INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
| 2026-09-28 15:55 CRITICAL HIGH LAW ENFORCEMENT
Executive Summary
AI-generated
A 24-year-old man from Amsterdam was arrested on September 29, 2026, in connection with the ShinyHunters group. The individual is expected to appear before the Rotterdam District Court on the same day. According to [IOC HIDDEN • LOGIN REQUIRED], Pepijn van der Stap (aka Umbreon), who worked at cybersecurity company Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD) in 2023, was previously apprehended for his role in a series of data thefts and extortions. The ShinyHunters group denied any connection with van der Stap after being contacted by The Hacker News about the arrest.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-35273 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ps•••••.war
da•••••.net
ap•••••.gov
fb•••••.gov
x•••••.jsp
Pl•••••.exe
tu•••••.jsp
u2•••••.jsp
162.219.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
LAPSUS$LAPSUS$TeamPCPTeamPCPShinyHuntersShinyHuntersScattered SpiderScattered Spider
UmbreonUmbreonNeo-reGeorgNeo-reGeorg
CVE-2026-35273CVE-2026-35273
Target & Sectors
BENELUX
BENELUX
NORTH_AMERICA
NORTH_AMERICA
educationeducation
governmentgovernment
healthhealth
mediamedia
technologytechnology
transportationtransportation
Incident Timeline
September 2021
Threat actors using the alias "Umbreon" sold a database containing information on 2.3 million people from The Netherlands in September 2021.
Click on any entity below to view its context and source!
target_region
Netherlands
Pepijn van der Stap’s alter ego “Umbreon” selling a database on RaidForums, offering information on 2.3 million people from The Netherlands in September 2021.
malware
Umbreon
Pepijn van der Stap’s alter ego “Umbreon” selling a database on RaidForums, offering information on 2.3 million people from The Netherlands in September 2021.
general_metric
2.3 people
Pepijn van der Stap’s alter ego “Umbreon” selling a database on RaidForums, offering information on 2.3 million people from The Netherlands in September 2021.
June 2023
Threat actors used an unpatched Oracle PeopleSoft bug to launch a phishing attack in June 2023.
late 2023
Threat actors using the handle "Umbreon" associated with van der Stap, exploited a PeopleSoft bug to extort victims and post their data on English language hacking communities.
Click on any entity below to view its context and source!
malware
Umbreon
At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle “
Umbreon
” to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached.
organisation
Van der Stap
At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle “
Umbreon
” to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached.
organisation
RaidForums
At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle “
Umbreon
” to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached.
March 2025
Rey was first publicly identified by the cybersecurity firm KELA in March 2025.
November 2025
KrebsOnSecurity messaged Rey's father in advance of a scheduled interview with his teenage son, Rey.
December 2025
Threat actors behind ShinyHunters exploited a PeopleSoft bug, which was released from prison in December 2025.
February 2026
ShinyHunters members used social engineering tactics to target Odido, the Netherlands' largest mobile telecommunications provider.
Click on any entity below to view its context and source!
source_region
Netherlands
Authorities in the Netherlands have been
asking the public for help
in identifying the voice in a recorded telephone call from February 2026 in which a native Dutch-speaking ShinyHunters member social engineered their way into
Odido
, the nation’s largest mobile telecommunications provider.
threat_actor
ShinyHunters
Authorities in the Netherlands have been
asking the public for help
in identifying the voice in a recorded telephone call from February 2026 in which a native Dutch-speaking ShinyHunters member social engineered their way into
Odido
, the nation’s largest mobile telecommunications provider.
industry
Telecommunications
Authorities in the Netherlands have been
asking the public for help
in identifying the voice in a recorded telephone call from February 2026 in which a native Dutch-speaking ShinyHunters member social engineered their way into
Odido
, the nation’s largest mobile telecommunications provider.
May 2026
Threat actors, identified as the ShinyHunters group, exploited a PeopleSoft bug to target and steal sensitive data from the FBIJobs.gov portal.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
The disclosure comes as the ShinyHunters group
broke
into the U.S. Federal Bureau of Investigation's FBIJobs.gov portal (which
remains inaccessible
as of writing) and stole about 2-3 TB of sensitive data to contest allegations made by the agency against the group in a May 2026 alert.
ShinyHunters said the FBI was targeted in response to a
May 2026 public service announcement
(PSA) that detailed the threat actor's targeting of
Canvas
, an online Learning Management System (LMS), while urging victims not to pay.
data_breach
2 TB
The disclosure comes as the ShinyHunters group
broke
into the U.S. Federal Bureau of Investigation's FBIJobs.gov portal (which
remains inaccessible
as of writing) and stole about 2-3 TB of sensitive data to contest allegations made by the agency against the group in a May 2026 alert.
attribution
FBI
The group says it targeted the FBI after a May 2026 public advisory describing its tactics and warning victims against paying.
ShinyHunters said the FBI was targeted in response to a
May 2026 public service announcement
(PSA) that detailed the threat actor's targeting of
Canvas
, an online Learning Management System (LMS), while urging victims not to pay.
attribution
Learning Management System
ShinyHunters said the FBI was targeted in response to a
May 2026 public service announcement
(PSA) that detailed the threat actor's targeting of
Canvas
, an online Learning Management System (LMS), while urging victims not to pay.
attribution
LMS
ShinyHunters said the FBI was targeted in response to a
May 2026 public service announcement
(PSA) that detailed the threat actor's targeting of
Canvas
, an online Learning Management System (LMS), while urging victims not to pay.
