Source: The Hacker News
Author: info@thehackernews.com (The Hacker News)
URL: https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html
ONE SENTENCE SUMMARY:
Dutch police arrested alleged ShinyHunters member Pepijn van der Stap as group claims FBI jobs hack via WAF bypass recently.
MAIN POINTS:
- Authorities confirmed arrest of a 24-year-old Amsterdam man tied to ShinyHunters investigations.
- Police stated the suspect will appear at Rotterdam District Court on September 29, 2026.
- Journalists Brian Krebs and DataBreaches.Net identified him as Pepijn van der Stap “Umbreon.”
- Reports say the arrest occurred September 15, 2026, though officials withheld specifics.
- Earlier, he was apprehended in 2023 for data theft and extortion activities.
- Employment history included cybersecurity firm Hadrian and volunteering with the Dutch DIVD.
- Van der Stap described intense paranoia from maintaining appearances while balancing lawful and illegal work.
- LinkedIn lists him as offensive security lead at Dutch company Neo Security.
- ShinyHunters claimed responsibility for hacking apply.fbijobs.gov and stealing terabytes of sensitive data.
- Investigators now assess a URL-encoding WAF bypass for CVE-2026-35273, not an Oracle PeopleSoft zero-day.
TAKEAWAYS:
- Dual-role security professionals can present elevated insider-risk and vetting challenges.
- Criminal groups may stage high-profile breaches as “marketing” to shape narratives and attention.
- Treat announced “zero-days” skeptically until validated by technical evidence and independent assessment.
- Web application firewalls remain vulnerable to evasion techniques like encoding tricks and rule bypasses.
- Defensive teams should prioritize monitoring for large-scale exfiltration from public-facing recruitment portals.