ShinyHunters member arrested by Dutch Police

Dutch police have arrested a 24-year-old Amsterdam man, believed to be Pepijn van der Stap, as part of the ShinyHunters investigation. Van der Stap was convicted in 2023 of multiple intrusions, data theft and extortion under the handle “Umbreon.” He was on supervised release at the time of the arrest and is reportedly working as an offensive security lead at Neo Security. According to Brian Krebs, the group’s current leader appears to have tied him to the recent FBI jobs portal hack, which used a modified Oracle PeopleSoft exploit and left an Umbreon image in the defacement.

Jason Brown, Director of Customer Advisory Counter Fraud Lead, iCOUNTER has this to say:

“An arrest is a disruption, not an ending. ShinyHunters operates like a brand, not a fixed crew. Handles change and members rotate, which is why its current leader is reportedly pinning the FBI hack on someone the group was previously associated with. Arrests like this matter. They create fear and distrust inside the group and give investigators leverage. But the people still operating won’t stop. They’ll adjust. Groups like this don’t win with new exploits alone. Their most damaging campaigns have come from going after the people inside vendors, help desks and SaaS providers who hold privileged access, then using that trust to reach dozens of downstream victims at once. That’s the real exposure for most organizations. The suspect in this case was reportedly working as an offensive security lead at a security company while on supervised release. Most organizations would never know that about a vendor’s staff. Managing third-party risk takes continuous visibility into which of your partners are being targeted, exposed or talked about by threat actors, not a one time questionnaire filed away at contract signing.”

Honestly, this means that we should see more ShinyHunters activity in the coming days. Which is bad news for all of us.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading