# ShinyHunters Arrest and PeopleSoft Zero-Day Exploitation

> Dutch police arrest a reformed hacker linked to ShinyHunters, prompting retaliatory attacks involving Oracle PeopleSoft CVE-2026-35273.

- Published: 2026-10-01T03:08:38.000Z
- Severity: high
- Category: Threat Intel
- Tags: ShinyHunters, Oracle, Ransomware, PeopleSoft, CVE-2026-35273
- CVEs: CVE-2026-35273 (CVSS 0)
- Author: Runtime Rebel Intel
- Primary source: https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/
- Canonical: https://runtimerebel.com/blog/shinyhunters-arrest-and-peoplesoft-zero-day-exploitation

## Key points

- Immediate impact: The ShinyHunters syndicate retaliated against law enforcement by launching high-profile data thefts targeting the FBI and extorting the Cl0p ransomware group.
- Affected systems: Oracle PeopleSoft instances vulnerable to zero-day exploitation via CVE-2026-35273.
- Remediation: Ensure all Oracle PeopleSoft deployments are fully patched against CVE-2026-35273 and review perimeter logs for indicators of compromise.

## Overview of the Dutch Police Arrest

Authorities in the Netherlands arrested a 24-year-old convicted cybercriminal on suspicion of aiding data thefts and extortions orchestrated by the prolific hacker collective [ShinyHunters](https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/). According to multiple sources familiar with the investigation, the detained individual is Pepijn van der Stap, a resident of Almere and Lelystad who was previously convicted in 2023 for cybercrimes associated with RaidForums and Breached under the handle “Umbreon.” 

Despite a prior conviction and a subsequent prison sentence, van der Stap had recently worked in offensive security roles for regional startups. Following his detention in mid-September, the [ShinyHunters](https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/) syndicate mobilized swiftly, confirming full emotional and financial support for their detained associate while openly taunting Dutch law enforcement.

## Retaliatory Attacks and PeopleSoft Exploitation

In the immediate wake of the arrest, the [threat actor](/glossary#threat-actor) group escalated operations with a series of brazen data thefts. Most notably, the collective claimed credit for breaching the FBI’s job application portal at `apply.fbijobs.gov`. According to security reporting, the incident exposed sensitive records—including Social Security numbers, internal team assignments, and psychiatric files—belonging to over 5,000 personnel.

Security analysis indicates that the campaign relied heavily on weaponising [CVE-2026-35273](/cve/cve-2026-35273), a security flaw affecting Oracle PeopleSoft. [Threat intelligence](/glossary#threat-intelligence) teams noted that the collective utilized this [vulnerability](/glossary#vulnerability) as a [zero-day](/glossary#zero-day) vector before Oracle issued formal patches and mitigation guidance.

### Impact on Telecommunications and Extortion Operations

Prior to the FBI incident, the same network of actors successfully compromised Odido, the largest mobile telecommunications provider in the Netherlands, using sophisticated [social engineering](/glossary#social-engineering) techniques over telephone lines to siphon records belonging to approximately 6.2 million Dutch citizens. Furthermore, the group turned its sights inward within the cybercrime ecosystem, launching extortion demands against the Cl0p [ransomware](/glossary#ransomware) operation.

## Mitigation and Recommendations

Defenders managing enterprise human resources platforms must prioritize immediate remediation steps to counter ongoing exploitation waves associated with these campaigns:

* Apply official vendor patches for [CVE-2026-35273](https://nvd.nist.gov/vuln/detail/CVE-2026-35273) across all Oracle PeopleSoft installations immediately.
* Deploy web application [firewall](/glossary#firewall) ([WAF](/glossary#waf)) rules designed to detect and block abnormal application-layer requests targeting recruitment and portal endpoints.
* Conduct thorough log analysis for unusual administrative authentications, particularly involving external recruitment portals and legacy HR workflows.

**Related:** [CVE-2026-21962: Oracle WebLogic RCE Under Active Attack](/blog/cve-2026-21962-oracle-weblogic-rce-under-active-attack), [Mount Royal University Data Breach: Ransomware Impact & Mitigation](/blog/mount-royal-university-data-breach-ransomware-impact-mitigation)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/shinyhunters-arrest-and-peoplesoft-zero-day-exploitation
