Suspected Leader of ShinyHunters Detained in Jordan, Reportedly Cooperating with FBI

A teenager from Amman, Jordan, suspected of acting as a central figure in the notorious data theft and extortion syndicate known as "ShinyHunters," has been taken into custody by local authorities. According to reports, the suspect is currently cooperating with the Federal Bureau of Investigation (FBI) to help identify other members of the sprawling, decentralized hacking collective.

The suspect, who operates under the hacker handle "Rey," was apprehended at a critical juncture for the group: ShinyHunters was in the midst of an active extortion campaign targeting a business unit recently divested by the global aerospace giant Boeing. The irony of the target is palpable; the business unit in question services the aviation industry, and the employer of Rey’s father—Royal Jordanian Airlines—relies on the very fleet of aircraft manufactured by Boeing.

The Rise and Fall of ‘Rey’

On October 3, Reuters cited three unnamed sources confirming that a suspected ShinyHunters member in Amman, identified as Saif Al-din Khader, had been detained and was assisting the FBI. This identification aligns with a detailed profile published by KrebsOnSecurity in November 2025, which highlighted Khader—or "Rey"—as a young, prolific actor who openly admitted to collaborating with multiple ransomware groups.

The investigation into Rey intensified following a September 28 exclusive report regarding the arrest of Pepijn van der Stap, a 24-year-old convicted cybercriminal based in the Netherlands. Dutch authorities apprehended Van der Stap on suspicion of facilitating data thefts for ShinyHunters. Following the dramatic September 15 raid on Van der Stap’s home, Rey reportedly seized control of the ShinyHunters brand. In a brazen display of ego and tactical miscalculation, Rey began publicly boasting about stealing highly sensitive data from the FBI and extorting the infamous ransomware group Cl0p.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

In an attempt to redirect heat from himself, Rey taunted both the FBI and Cl0p on Twitter/X with a series of memes. He notably included the avatar of Van der Stap’s former hacking alias, "Umbreon," in his posts—a transparent attempt to frame the Dutchman for his own recent exploits.

Exploiting the Oracle Vulnerability

The group’s recent surge in activity was predicated on the exploitation of CVE-2026-35273, a significant vulnerability in PeopleSoft, a software-as-a-service (SaaS) platform owned by Oracle. Used globally by corporations and government agencies for payroll, human resources, and recruitment, the platform provided a lucrative gateway for data theft.

Although Oracle issued a patch for the vulnerability, ShinyHunters had been utilizing it as a zero-day exploit since June. Even after Mandiant released web application firewall (WAF) rules designed to mitigate the threat for organizations unable to patch immediately, the group successfully pivoted to a well-known URL-encoding trick to bypass those protections.

In a joint report published September 25, security researchers from Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had utilized the exploit to compromise dozens of systems across diverse sectors, including healthcare, technology, government, and transportation. The damage reached the highest levels of federal security; on October 5, Reuters reported that the FBI had terminated an Accenture contractor after it was discovered that a failure to patch the vulnerability led to the compromise of an FBI recruitment website. This breach exposed sensitive records of more than 5,000 FBI personnel, including medical and psychiatric history, as well as specific unit and specialization details.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The Boeing Connection

The scope of Rey’s alleged criminal activity extended to the aerospace sector. Investigators familiar with the case confirmed that when Rey was apprehended, he was actively extorting a navigation and digital aviation unit recently divested by Boeing. The investigation gained significant urgency due to the nature of the stolen data, which experts warned could pose tangible operational safety and security risks.

Boeing confirmed the extortion attempts, noting that the incident involved data linked to Jeppesen ForeFlight, a subsidiary the aerospace giant sold to private equity firm Thoma Bravo for $10.55 billion in November 2025. A spokesperson for the company stated, “We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter with the Jeppesen ForeFlight team.” For its part, Jeppesen ForeFlight maintained that its own investigation revealed no impact on its internal operations or products.

The connection to the suspect’s family life remains a point of intense scrutiny. Strong evidence suggests that Rey’s father is employed by Royal Jordanian Airlines, a carrier controlled by the Jordanian government. During 2025, Rey claimed on Telegram that his father was an airline pilot. While that assertion remains unconfirmed, earlier security findings showed that the Khader family’s shared computer had been compromised by password-stealing malware. The logs from that infection revealed that Rey’s father frequently used the same credentials to access internal employee portals for Royal Jordanian Airlines. Neither the suspect nor his father has responded to requests for comment. Shortly after inquiries were sent, Rey began a frantic digital purge, deleting his social media presence and his Twitter/X account.

Allegations of Murder-for-Hire

The narrative surrounding the Dutch suspect, Pepijn van der Stap, has taken an even darker turn. While Van der Stap had previously been portrayed in some tech circles as a "reformed" hacker, Dutch news outlet RTL reported on September 29 that authorities now suspect him of orchestrating at least two contract killings.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Van der Stap, who had served the majority of a four-year sentence for previous cybercrimes, had seemingly rebranded himself as an "offensive security lead" at a Dutch firm called Neo Security. The firm’s owner, Benjamin Korper, stated that an external investigation had been launched to determine if Van der Stap had compromised his employer or clients, though no evidence of such activity has surfaced to date. The arrest of Van der Stap in mid-September, which reportedly involved the use of flash-bang grenades by Dutch police, signaled a definitive end to his brief, high-profile career as a security consultant.

The "Dread Pirate Roberts" Model

The evolution of ShinyHunters reflects a broader trend in modern cybercrime: the rise of the "franchise" model. Much like the Dread Pirate Roberts from the film The Princess Bride, the ShinyHunters name has become a title passed along to whoever controls the brand, rather than a fixed group of individuals. The original core of the group, largely consisting of French nationals, was dismantled by law enforcement years ago.

Today, the brand serves as a banner for a loose collection of freelancers. These affiliates provide stolen credentials from SaaS platforms to the group in exchange for a percentage of the eventual ransom. This shift has drawn ire from older members of the cybercriminal community, who view the current operators as "larpers" who have cheapened the group’s reputation.

Following the arrest of Van der Stap, the Telegram channels linked to the group turned on Rey, ridiculing him for his lack of operational security and his failure to maintain the brand’s supposed "professionalism." A new Telegram channel, dubbed "The Battle," has dedicated itself to exposing Rey’s identity and tracking his movements, accusing him of causing over $200 million in damages while merely riding the coattails of a defunct hacking collective.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The group’s attempt to hack the FBI earlier this year served as the climax of their recent publicity-seeking behavior. While the hackers claimed the breach was a tactical strike against the FBI’s advisory warnings, the FBI’s May 2026 notice had clearly struck a nerve. The agency warned that ShinyHunters was known for aggressive harassment, including "swatting" and the threat of leaking non-existent compromising material. By attempting to hit back, the hackers admitted they were primarily concerned with the "public relations and marketing" aspect of their business—a final, desperate attempt to maintain their leverage before the walls closed in.

Share:

Lina Hope writes for Tech Maze.

Leave a comment