June 2026
ShinyHunters weaponized a similar flaw in CVE-2026-35273 to break into enterprise networks and extort victims.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
However, ShinyHunters weaponized a similar flaw (
CVE-2026-35273
) in June 2026 to break into enterprise networks and extort victims.
vulnerability
CVE-2026-35273
However, ShinyHunters weaponized a similar flaw (
CVE-2026-35273
) in June 2026 to break into enterprise networks and extort victims.
June 9
ShinyHunters exploited a zero-day bug in Oracle PeopleSoft between May 27 and June 9.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Mandiant reported in June that ShinyHunters was exploiting the bug as a zero-day between May 27 and June 9 in attacks on academic institutions.
general_metric
27 May
Mandiant reported in June that ShinyHunters was exploiting the bug as a zero-day between May 27 and June 9 in attacks on academic institutions.
June 10
Threat actors ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft to steal data from 100 global organizations.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
On June 10,
BleepingComputer first reported
that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.
tactic
Extortion
On June 10,
BleepingComputer first reported
that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.
organisation
BleepingComputer
On June 10,
BleepingComputer first reported
that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.
victims
100 global organizations
On June 10,
BleepingComputer first reported
that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.
2026/08/29
Threat actors TeamPCP exploited a PeopleSoft bug to compromise global code supply chains.
Click on any entity below to view its context and source!
source_region
Australia
…is year to help better monetize important stolen credentials collected by
TeamPCP
, an upstart group that was having great success compromising global code supply chains with malicious software but hadn’t been able to profit much from their stolen data (two alleged leaders of TeamPCP
were arrested last month in Australia
, and in an interview the TeamPCP leader claimed they made just $20,000).
September 9, 2026
Van der Stap, a self-proclaimed reformed hacker, appeared in an interview with KrebsOnSecurity on September 9, 2026.
Click on any entity below to view its context and source!
organisation
KrebsOnSecurity
In an interview with KrebsOnSecurity on September 9, 2026, Van der Stap cast himself as a reformed hacker who was trying to turn his life around and make a positive contribution to society.
September 15, 2026
Threat actors, identified as ShinyHunters, exploited a previously unknown vulnerability in Oracle PeopleSoft to carry out the attack that led to van der Stap's arrest on September 15, 2026.
September 16
Van der Stap was arrested by Dutch authorities on or around September 16.
Click on any entity below to view its context and source!
target_region
Netherlands
According to two sources with knowledge of the matter, Van der Stap was arrested by Dutch authorities on or around September 16, and has been held in custody for questioning since.
2026/09/21
ShinyHunters used artificial intelligence to target the FBI's jobs website and allegedly steal sensitive data on operations and agents.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Last week, ShinyHunters took credit
for an attack on the FBI
that saw the group deface a jobs website run by the agency and allegedly steal troves of sensitive data on FBI operations and agents.
attribution
FBI
Last week, ShinyHunters took credit
for an attack on the FBI
that saw the group deface a jobs website run by the agency and allegedly steal troves of sensitive data on FBI operations and agents.
The group upped the ante last week with its attack on the FBI, providing 5,000-person samples of stolen data to numerous news outlets that confirmed the legitimacy of the data.
general_metric
5,000 officials
The group upped the ante last week with its attack on the FBI, providing 5,000-person samples of stolen data to numerous news outlets that confirmed the legitimacy of the data.
Sept. 22
Threat actors used a taunting meme uploaded to Twitter by Rey's now-defunct account on September 22 as part of their ShinyHunters exploit against the Oracle PeopleSoft bug.
September 22
ShinyHunters claimed to have exploited an Oracle PeopleSoft bug allowing remote code execution, which they used to access the FBI Jobs platform and laterally spread into the FBI's AWS GovCloud infrastructure.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
ShinyHunters told BleepingComputer on September 22 that the alleged vulnerability allowed remote code execution and was used to access the FBI Jobs platform, then spread laterally into the FBI's AWS GovCloud infrastructure.
The claim surfaced on September 22 and quickly drew attention after ShinyHunters said it had obtained data on a large number of current and former FBI personnel.
attribution
FBI
ShinyHunters told BleepingComputer on September 22 that the alleged vulnerability allowed remote code execution and was used to access the FBI Jobs platform, then spread laterally into the FBI's AWS GovCloud infrastructure.
The claim surfaced on September 22 and quickly drew attention after ShinyHunters said it had obtained data on a large number of current and former FBI personnel.
tactic
Remote Code Execution
ShinyHunters told BleepingComputer on September 22 that the alleged vulnerability allowed remote code execution and was used to access the FBI Jobs platform, then spread laterally into the FBI's AWS GovCloud infrastructure.
data_breach
23 September
"
"One small operational clue is the September 23 timestamp on the group's post, while the news emerged on September 22 in the U.S.
September 23, 2026
ShinyHunters allegedly used a zero-day exploit in Oracle PeopleSoft to steal staff data, prompting the FBI to investigate.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack
Pierluigi Paganini
September 23, 2026
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet.
attribution
FBI
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack
Pierluigi Paganini
September 23, 2026
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet.
Sep 23, 2026
Threat actors exploited a previously unknown vulnerability in Oracle PeopleSoft to gain unauthorized access to sensitive data.
