Overview of the Dutch Police Arrest
Authorities in the Netherlands arrested a 24-year-old convicted cybercriminal on suspicion of aiding data thefts and extortions orchestrated by the prolific hacker collective ShinyHunters. According to multiple sources familiar with the investigation, the detained individual is Pepijn van der Stap, a resident of Almere and Lelystad who was previously convicted in 2023 for cybercrimes associated with RaidForums and Breached under the handle “Umbreon.”
Despite a prior conviction and a subsequent prison sentence, van der Stap had recently worked in offensive security roles for regional startups. Following his detention in mid-September, the ShinyHunters syndicate mobilized swiftly, confirming full emotional and financial support for their detained associate while openly taunting Dutch law enforcement.
Retaliatory Attacks and PeopleSoft Exploitation
In the immediate wake of the arrest, the threat actor group escalated operations with a series of brazen data thefts. Most notably, the collective claimed credit for breaching the FBI’s job application portal at apply.fbijobs.gov. According to security reporting, the incident exposed sensitive records—including Social Security numbers, internal team assignments, and psychiatric files—belonging to over 5,000 personnel.
Security analysis indicates that the campaign relied heavily on weaponising CVE-2026-35273, a security flaw affecting Oracle PeopleSoft. Threat intelligence teams noted that the collective utilized this vulnerability as a zero-day vector before Oracle issued formal patches and mitigation guidance.
Impact on Telecommunications and Extortion Operations
Prior to the FBI incident, the same network of actors successfully compromised Odido, the largest mobile telecommunications provider in the Netherlands, using sophisticated social engineering techniques over telephone lines to siphon records belonging to approximately 6.2 million Dutch citizens. Furthermore, the group turned its sights inward within the cybercrime ecosystem, launching extortion demands against the Cl0p ransomware operation.
Mitigation and Recommendations
Defenders managing enterprise human resources platforms must prioritize immediate remediation steps to counter ongoing exploitation waves associated with these campaigns:
- Apply official vendor patches for CVE-2026-35273 across all Oracle PeopleSoft installations immediately.
- Deploy web application firewall (WAF) rules designed to detect and block abnormal application-layer requests targeting recruitment and portal endpoints.
- Conduct thorough log analysis for unusual administrative authentications, particularly involving external recruitment portals and legacy HR workflows.
Related: CVE-2026-21962: Oracle WebLogic RCE Under Active Attack, Mount Royal University Data Breach: Ransomware Impact & Mitigation