHANEL
organisation OAuth
organisation Social Security
data_breach 5,000 records
organisation the white board
organisation Clock
‎September 29, 2026
A suspect in the ShinyHunters group is scheduled to appear before the Rotterdam District Court on September 29, 2026.
attribution the Rotterdam District Court
‎Sep 29, 2026
Threat actors exploited a previously unknown vulnerability in Oracle PeopleSoft to gain unauthorized access.
‎Tuesday, September 29
The Dutch police announced that a suspect in the ShinyHunters Oracle PeopleSoft bug case will appear before the Rotterdam District Court on Tuesday, September 29.
target_region Netherlands
attribution the Rotterdam District Court
Tactical Metrics
Metrics
financial
20,000
Leader
Metrics
financial
100,000,000
Track
Metrics
financial
1,500,000
Prosecutors
Metrics
infrastructure
‎Linux
Affected Product
Metrics
victims
100
Global Organizations
Metrics
data_breach
2
Tb
Metrics
infrastructure
‎Windows
Affected Product
Metrics
data_breach
3
Tb
Metrics
data_breach
5,000
Records
Metrics
data_breach
23
September