Sept. 24
Threat actors used the Oracle PeopleSoft bug to target ShinyHunters.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
On Sept. 24, KrebsOnSecurity again contacted Rey’s dad, asking to interview him and his son for a story on Rey’s apparent ascendency as the head of ShinyHunters.
Sept. 25
ShinyHunters mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across various industries.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
In
a report
released Sept. 25, security experts at
Mandiant
and the
Google Threat Intelligence Group
(GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
industry
Government
In
a report
released Sept. 25, security experts at
Mandiant
and the
Google Threat Intelligence Group
(GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
industry
Education
In
a report
released Sept. 25, security experts at
Mandiant
and the
Google Threat Intelligence Group
(GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
industry
Technology
In
a report
released Sept. 25, security experts at
Mandiant
and the
Google Threat Intelligence Group
(GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
industry
Healthcare
In
a report
released Sept. 25, security experts at
Mandiant
and the
Google Threat Intelligence Group
(GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
industry
Transportation
In
a report
released Sept. 25, security experts at
Mandiant
and the
Google Threat Intelligence Group
(GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
attribution
Google Threat Intelligence Group
In
a report
released Sept. 25, security experts at
Mandiant
and the
Google Threat Intelligence Group
(GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
Sep 26, 2026
Threat actors exploited a previously unknown vulnerability in Oracle PeopleSoft to gain unauthorized access to sensitive data.
2026/09/28
ShinyHunters used a URL-encoding trick to bypass Mandiant's suggested web application firewall rules designed to mitigate the CVE-2026-35273 vulnerability in Oracle PeopleSoft.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters.
Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group
ShinyHunters
.
Those sources said Rey had an ongoing beef with the Dutch hacker over control of the ShinyHunters brand and data, and that the inclusion of the oversized Umbreon Pokemon image in the FBI jobs site defacement was likely an attempt by Rey to pin the hack on the Dutchman.
In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation.
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.
"It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday.
Exclusive, breaking: Dutch Police Arrest "Reformed" Hacker i....
Exclusive, breaking: Dutch Police Arrest "Reformed" Hacker in ShinyHunters investigation
Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters.
In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
Ravie Lakshmanan
Sep 29, 2026
United States
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.
"This was all a marketing campaign to protect our business and actively combat disinformation," a ShinyHunters representative
told
404 Media.
"
The development comes as ShinyHunters claimed credit for its
brazen hack
of the U.S. Federal Bureau of Investigation's (FBI) job application site apply.fbijobs.gov, stealing terabytes of sensitive data.
"
Although the group said it exploited a new zero-day flaw in Oracle PeopleSoft to gain unauthorized access and siphon the data, it's now assessed that ShinyHunters
employed
a URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate CVE-2026-35273.
"It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies
said
in an X post Monday.
"
When ShinyHunters was contacted by The Hacker News about the arrest, the group denied having any connection with van der Stap.
They want to seem like they are ahead of the FBI in investigating ShinyHunters.
(The story was updated after publication to include a response from ShinyHunters.)
In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the
FBI
and extorting the Russian ransomware group
Cl0p
.
“The Dutch police will need all the luck in the world – and everyone’s prayers – if they want to catch him before we carry out another large-scale data theft in the Netherlands,” the ShinyHunters statement said.
Multiple sources close to the ShinyHunters investigation said the group’s recent risky attacks against the FBI and one of Russia’s most venerated ransomware groups amounted to a major pivot away from the more measured tenor of the hacking gang’s operations.
Those sources said the sudden shift came about after ShinyHunters was taken over by
a teenage cybercriminal from Amman, Jordan
who goes by the nickname
Rey
and operates as part of a cybercrime group called
ScatteredLapsussHunters
(SLSH), which experts say is an amalgamation of three hacking groups —
Scattered Spider
,
LAPSUS$
and
ShinyHunters
.
According to
a story in Wired
this month, ShinyHunters and SLSH members briefly partnered earlier this year to help better monetize important stolen credentials collected by
TeamPCP
, an upstart group that was having great success compromising global code supply chains with malicious software but hadn’t been able to profit much from their stolen data (two alleged leaders of TeamPCP
were arre…
Responding to Dutch news media, ShinyHunters confirmed that the suspect in the audio clip is indeed a member of the hacker collective.
Van der Stap’s former hacker alias Umbreon was hidden in plain sight throughout the imagery ShinyHunters used to spread news about the FBI hack: The defacement image that ShinyHunters left behind on the hacked FBI jobs site included an ASCII art design featuring the Pokemon character Umbreon.
The image appears identical to a defacement message ShinyHunters used in their
2020 hack
of the English-language cybercrime community Hackforums.
The defacement message left by ShinyHunters on the FBI jobs site included an ASCII art rendition of the Pokemon character Umbreon.
Mandiant researcher
Austin Larsen
told KrebsOnSecurity earlier this month that ShinyHunters has been enjoying a successful extortion spree so far this year, and is on track to pull in nearly $100 million in extortion payments from cybercrime victims in 2026.
Useless.”
FBI, CL0P HACKS
Just days after sources say Van der Stap was detained by Dutch authorities, ShinyHunters claimed credit for an unusually brazen breach at the FBI’s job application site apply.fbijobs.gov.
ShinyHunters said it gained access to the FBI site and other victims by exploiting a recently patched vulnerability (CVE-2026-35273) in
PeopleSoft
, a software-as-a-service platform from the software giant
Oracle
that is broadly used by companies to manage hiring and human resources, benefits and payroll.
