Dutch authorities have arrested a 24-year-old man from Amsterdam, identified as Pepijn van der Stap, in connection with the notorious hacking group ShinyHunters. The arrest, confirmed by the Politie Landelijke Opsporing en Interventies, took place on September 15, 2026, and van der Stap is set to appear before the Rotterdam District Court today, September 29, 2026. This development highlights ongoing law enforcement efforts to combat cybercrime linked to high-profile data breaches.
While the investigation does not explicitly mention any direct impact on the UAE or broader Middle East region, the ShinyHunters group has been known for its extensive data breaches, which could have implications for organizations operating in or connected to the region. The group’s activities, including a recent breach of the FBI’s job application site, raise concerns about the security of sensitive data globally, including in the Gulf Cooperation Council (GCC) states.
- Van der Stap was previously arrested in 2023 for involvement in data thefts and extortion.
- He worked at cybersecurity firm Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD).
- ShinyHunters claimed responsibility for a significant hack of the FBI’s job application site, stealing terabytes of data.
- The group asserts that their actions were not financially motivated and were part of a marketing strategy.
- They reportedly exploited a zero-day vulnerability in Oracle PeopleSoft to access sensitive information.
The ShinyHunters group has claimed that their recent activities, including the breach of the FBI’s systems, were not intended as extortion but rather as a means to draw attention to their operations. They stated, “We do not care what the public says and we are not affected by it nor do we cloud our judgement by external opinions and thoughts.” This assertion raises questions about the motivations behind their cyber activities and the potential risks they pose to organizations worldwide.
In terms of technical context, the group reportedly exploited a new zero-day vulnerability in Oracle PeopleSoft, specifically CVE-2026-35273, to gain unauthorized access. They utilized a URL-encoding trick to bypass web application firewall (WAF) protections, indicating a sophisticated understanding of web security mechanisms. This incident underscores the importance of robust cybersecurity measures for organizations that may be vulnerable to similar tactics.
Organizations should assess their security posture, particularly those using Oracle PeopleSoft, and ensure that they are applying the latest patches and security updates. Monitoring for unusual activity and reinforcing web application firewalls can help mitigate risks associated with such vulnerabilities. It is crucial for cybersecurity teams to stay informed about emerging threats and to implement proactive measures to protect sensitive data.
Source and evidence
The information in this report is based on a publication by The Hacker News, detailing the arrest of Pepijn van der Stap and the activities of the ShinyHunters group, dated September 29, 2026. The report includes statements from law enforcement and the group itself, providing context to the ongoing investigation and the implications of their cyber activities.
CWME will continue tracking regional implications as more verified information becomes available.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.


