Suspected ShinyHunters Leader Detained in Jordan; Cooperation with FBI Underway

A teenager from Amman, Jordan, suspected of serving as a primary figurehead for the prolific data theft and extortion syndicate known as "ShinyHunters," has been detained by local authorities. Sources familiar with the investigation indicate that the suspect, who operates under the handle “Rey,” is currently cooperating with the Federal Bureau of Investigation (FBI) to help identify other members of the sprawling, decentralized hacking collective.

The detention of the suspect, identified in previous reporting as Saif Al-din Khader, occurred at a critical juncture: ShinyHunters was in the midst of an active extortion campaign targeting a business unit recently divested by the global aerospace giant Boeing. The irony of the situation has not been lost on investigators, as the suspect’s father is reportedly an employee of Royal Jordanian Airlines, which operates a fleet of commercial aircraft manufactured by Boeing.

The Rise and Fall of ‘Rey’

The link between the Amman-based teenager and the global cybercrime stage was solidified in a November 2025 profile by KrebsOnSecurity, in which Khader admitted to his involvement with multiple high-profile ransomware groups. His activities escalated significantly following the September 15 arrest of 24-year-old Dutch cybercriminal Pepijn van der Stap, known by the alias “Umbreon.”

Following the Dutch police raid—which reportedly involved the use of flash-bang grenades at Van der Stap’s residence—Rey moved to consolidate control over the ShinyHunters brand. In a brazen display of cyber-theater, he boasted publicly about compromising FBI systems and extorting the notorious Cl0p ransomware group. To further confuse investigators and deflect heat, Rey utilized his social media presence on Twitter/X to post memes that featured Umbreon’s avatar, a calculated effort to frame the recently arrested Dutchman for his own ongoing hacks.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The FBI’s interest in the group reached a fever pitch following reports that ShinyHunters had gained access to internal systems by exploiting a vulnerability in PeopleSoft, a widely used software-as-a-service (SaaS) platform managed by Oracle. The flaw, tracked as CVE-2026-35273, allowed the group to target organizations across diverse sectors, including healthcare, education, government, and technology. Security researchers at Mandiant and Google’s Threat Intelligence Group (GTIG) confirmed that the group had mass-exploited this vulnerability to siphon data from dozens of entities.

The fallout from these breaches has been severe. Reuters reported that the FBI was forced to terminate a contract with Accenture after it was discovered that a failure to patch the agency’s own recruitment portal led to the exposure of sensitive data belonging to over 5,000 FBI personnel. The leaked information included unit specializations, medical records, and psychiatric evaluations, creating a significant national security concern.

Extortion Targets and Operational Risks

The investigation into Rey gained momentum as it became clear that the group was targeting Jeppesen ForeFlight, a navigation and digital aviation data subsidiary that Boeing sold to private equity firm Thoma Bravo in late 2025 for $10.55 billion. Sources suggested that the stolen data included information that could pose genuine operational safety risks to the aviation industry.

Boeing issued a statement acknowledging the extortion attempts, noting that they are reviewing the matter alongside the Jeppesen ForeFlight team. For its part, Jeppesen ForeFlight has maintained a defensive posture, asserting that their investigation has shown no material impact on their core operations or aviation products.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The personal connection between the suspect and the aviation industry remains a focal point of the investigation. While it has not been independently verified that Rey’s father is a pilot for Royal Jordanian Airlines, digital breadcrumbs discovered during earlier investigations suggest a high likelihood of this link. A previous compromise of the Khader family’s computer revealed that the father used the same login credentials for various Royal Jordanian employee portals as those found in other breached databases. Despite repeated attempts by journalists to reach the family for comment, both the suspect and his father have remained silent, with Rey opting to scrub his digital presence—including his Twitter/X account—shortly after inquiries were made.

Interestingly, despite his purge of social media, Rey’s technical blog hosted on GitHub remained active for some time. The blog served as a repository for his exploits, including a detailed post from March 2026 that "doxxed" two Russian nationals, claiming they were the core developers behind the Cl0p ransomware group.

A Network of Criminal Franchising

The recent developments regarding Pepijn van der Stap have added a darker layer to the saga. Reports from Dutch news outlets, including RTL, suggest that Van der Stap is now under investigation for allegedly ordering at least two contract murders. This development has shocked many in the tech industry, as Van der Stap had successfully branded himself as a "reformed" hacker, even securing a position as an "offensive security lead" at a Dutch firm called Neo Security prior to his arrest.

The owner of Neo Security, Benjamin Korper, has stated that an external firm is currently auditing the company to ensure that Van der Stap did not leverage his position to compromise their clients. To date, no evidence of such internal sabotage has been found.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Experts in the threat intelligence community observe that the current iteration of ShinyHunters bears little resemblance to the group’s original founders, most of whom were French citizens who have largely been neutralized by law enforcement. Instead, the group has evolved into a "franchise" model, reminiscent of the Dread Pirate Roberts archetype. In this modern cyber-underworld, the "ShinyHunters" brand is a mantle that various freelancers and affiliates pick up to facilitate extortion.

These affiliates use the group’s name to negotiate deals, often splitting ransoms with other groups in exchange for access to stolen credentials. The FBI’s focus has shifted to these scattered, freelance operators who keep the brand alive through sporadic, high-visibility attacks.

The Battle for Reputation

The group’s decision to target the FBI was, according to the hackers themselves, a public relations maneuver. In an interview with The Register, the group claimed they attacked the bureau to refute a May 2026 FBI flash notice that warned victims against paying ransoms. The hackers argued that the FBI’s advice was "unprofessional" and that they needed to demonstrate their "technical capabilities" to maintain leverage over future victims.

The FBI’s advisory, however, painted a grim picture of the group’s methods, warning that ShinyHunters frequently resorted to swatting, harassing victims’ family members, and making false claims about the existence of compromising personal materials to coerce payments.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The current atmosphere within the cybercrime community is one of disdain for the "new" ShinyHunters. A Telegram channel aptly titled "The Battle" has spent weeks mocking Rey, portraying him as a "clueless greenhorn" who exploited a brand name that had already been dismantled by global law enforcement. Critics within these underground forums argue that Rey’s attempt to play the part of a legendary hacker was a tactical error that drew unnecessary attention from the FBI, ultimately leading to the group’s digital and physical collapse.

As the dust settles, the case of Rey serves as a stark illustration of the modern cybercrime ecosystem: a world of ephemeral brands, high-stakes extortion, and young hackers who often underestimate the reach of international intelligence agencies. With the suspect now cooperating with the FBI, the investigation may soon peel back the final layers of what has become one of the most persistent, if fragmented, extortion networks of the decade.

Share:

Iffa Jayyana writes for Tech Maze.

Leave a comment