In that intrusion, ShinyHunters tricked an Odido employee into logging in at a spoofed website, and then used that access to steal data on more than 6.2 million Dutch people.
We do not look down on our staff and members; we take excellent care of them,” reads a statement ShinyHunters shared with
NL Times
.
Reuters examined documents shared by ShinyHunters and found they included sensitive psychiatric and medical files of FBI staff.
Oracle quickly issued a fix for the Peoplesoft vulnerability that ShinyHunters reportedly began exploiting as a zero-day in June, and at the time Mandiant released web application firewall rules intended for organizations who couldn’t apply the security update quickly enough.
But on Friday, BleepingComputer reported that ShinyHunters
used a URL-encoding trick
to bypass Mandiant’s suggested web application firewall rules designed to mitigate the threat from the PeopleSoft flaw.
The message at the top read, “This site has been seized by ShinyHunters.
Where does the bad blood between SLSH and ShinyHunters come from?
Wired’s
Andy Greenberg
reported that a few weeks after partnering with TeamPCP, “ShinyHunters went rogue, carrying out its own extortions with TeamPCP’s credentials but without giving the supply-chain hackers their cut.”
DIVD has released few details about that incident, but a spokesperson for the nonprofit told KrebsOnSecurity it does not appear related to ShinyHunters, nor are there any signs the matter involves the work of a previous volunteer.
Update, 4:54 p.m. ET:
The Dutch police have confirmed the arrest of a 24-year-old in connection with the ShinyHunters investigation.
“[ShinyHunters] has a well-established pattern of data theft extortion, that is, stealing data and threatening to release it on a data leak site unless the victim pays a ransom,” Mandiant said.
ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns.
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.
In its
blog
on Friday, Mandiant warned that ShinyHunters had restarted its exploitation of the bug and “adapted to published defensive guidance, targeting organizations that implemented [workarounds] but did not patch the vulnerability.”
On its website and in
interviews
with news outlets, ShinyHunters claimed it breached the FBI through a vulnerability in Oracle PeopleSoft — setting off a scramble to determine if the group found a new bug in the software or if it was exploiting a past issue.
ShinyHunters has claimed dozens of high-profile attacks in recent months and has been in the crosshairs of the FBI for nearly a year after dozens of attacks on large companies like
Ticketmaster
and
AT&T
as well as educational publisher
McGraw Hill
,
Carnival Cruise Line
,
7-Eleven
and
other
companies
.
On Monday, Dutch police
said
they arrested a 24-year-old suspected member of ShinyHunters from Amsterdam.
The ShinyHunters-linked activity involves the weaponization of
CVE-2026-35273
(CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution.
"We want to reiterate and emphasise that we are NOT extorting the FBI," a ShinyHunters spokesperson told The Hacker News.
In a separate statement shared with The Register, the group
said
they
started off
as
GnosticPlayers
before rebranding to ShinyHunters in 2020.
Google also reported that same day that ShinyHunters, whom they track as UNC6240, was exploiting the CVE-2026-35273 flaw in attacks on the education sector, confirming BleepingComputer's reporting.
On compromised Windows servers, ShinyHunters used these shells to deploy an executable named 'Ple64.exe', which masquerades as a signed Light Alloy media player installer but installs a backdoor tracked by Google as SIDEEYE.
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
Mandiant also observed ShinyHunters using the legitimate MeshAgent remote management software to maintain access to compromised Linux systems.
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks.
However, in a
new report
, Google says ShinyHunters has now modified its exploit to bypass WAF rules that look for this literal path, rather than encoded versions of it.
PSEMHUB WAF bypass
Source: Mandiant
Google warns ShinyHunters may not always use the '%50' bypass variation, and could switch to other percent-encoded, mixed-case, or other variations of '/PSEMHUB/' to bypass WAFs.
On vulnerable systems, these requests return information about the host operating system without writing files or disrupting the service, allowing ShinyHunters to determine whether a server can be exploited quietly.
ShinyHunters previously claimed a new PeopleSoft zero-day
These new attacks come after
ShinyHunters claimed that they breached FBI systems
using what they described as a new Oracle PeopleSoft zero-day vulnerability.
ShinyHunters has confirmed to BleepingComputer that they used this WAF bypass against FBI Jobs, but continue to claim that they also exploited "NEW unknown vulnerability in the same PSEMHUB component.
Google and Mandiant later linked exploitation of that flaw to ShinyHunters activity targeting organizations, particularly in the education sector.
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack.
The popular cybercrime group ShinyHunters
is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants.
The agency has not confirmed that its internal systems were compromised or that ShinyHunters obtained the data it claims to possess.
ShinyHunters has provided a possible technical explanation for the alleged intrusion.
The claim is notable because ShinyHunters has already been linked to attacks exploiting a real PeopleSoft zero-day earlier this year.
There is also a clear motive behind the operation claimed by ShinyHunters.
ShinyHunters disputes the FBI’s characterization of its activities and is reportedly demanding that the Bureau retract or correct the warning.
ShinyHunters has recently claimed responsibility for several major breaches and has been involved in a public dispute with the
Clop cybercrime operation
.
Until investigators confirm the intrusion, the extent of access and the origin of the leaked records, the ShinyHunters account should remain a claim rather than an established FBI breach.
