An arrest can establish that police have a suspect. It cannot, by itself, establish which intrusion that person carried out, which online persona they used, or whether a criminal group has stopped operating. That distinction matters in the Dutch ShinyHunters investigation, where an arrest, an earlier telecom breach, and a later claim against an FBI recruiting site have been pulled into one story.

As of September 29, 2026: Dutch police say they arrested a 24-year-old Amsterdam man on September 15 on suspicion of a role in ShinyHunters. A Rotterdam court has ordered another 90 days of detention, according to Associated Press reporting on the police announcement. Police have not publicly named him. KrebsOnSecurity identified him as Pepijn van der Stap using sources familiar with the matter; his employer separately confirmed that identification to Reuters.

The Dutch police also said the suspect is being investigated for alleged attempts to solicit two murders. Police said that allegation arose from material on a seized laptop and is separate from the ShinyHunters investigation, according to AP. It remains an allegation, not a conviction.

Where the Evidence Ends

Van der Stap’s earlier cybercrime conviction is established history, and Krebs reports that he had described himself as reformed in a September 9 interview. Neither fact establishes his conduct in 2026. The police have confirmed an investigation and an arrest; public statements have not supplied a charge sheet or forensic account linking him to a specific ShinyHunters intrusion. His employer told Reuters that an external review had so far found no evidence he had attacked the company or its customers. ShinyHunters told BNR it had no connection to the arrested man. That denial is a claim by an interested party, not independent exculpatory evidence.

The timing is also easy to overread. ShinyHunters claimed the FBI jobs-site intrusion after the September 15 arrest. Krebs describes an Umbreon image in the site’s defacement; Umbreon was a handle associated with Van der Stap’s earlier activity. A reused image or handle is weak attribution evidence because another operator can copy it. Krebs reports sources who interpret it as an attempt to implicate him, but that motive is not publicly proven. The arrest should not be presented as an explanation for the FBI incident, and the FBI claim should not be presented as proof of the suspect’s role.

Our earlier report on the FBI jobs-site claim separates the group’s asserted scope from what the FBI had acknowledged. AP reports that the FBI was still investigating the claimed breach; the group’s description of the stolen data had not been independently verified in the public record.

The Defensible Attack Paths

The Dutch police account of the Odido breach describes a Dutch-speaking caller who impersonated an IT colleague and persuaded a customer-service employee to give access to an internal system. Police say the group then obtained data on more than six million customers. That establishes a concrete social-engineering path; it does not identify the arrested man as the caller. The case shows why a support workflow needs its own independent identity checks.

A separate, technical path is active against Oracle PeopleSoft. Google Threat Intelligence Group and Mandiant reported on September 25 that the cluster they track as UNC6240 exploited CVE-2026-35273 in exposed PeopleSoft Environment Management Hub deployments. They observed requests to /%50SEMHUB/hub: %50 decodes to P, so a firewall rule matching only the literal /PSEMHUB/ path can miss it. Their report describes both web-shell deployment and command execution without a file written to disk. It does not establish that this vulnerability was the entry point in Odido or the FBI jobs-site incident. Our PeopleSoft response guide covers that campaign in detail.

What Defenders Should Do

OwnerActionEvidence that it works
Service-desk and identity teamsFor password resets, MFA enrollment, and privileged access changes, require a callback to a number already on file or another approved high-assurance verification path. Treat caller-provided employee details as insufficient proof.Review a sample of completed high-risk tickets: each should contain the independent verification and approver, with no exception based solely on caller knowledge.
Identity and SaaS teamsLimit enrollment of new authenticators and access from unmanaged devices; move high-risk roles toward phishing-resistant MFA. Alert on new MFA devices, unusual sessions, and large SaaS exports.Test a controlled reset and enrollment request from an untrusted device, then confirm the block or alert appears in identity and SaaS logs.
PeopleSoft ownersApply Oracle’s fix and follow the vendor’s Environment Management Hub guidance. If patching must wait, restrict external access to the hub at the perimeter using normalized URL paths; do not rely on a literal-string WAF rule alone.Confirm the installed fix and exposure state, then verify that external requests to both /PSEMHUB/ and encoded variants such as /%50SEMHUB/ cannot reach the hub.
Incident respondersFor suspected PeopleSoft exposure, preserve web-tier, WebLogic, identity, and egress logs; search for encoded hub requests, unexpected JSP files on every web node, and shell processes spawned by WebLogic.Correlate requests with host activity and data access. Absence of a JSP file does not clear a host because Google documented fileless execution.

The identity and help-desk steps follow Mandiant’s guidance for ShinyHunters-branded SaaS theft; the PeopleSoft steps follow its September 25 investigation. These are separate preventive paths for separate access methods. Logging and hunting help establish whether an intrusion occurred; they do not replace the verification workflow or the PeopleSoft fix. If compromise is found, revoke affected sessions and integrations, contain the exposed application, and scope data access before deciding what to disclose.

The operational conclusion is straightforward: track the criminal case as an investigation, and defend against the access methods supported by evidence. Neither an arrest nor a group’s denial changes the need to close a vulnerable service or a help-desk workflow attackers can talk their way through.

Sources