Full Report
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the
Analysis Summary
# Threat Actor: ShinyHunters (and associate "Umbreon")
## Attribution & Identity
* **Identified Individual:** Pepijn van der Stap, a 24-year-old Amsterdam resident arrested in September 2026.
* **Aliases:** Umbreon.
* **Known Associations:**
* **ShinyHunters:** A high-profile cybercriminal group known for large-scale data breaches.
* **Professional Background:** Van der Stap previously worked for the cybersecurity firm **Hadrian**, volunteered for the **Dutch Institute for Vulnerability Disclosure (DIVD)**, and most recently served as the offensive security lead at **Neo Security**.
* **Legal History:** Previously apprehended in 2023 for data theft and extortion; was on probation at the time of the 2026 arrest.
## Activity Summary
* **FBI Job Portal Breach (2026):** ShinyHunters claimed responsibility for breaching `apply.fbijobs[.]gov`, allegedly stealing terabytes of sensitive data including employee information.
* **Historical Campaigns:** The group has a long history of data theft, database leaks, and extortion against numerous global corporations.
## Tactics, Techniques & Procedures
* **WAF Bypass:** Utilized a URL-encoding trick to bypass Web Application Firewall (WAF) rules designed to block exploits.
* **Vulnerability Exploitation:**
* **CVE-2026-35273:** Exploited this specific vulnerability in Oracle PeopleSoft.
* **Zero-Day Claims:** The group frequently claims the use of zero-day vulnerabilities (e.g., in Oracle PeopleSoft) to bolster their reputation.
* **Data Exfiltration:** Siphoning large volumes (terabytes) of sensitive data for leak or leverage.
* **Psychological Operations:** Use of high-profile breaches as "marketing campaigns" to combat perceived disinformation and gain widespread attention.
## Targeting
* **Sectors:** Government, Cybersecurity, Technology, and general corporate sectors.
* **Geography:** Global; specifically the United States (FBI) and the Netherlands (based on actor residency).
* **Victims:**
* U.S. Federal Bureau of Investigation (FBI).
* Historically, a wide range of private companies (implied by "history in past operations").
## Tools & Infrastructure
* **Software:** Oracle PeopleSoft (Targeted application).
* **Techniques:** URL-encoding obfuscation.
* **Domains:** `apply.fbijobs[.]gov` (Victim infrastructure).
## Implications
* **Strategic Threat:** The actor demonstrates a high level of technical proficiency, including the ability to bypass modern security controls (WAFs).
* **Insider/Recidivism Risk:** The arrest of an individual working in offensive security roles highlights a significant "poacher turned gamekeeper" risk, where individuals utilize professional defensive knowledge to facilitate criminal activity.
* **Shift in Motivation:** While historically financially motivated (extortion), the group now claims to engage in "ideological" or "marketing" breaches to gain influence, making their behavior less predictable.
## Mitigations
* **Patch Management:** Immediate patching of Oracle PeopleSoft vulnerabilities, specifically CVE-2026-35273.
* **Advanced WAF Configuration:** Ensure WAFs are configured to inspect and normalize encoded URLs to prevent encoding-based bypasses.
* **Personnel Security:** Enhanced vetting for individuals in "Offensive Security" or sensitive vulnerability research roles, particularly those with a history of involvement in underground forums.
* **Identity Governance:** Implement runtime identity controls and strict IAM policies to limit the blast radius if an application is compromised.