Ravie Lakshmanan
Sep 23, 2026
Data Breach / Cybercrime
The cyber extortion group known as
ShinyHunters
on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.
"
A ShinyHunters spokesperson told The Register that the group exploited a new Oracle PeopleSoft zero-day vulnerability to gain remote code execution and deface the FBI's jobs site with a "This site has been seized by ShinyHunters" banner.
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants.
Kindly excuse our unprofessionalism."
"ShinyHunters; claim of an FBI breach is an unusually provocative move in the ongoing contest between law enforcement and cybercrime groups and should absolutely be taken seriously," Etay Maor, VP of threat intelligence at Cato Networks, said.
"
Maor also described ShinyHunters as a resilient criminal brand that has managed to outlast takedowns, arrests, and forum seizures by evolving its methods and attracting new operators, suggesting it's more than a "fixed set of people or infrastructure.
organisation
Oracle PeopleSoft
"
Although the group said it exploited a new zero-day flaw in Oracle PeopleSoft to gain unauthorized access and siphon the data, it's now assessed that ShinyHunters
employed
a URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate CVE-2026-35273.
ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns.
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks.
Ravie Lakshmanan
Sep 26, 2026
Vulnerability / Web Security
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.
organisation
CVE-2026
"
Although the group said it exploited a new zero-day flaw in Oracle PeopleSoft to gain unauthorized access and siphon the data, it's now assessed that ShinyHunters
employed
a URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate CVE-2026-35273.
The Google-owned security firm Mandiant published a blog on Friday about CVE-2026-35273 — a vulnerability disclosed in June that impacts Oracle’s PeopleSoft.
organisation
The Hacker News
"
When ShinyHunters was contacted by The Hacker News about the arrest, the group denied having any connection with van der Stap.
threat_actor
Scattered Spider
Those sources said the sudden shift came about after ShinyHunters was taken over by
a teenage cybercriminal from Amman, Jordan
who goes by the nickname
Rey
and operates as part of a cybercrime group called
ScatteredLapsussHunters
(SLSH), which experts say is an amalgamation of three hacking groups —
Scattered Spider
,
LAPSUS$
and
ShinyHunters
.
threat_actor
LAPSUS$
Those sources said the sudden shift came about after ShinyHunters was taken over by
a teenage cybercriminal from Amman, Jordan
who goes by the nickname
Rey
and operates as part of a cybercrime group called
ScatteredLapsussHunters
(SLSH), which experts say is an amalgamation of three hacking groups —
Scattered Spider
,
LAPSUS$
and
ShinyHunters
.
organisation
Wired
According to
a story in Wired
this month, ShinyHunters and SLSH members briefly partnered earlier this year to help better monetize important stolen credentials collected by
TeamPCP
, an upstart group that was having great success compromising global code supply chains with malicious software but hadn’t been able to profit much from their stolen data (two alleged leaders of TeamPCP
were arre…
threat_actor
TeamPCP
According to
a story in Wired
this month, ShinyHunters and SLSH members briefly partnered earlier this year to help better monetize important stolen credentials collected by
TeamPCP
, an upstart group that was having great success compromising global code supply chains with malicious software but hadn’t been able to profit much from their stolen data (two alleged leaders of TeamPCP
were arre…
Wired’s
Andy Greenberg
reported that a few weeks after partnering with TeamPCP, “ShinyHunters went rogue, carrying out its own extortions with TeamPCP’s credentials but without giving the supply-chain hackers their cut.”
The Wired story noted how Mandiant had infiltrated TeamPCP and was secretly responsible for having the crime group’s stolen credentials burned so quickly: Mandiant was secretly feeding those credentials to the major cloud providers like Amazon and Microsoft, who quickly invalidated the stolen keys.
financial
$100 track
Mandiant researcher
Austin Larsen
told KrebsOnSecurity earlier this month that ShinyHunters has been enjoying a successful extortion spree so far this year, and is on track to pull in nearly $100 million in extortion payments from cybercrime victims in 2026.
organisation
Odido
In that intrusion, ShinyHunters tricked an Odido employee into logging in at a spoofed website, and then used that access to steal data on more than 6.2 million Dutch people.
organisation
NL Times
We do not look down on our staff and members; we take excellent care of them,” reads a statement ShinyHunters shared with
NL Times
.
organisation
Peoplesoft
Oracle quickly issued a fix for the Peoplesoft vulnerability that ShinyHunters reportedly began exploiting as a zero-day in June, and at the time Mandiant released web application firewall rules intended for organizations who couldn’t apply the security update quickly enough.
But on Friday, BleepingComputer reported that ShinyHunters
used a URL-encoding trick
to bypass Mandiant’s suggested web application firewall rules designed to mitigate the threat from the PeopleSoft flaw.
The Google-owned security firm Mandiant published a blog on Friday about CVE-2026-35273 — a vulnerability disclosed in June that impacts Oracle’s PeopleSoft.
The next day,
Oracle fixed the PeopleSoft zero-day
as CVE-2026-35273, stating that it allows unauthenticated remote code execution.
The vulnerability was
first exploited
as a zero-day in attacks against academic institutions to conduct reconnaissance, deploy remote access software like MeshCentral agent for persistence, move laterally over SSH, run a shell script to connect via SSH to other internal PeopleSoft machines using known username/password combinations, and steal data.
