Dutch police arrested 23-year-old convicted cybercriminal Pepijn van der Stap, known as Umbreon, on suspicion of supporting ShinyHunters-linked data theft and extortion. The investigation follows a February social-engineering intrusion at Dutch telecom provider Odido, where attackers allegedly stole data belonging to more than 6.2 million people. Reporting attributes parts of the operation to a Jordanian teenager known as Rey, associated with the ScatteredLapsussHunters collective, who may have taken control of the ShinyHunters brand and used Umbreon imagery in an FBI job-application-site defacement to implicate or taunt van der Stap amid an internal dispute.
Following the reported arrest, ShinyHunters claimed compromises of the FBI recruitment portal and the Clop ransomware group's Tor leak site. The Clop intrusion was attributed to unauthenticated Grav CMS path traversal vulnerability CVE-2026-42608 in an outdated Grav 1.7.43 deployment; ShinyHunters claimed to have taken source code, plugins, logs, and Tor onion-service private keys, prompting Clop to move its leak site. The group has also allegedly mass-exploited Oracle PeopleSoft flaw CVE-2026-35273 against dozens of organizations, according to Mandiant and Google Threat Intelligence Group. Organizations using Grav 1.7 should upgrade to the patched 1.7.53.4 release, while PeopleSoft operators should urgently assess exposure to the Oracle vulnerability and investigate for compromise.
See which actors are running it and whether you're in range.
12 events from the most recent confirmed update back to the earliest known activity.
Mandiant and Google Threat Intelligence Group reported that ShinyHunters had mass-exploited CVE-2026-35273 to steal data from dozens of organizations. Reported victims spanned education, technology, healthcare, agriculture, transportation, and government sectors.
Dutch authorities arrested van der Stap on suspicion of assisting ShinyHunters-linked data theft and extortion, and held him for questioning. At the time, he was reportedly employed as an offensive-security lead at Neo Security.
ShinyHunters breached Clop’s Tor data-leak site, first uploading a text file and later replacing it with an Umbreon-themed defacement. The group claimed to have stolen the site source code, Grav plugins, server logs, and Tor onion-service private keys, while Clop disputed that the server contained valuable operational or financial data.
ShinyHunters reportedly began exploiting CVE-2026-35273 in Oracle PeopleSoft as a zero-day. Oracle subsequently released a patch, while the group reportedly used URL encoding to bypass proposed Mandiant web-application-firewall mitigations.
Grav published an advisory for CVE-2026-42608, an unauthenticated path-traversal vulnerability in Grav core form-upload handling. The 2.x remediation added identifier validation through a sanitizeId() allowlist.
A Dutch-speaking ShinyHunters member allegedly directed an Odido employee to a spoofed website, obtained access, and stole data concerning more than 6.2 million people. Dutch police later sought help identifying the caller, and ShinyHunters confirmed the recorded caller was a group member.
Grav privately fixed CVE-2026-42608 in Grav 2.0.0-beta.2. The flaw allowed unauthenticated path traversal through form-upload handling and affected legacy Grav 1.7 deployments that had not received a backport.
Pepijn van der Stap was released from prison after serving part of his sentence for prior data theft and extortion activity.
Dutch cybercriminal Pepijn van der Stap, known online as “Umbreon,” was convicted of data theft and extortion offenses that prosecutors said generated €1.5 million to €2.7 million. He received a four-year prison sentence, with one year suspended.
Following the compromise and defacement of its prior server, Clop moved its leak site to a new Tor onion address. It said the old address would remain temporarily accessible before retirement.
Grav confirmed that ShinyHunters exploited CVE-2026-42608 against Clop’s outdated Grav 1.7.43 installation. After receiving exploitation details, Grav backported the fix to the legacy branch and released Grav 1.7.53.4, urging 1.7 users to upgrade.
Soon after van der Stap’s reported detention, ShinyHunters claimed it compromised the FBI job-application website, apply.fbijobs.gov; the FBI confirmed the site was hacked. Reporting said the exposed material included Social Security numbers and other personal information for more than 5,000 officials, including psychiatric and medical records.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalware.news
Open sourcekrebsonsecurity.com
Open sourcebleepingcomputer.com
Open sourcenltimes.nl
Open sourcepolitie.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.