
Dutch Police Arrest Suspect Linked to ShinyHunters Group
A 24-year-old Amsterdam man has been arrested in connection with the ShinyHunters hacking group, with a court appearance set for September 29.
Dutch police have arrested a 24-year-old man from Amsterdam in an ongoing investigation into the ShinyHunters hacking group, officials confirmed on Monday. The Politie Landelijke Opsporing en Interventies, the force's national investigation and intervention unit, stated on social media that the individual is expected to appear before the Rotterdam District Court on September 29, 2026. While authorities did not publicly name the suspect, independent security journalist Brian Krebs and the publication DataBreaches.Net identified him as Pepijn van der Stap, also known by the online alias Umbreon.
Van der Stap was previously apprehended in 2023 for his role in a series of data thefts and extortions. At that time, he worked at the cybersecurity company Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD), a well-known organisation that coordinates reporting of security flaws. In a 2023 conversation with DataBreaches.Net, he described how his legitimate security work heightened his fears of being caught. "Working at Hadrian and volunteering at DIVD made me more paranoid about keeping up appearances, and I actually felt more pressure and paranoia," he said. "The paranoia became so extreme that I was expecting a knock on the door at any time." Public records show van der Stap is now employed as the offensive security lead at Neo Security, a Dutch firm. On his LinkedIn profile, he wrote that his path "hasn't been a straight line" and that he had learned "hard lessons" from seeing security from different angles.
ShinyHunters, when reached by The Hacker News, denied any connection to the arrested man. "That individual has no association with us. Frankly, we are laughing," a representative for the group said. They accused the Dutch police of seeking publicity after what they called "the massive embarrassment in result of the Odido hack," and suggested the force wanted to appear ahead of the FBI in investigating the group. The denial comes as ShinyHunters has claimed responsibility for a high-profile breach of the FBI's recruitment website at apply.fbijobs.gov, where they say they stole terabytes of data.
In statements to 404 Media and The Hacker News, the group insisted that the FBI incident was not an extortion attempt and was not financially motivated. "This was all a marketing campaign to protect our business and actively combat disinformation," one spokesperson said. Another added, "We again want to emphasise that this is not extortion, it was never one to begin with, not a threat, not a ransom, and not financially motivated. Nothing will happen." The attack, according to the group, exploited a newly reported vulnerability — a weakness in a widely used enterprise application suite for human resources and job portals tracked as CVE-2026-35273. Rather than using a traditional exploit, security researchers now assess that ShinyHunters used a technique known as URL-encoding to bypass rules in the web application firewall, or WAF, that was supposed to block the flaw. A WAF is a security filter that sits in front of a web application and examines incoming traffic to stop malicious requests. By encoding the characters in the attack URL in a certain way, the group appears to have tricked the firewall into treating the request as harmless.
For website owners and administrators, the case illustrates how even a well-known vulnerability with a published patch can remain dangerous if protective layers like a WAF are not kept updated with the latest rule sets. A WAF is only as effective as the signatures and filters it uses, and attackers actively test methods to evade them. The same risk applies to any internet-facing application — forums, login pages, customer portals — that processes user-submitted information. For businesses that run their own web infrastructure, the incident highlights the importance of choosing a hosting environment where security updates and firewall rules are managed proactively by experts who track the evolving threat landscape.
For website owners, this case underscores why managed hosting platforms like AEU Hosting that maintain hardened web application firewall rules and proactively apply security patches are essential, helping to block the kind of URL-encoding tricks that let attackers slip past unprotected sites.
Si të Mbroheni
- Keep all your website software, especially any login or job application portals, updated automatically so security patches are applied as soon as they are released.
- Use a web application firewall (WAF) service for your site and ensure its rules are kept current to block known attack patterns.
- Monitor your website logs regularly for unusual URL patterns or access attempts that include encoded characters, which may indicate bypass attempts.
- Enforce multi-factor authentication on any user accounts that have administrative access to your hosting or site backend.
- If your site uses a third-party application like PeopleSoft, subscribe to vendor security alerts and apply patches immediately.
Dobësitë & Zgjidhjet
- CVE-2026-35273 A vulnerability in an enterprise human resources platform that ShinyHunters claimed to have exploited; the group used a URL-encoding trick to bypass web application firewall rules designed to stop it. Shiko zgjidhjen & detajet →
Termat e Shpjeguar
- ShinyHunters A hacking group known for breaching companies to steal data and, at times, attempting extortion.
- Web Application Firewall (WAF) A security system that monitors and filters the traffic between the internet and a web application to block attacks.
- CVE Common Vulnerabilities and Exposures, a public list that gives each known security flaw a unique number.
- URL-encoding A way of converting characters in a web address into a format that can be safely sent over the internet; attackers can misuse it to hide malicious commands.
- Zero-day A software vulnerability that is unknown to the vendor or has no official fix yet, leaving systems exposed.
- Offensive security The practice of testing an organisation's defences by actively trying to break into its systems, a legitimate job role often called penetration testing.