There are currently no details of a PeopleSoft pre-authenticated RCE zero-day.
organisation
Mandiant
Oracle quickly issued a fix for the Peoplesoft vulnerability that ShinyHunters reportedly began exploiting as a zero-day in June, and at the time Mandiant released web application firewall rules intended for organizations who couldn’t apply the security update quickly enough.
Google and Mandiant later linked exploitation of that flaw to ShinyHunters activity targeting organizations, particularly in the education sector.
At that time, Google-owned Mandiant said it initiated notifications to over 100 global organizations whose IP addresses matched vulnerable endpoints, most of them located in the U.S.
"This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint," Mandiant
said
.
At the time, Mandiant advised organizations that could not immediately install the security updates or disable the Environment Management Hub to block external access to the vulnerable `/PSEMHUB/*` endpoint.
organisation
BleepingComputer
But on Friday, BleepingComputer reported that ShinyHunters
used a URL-encoding trick
to bypass Mandiant’s suggested web application firewall rules designed to mitigate the threat from the PeopleSoft flaw.
organisation
Wired’s
Wired’s
Andy Greenberg
reported that a few weeks after partnering with TeamPCP, “ShinyHunters went rogue, carrying out its own extortions with TeamPCP’s credentials but without giving the supply-chain hackers their cut.”
organisation
The Register
In a separate statement shared with The Register, the group
said
they
started off
as
GnosticPlayers
before rebranding to ShinyHunters in 2020.
organisation
GnosticPlayers
In a separate statement shared with The Register, the group
said
they
started off
as
GnosticPlayers
before rebranding to ShinyHunters in 2020.
organisation
Google
Google also reported that same day that ShinyHunters, whom they track as UNC6240, was exploiting the CVE-2026-35273 flaw in attacks on the education sector, confirming BleepingComputer's reporting.
Google and Mandiant later linked exploitation of that flaw to ShinyHunters activity targeting organizations, particularly in the education sector.
The Google-owned security firm Mandiant published a blog on Friday about CVE-2026-35273 — a vulnerability disclosed in June that impacts Oracle’s PeopleSoft.
Ravie Lakshmanan
Sep 26, 2026
Vulnerability / Web Security
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.
infrastructure
Windows
On compromised Windows servers, ShinyHunters used these shells to deploy an executable named 'Ple64.exe', which masquerades as a signed Light Alloy media player installer but installs a backdoor tracked by Google as SIDEEYE.
infrastructure
Linux
Mandiant also observed ShinyHunters using the legitimate MeshAgent remote management software to maintain access to compromised Linux systems.
"To establish persistent access after web shell placement on Linux systems, UNC6240 deployed the legitimate RMM tool MeshAgent.
organisation
MeshAgent
Mandiant also observed ShinyHunters using the legitimate MeshAgent remote management software to maintain access to compromised Linux systems.
"To establish persistent access after web shell placement on Linux systems, UNC6240 deployed the legitimate RMM tool MeshAgent.
organisation
Data Breach / Cybercrime
Ravie Lakshmanan
Sep 23, 2026
Data Breach / Cybercrime
The cyber extortion group known as
ShinyHunters
on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.
organisation
the U.S. Federal Bureau of Investigation
Ravie Lakshmanan
Sep 23, 2026
Data Breach / Cybercrime
The cyber extortion group known as
ShinyHunters
on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.
data_breach
2 TB
The group claimed it stole between 2TB and 3TB of data related to current and former FBI employees, job applicants, and other internal systems.
They allegedly said that between 2 TB and 3 TB of data had been taken and that the FBI jobs infrastructure had been compromised.
data_breach
3 TB
The group claimed it stole between 2TB and 3TB of data related to current and former FBI employees, job applicants, and other internal systems.
They allegedly said that between 2 TB and 3 TB of data had been taken and that the FBI jobs infrastructure had been compromised.
organisation
Van der Stap
Van der Stap confessed to his data theft and extortion activity, and was sentenced to four years in prison (one of which was suspended).
organisation
Neo Security
Van der Stap is currently employed as offensive security lead at the Dutch company
Neo Security
, which did not respond to requests for comment.
organisation
Reuters
Reuters and other media outlets confirmed the recruitment website did experience disruption around the time of the claim.
organisation
Oracle’s
The Google-owned security firm Mandiant published a blog on Friday about CVE-2026-35273 — a vulnerability disclosed in June that impacts Oracle’s PeopleSoft.
organisation
CVE-2026-35273
The next day,
Oracle fixed the PeopleSoft zero-day
as CVE-2026-35273, stating that it allows unauthenticated remote code execution.
organisation
DataBreaches
Although law enforcement officials did not disclose any additional details, independent security journalist
Brian Krebs
and
DataBreaches.
organisation
Pepijn
Net
identified the arrested man as Pepijn van der Stap (aka Umbreon), who was
previously apprehended
in 2023 for his role in a series of data thefts and extortions.
The LinkedIn profile for Pepijn van der Stap.
organisation
LinkedIn
The LinkedIn profile for Pepijn van der Stap.
organisation
the Dutch company Neo Security
"
He is presently employed as the offensive security lead at the Dutch company Neo Security, according to LinkedIn.
organisation
Amazon
The Wired story noted how Mandiant had infiltrated TeamPCP and was secretly responsible for having the crime group’s stolen credentials burned so quickly: Mandiant was secretly feeding those credentials to the major cloud providers like Amazon and Microsoft, who quickly invalidated the stolen keys.
organisation
Microsoft
The Wired story noted how Mandiant had infiltrated TeamPCP and was secretly responsible for having the crime group’s stolen credentials burned so quickly: Mandiant was secretly feeding those credentials to the major cloud providers like Amazon and Microsoft, who quickly invalidated the stolen keys.
financial
$20,000 leader
According to
a story in Wired
this month, ShinyHunters and SLSH members briefly partnered earlier this year to help better monetize important stolen credentials collected by
TeamPCP
, an upstart group that was having great success compromising global code supply chains with malicious software but hadn’t been able to profit much from their stolen data (two alleged leaders of TeamPCP
were arres…
financial
€1.5 prosecutors
Van der Stap was previously convicted in 2023 in connection with a string of data thefts and extortions that prosecutors said earned between €1.5 million and €2.7 million.
organisation
MeshCentral
The vulnerability was
first exploited
as a zero-day in attacks against academic institutions to conduct reconnaissance, deploy remote access software like MeshCentral agent for persistence, move laterally over SSH, run a shell script to connect via SSH to other internal PeopleSoft machines using known username/password combinations, and steal data.
organisation
SSH
The vulnerability was
first exploited
as a zero-day in attacks against academic institutions to conduct reconnaissance, deploy remote access software like MeshCentral agent for persistence, move laterally over SSH, run a shell script to connect via SSH to other internal PeopleSoft machines using known username/password combinations, and steal data.
organisation
IP
At that time, Google-owned Mandiant said it initiated notifications to over 100 global organizations whose IP addresses matched vulnerable endpoints, most of them located in the U.S.
"This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint," Mandiant
said
.
victims
100 global organizations
At that time, Google-owned Mandiant said it initiated notifications to over 100 global organizations whose IP addresses matched vulnerable endpoints, most of them located in the U.S.
"This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint," Mandiant
said
.
organisation
the Environment Management Hub
At the time, Mandiant advised organizations that could not immediately install the security updates or disable the Environment Management Hub to block external access to the vulnerable `/PSEMHUB/*` endpoint.
organisation
JSP
Drop two JSP web shells in the PSEMHUB.war directory with an aim to minimize WAF detections during post-exploitation: "x.jsp" enables cross-platform command execution, while "u.jsp" allows chunked file uploads to the server and command execution via "cmd.exe.
Once they determine a system is vulnerable, the threat actors exploit the flaw again to execute commands directly in memory or deploy JSP web shells.
organisation
TCP
"
Use "u.jsp" to upload a valid, signed trojanized installer ("Ple64.exe") that loads in memory SIDEEYE, a C++ backdoor that communicates with an external server ("162.219.30[.]165") over TCP to facilitate browser and desktop application credential theft, process and file management, interactive reverse shell and reverse proxy capabilities.
organisation
RMM
"To establish persistent access after web shell placement on Linux systems, UNC6240 deployed the legitimate RMM tool MeshAgent.
organisation
POST
The entire attack chain is as follows -
Identify susceptible targets by sending POST requests to "/%50SEMHUB/hub" containing a serialized Java object.
Before attempting exploitation, the attackers typically send between five and 15 POST requests to `/%50SEMHUB/hub` containing serialized Java objects.
organisation
WebLogic
The remaining commands have been found to be run under PeopleSoft or WebLogic service accounts.
Organizations are also advised to search WebLogic access logs for requests to '/PSEMHUB/' and encoded variants such as '/%50SEMHUB/' to detect signs of exploitation.
organisation
Disable the Environment Management Hub
Disable the Environment Management Hub (EMHub) service in multi-server configurations, or, remove the PSEMHUB application entirely in single-server configurations.
organisation
Rotate
Rotate credentials readable by the PeopleSoft application service account.
organisation
Oracle WebLogic
Oracle WebLogic, on the other hand, decodes the encoded 'P' and routes the request to the vulnerable endpoint, bypassing the WAF rule.
organisation
HTTPS
This toolkit allows SOCKS5 proxy traffic to be tunneled over normal HTTP and HTTPS connections, letting the compromised PeopleSoft server be used to spread laterally into the internal network.
organisation
NFL
"
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
"
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
OAuth
"
"Its recent playbook has emphasized abusing trusted identity paths through help-desk social engineering, malicious OAuth applications, and stolen SaaS integration tokens, rather than simply breaking through a technical perimeter.
organisation
Social Security
The group reportedly offered a sample of around 5,000 records as evidence and claimed that the stolen information could include names, addresses, phone numbers, Social Security numbers, assignments and, in some cases, family details.
data_breach
5,000 records
The group reportedly offered a sample of around 5,000 records as evidence and claimed that the stolen information could include names, addresses, phone numbers, Social Security numbers, assignments and, in some cases, family details.
organisation
the white board
Get your bosses in front of the white board in the war room.
organisation
Clock
Clock is ticking moron.
September 29, 2026
A suspect in the ShinyHunters group is scheduled to appear before the Rotterdam District Court on September 29, 2026.
Click on any entity below to view its context and source!
attribution
the Rotterdam District Court
Police said the individual is expected to appear before the Rotterdam District Court on September 29, 2026.
Sep 29, 2026
Threat actors exploited a previously unknown vulnerability in Oracle PeopleSoft to gain unauthorized access.
Tuesday, September 29
The Dutch police announced that a suspect in the ShinyHunters Oracle PeopleSoft bug case will appear before the Rotterdam District Court on Tuesday, September 29.
Click on any entity below to view its context and source!
target_region
Netherlands
In
a statement on Twitter/X
, the Dutch police said the man will appear on Tuesday, September 29 before the chambers of the Rotterdam District Court, and that it will provide more information tomorrow.
attribution
the Rotterdam District Court
In
a statement on Twitter/X
, the Dutch police said the man will appear on Tuesday, September 29 before the chambers of the Rotterdam District Court, and that it will provide more information tomorrow.
Tactical Metrics
Metrics
financial
20,000
Leader
Click for context!
According to
a story in Wired
this month, ShinyHunters and SLSH members briefly partnered earlier this year to help better monetize important stolen credentials collected by
TeamPCP
, an upstart group that was having great success compromising global code supply chains with malicious software but hadn’t been able to profit much from their stolen data (two alleged leaders of TeamPCP
were arres…
Metrics
financial
100,000,000
Track
Mandiant researcher
Austin Larsen
told KrebsOnSecurity earlier this month that ShinyHunters has been enjoying a successful extortion spree so far this year, and is on track to pull in nearly $100 million in extortion payments from cybercrime victims in 2026.
Metrics
financial
1,500,000
Prosecutors
Van der Stap was previously convicted in 2023 in connection with a string of data thefts and extortions that prosecutors said earned between €1.5 million and €2.7 million.
Metrics
infrastructure
Linux
Affected Product
"To establish persistent access after web shell placement on Linux systems, UNC6240 deployed the legitimate RMM tool MeshAgent.
Mandiant also observed ShinyHunters using the legitimate MeshAgent remote management software to maintain access to compromised Linux systems.
Metrics
victims
100
Global Organizations
At that time, Google-owned Mandiant said it initiated notifications to over 100 global organizations whose IP addresses matched vulnerable endpoints, most of them located in the U.S.
"This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint," Mandiant
said
.
On June 10,
BleepingComputer first reported
that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.
Metrics
data_breach
2
Tb
The disclosure comes as the ShinyHunters group
broke
into the U.S. Federal Bureau of Investigation's FBIJobs.gov portal (which
remains inaccessible
as of writing) and stole about 2-3 TB of sensitive data to contest allegations made by the agency against the group in a May 2026 alert.
The group claimed it stole between 2TB and 3TB of data related to current and former FBI employees, job applicants, and other internal systems.
They allegedly said that between 2 TB and 3 TB of data had been taken and that the FBI jobs infrastructure had been compromised.
Metrics
infrastructure
Windows
Affected Product
On compromised Windows servers, ShinyHunters used these shells to deploy an executable named 'Ple64.exe', which masquerades as a signed Light Alloy media player installer but installs a backdoor tracked by Google as SIDEEYE.
Metrics
data_breach
3
Tb
The group claimed it stole between 2TB and 3TB of data related to current and former FBI employees, job applicants, and other internal systems.
They allegedly said that between 2 TB and 3 TB of data had been taken and that the FBI jobs infrastructure had been compromised.
Metrics
data_breach
5,000
Records
The group reportedly offered a sample of around 5,000 records as evidence and claimed that the stolen information could include names, addresses, phone numbers, Social Security numbers, assignments and, in some cases, family details.
Metrics
data_breach
23
September
"
"One small operational clue is the September 23 timestamp on the group's post, while the news emerged on September 22 in the U.S.
Intelligence Sources
The Hacker News
2026-09-29
The Hacker News
2026-09-26
BleepingComputer
2026-09-26
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
BleepingComputer
The Hacker News
2026-09-23
Krebs On Security
2026-09-28
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Krebs On Security
TheRecord
2026-09-28
Security Affairs
2026-09-23
AlienVault OTX
2026-09-28
AlienVault OTX
2026-09-29
Mastodon BrianKrebs
2026-09-28
Exclusive, breaking: Dutch Police Arrest "Reformed" Hacker i...
Mastodon BrianKrebs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T10:46
Comprehensive Tactical Telemetry
Highly Correlated Entities
51x
organisation
Identified Entity
Oracle PeopleSoft
entity
40x
attribution
Attributing Entity
FBI
authority
33x
timeline
Temporal Reference
23-year-old
date
9x
tactic
Cyber Operation Type
Ransomware
tactic
8x
industry
Targeted Sector
Media
sector
4x
source region
Origin Country
Netherlands
country
4x
threat actor
APT Group
ShinyHunters
actor
4x
target region
Target Country
Netherlands
country
2x
general metric
Sep
29
sep
2x
malware
Malware Payload
Umbreon
tool
2x
infrastructure
Affected Product
Linux
software
2x
data breach
Tb
2
tb
2x
general metric
%
50
%
Contextual Telemetry
Context Block
19 METRICS
general metric
Media
404
media
vulnerability
Exploited CVE
CVE-2026-35273
cve
general metric
People
2,300,000
people
financial
Leader
20,000
leader
general metric
Officials
5,000
officials
general metric
Hack
2,020
hack
financial
Track
100,000,000
track
financial
Prosecutors
1,500,000
prosecutors
general metric
Dutch People
6,200,000
dutch people
general metric
May
27
may
general metric
Eleven
7
eleven
general metric
Score
10
score
victims
Global Organizations
100
global organizations
general metric
Cve-2026
35,273
cve-2026
data breach
Records
5,000
records
general metric
District
4
district
general metric
Instances
10
instances
general metric
Sep
23
sep
data breach
September
23
september
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.