Teen Leader of Notorious ShinyHunters Hacking Group Detained in Jordan, Cooperating with FBI

A teenager from Amman, Jordan, suspected of acting as the central figure behind the prolific data theft and extortion syndicate known as "ShinyHunters," has been taken into custody by local authorities. According to reports, the suspect is currently cooperating with the Federal Bureau of Investigation (FBI) in a bid to unmask other high-level members of the hacking collective.

The suspect, who operates under the hacker handle "Rey," was apprehended at a critical juncture: the group was actively engaged in an extortion campaign targeting a business unit recently divested by the global aerospace giant Boeing. The irony of the target is not lost on investigators, as the suspect’s own father is reportedly employed by Royal Jordanian Airlines, an entity that relies heavily on a fleet of Boeing aircraft.

The Rise and Fall of ‘Rey’

The confirmation of the arrest follows an October 3 report from Reuters, which cited three unnamed sources indicating that a suspected ShinyHunters member, identified as Saif Al-din Khader, was in custody and assisting the FBI. This individual had previously been profiled by KrebsOnSecurity in November 2025, during which the young man openly admitted to his involvement with various ransomware organizations.

The arrest of Khader—or "Rey"—marks a significant escalation in the international pursuit of ShinyHunters. His influence within the cybercrime underground grew rapidly in late 2025 and 2026. Most recently, his profile was bolstered by the September 28 arrest of 24-year-old Dutch national Pepijn van der Stap, who was taken into custody by Dutch police on suspicion of facilitating the group’s data theft and extortion operations.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Following Van der Stap’s arrest on September 15, Rey moved quickly to consolidate power, assuming control of the ShinyHunters brand. In a display of brazen confidence, he publicly boasted about his ability to compromise the FBI and extort the notorious ransomware group Cl0p. To solidify his dominance, Rey utilized his long-standing Twitter/X account to taunt both agencies and rival hackers, going so far as to include the avatar of "Umbreon"—the former alias of Van der Stap—in his memes, a move clearly intended to frame the Dutchman for his own criminal activities.

Exploiting the Oracle PeopleSoft Vulnerability

The group’s ability to breach high-profile targets was largely predicated on the exploitation of CVE-2026-35273, a critical vulnerability within Oracle’s PeopleSoft platform. This software-as-a-service suite is a cornerstone for many major organizations, managing complex operations including payroll, human resources, benefits, and hiring.

Although Oracle moved quickly to patch the vulnerability after it was identified as a zero-day in June 2026, the damage had already been done. Security firm Mandiant had released specific web application firewall (WAF) rules to protect organizations that could not immediately implement the patch. However, ShinyHunters proved resourceful, utilizing a well-documented URL-encoding technique to bypass these security measures.

A joint report published on September 25 by Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had utilized this exploit in a mass-exploitation campaign. The scope of the attacks was vast, spanning sectors as diverse as higher education, healthcare, technology, agriculture, transportation, and government. The breach of the FBI’s own recruitment website was particularly damaging, leading to the reported removal of an Accenture contractor for failing to apply the necessary security updates. This breach exposed the personal data of over 5,000 FBI personnel, including sensitive details regarding their specializations and medical history.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Extortion and the Boeing Connection

The investigation into ShinyHunters gained significant momentum when the group began targeting a digital aviation and navigation unit divested by Boeing. Sources close to the investigation suggest that the stolen data included sensitive operational information, raising concerns about potential safety and security risks.

Boeing issued a statement confirming that it was aware of the claims made by the threat actor regarding data associated with Jeppesen ForeFlight, a subsidiary that had been sold to the private equity firm Thoma Bravo in November 2025 for $10.55 billion. While the aerospace company confirmed it was reviewing the matter, Jeppesen ForeFlight maintained that their internal investigation found no evidence of an impact on their own operations or products.

The proximity of this extortion attempt to the suspect’s personal life remains a point of intense interest for investigators. Strong evidence suggests that Khader’s father is employed by Royal Jordanian Airlines. In early 2025, Rey had claimed on Telegram that his father was an airline pilot, a detail that, while unconfirmed, aligns with evidence recovered from a compromised family computer. Forensic analysis of that device revealed that the same credentials used to log into the family machine were also used to access employee portals for the airline. Neither Khader nor his father responded to requests for comment. Following these inquiries, Rey began a systematic purge of his digital footprint, deleting his social media profiles—though his GitHub blog, which had previously doxed two Russian operators behind the Cl0p ransomware group, remained online.

Allegations of Extreme Violence

The legal troubles facing the ShinyHunters network have expanded beyond mere data theft. In the Netherlands, reports have emerged suggesting that Pepijn van der Stap, who had previously presented himself as a reformed hacker working in "offensive security," was involved in far more sinister activities. According to the Dutch outlet RTL, investigators suspect Van der Stap of ordering at least two contract murders to be carried out abroad.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Van der Stap had been released from prison after serving the majority of a four-year sentence for cybercrimes that netted millions of euros. Despite his claims of having transitioned to a legitimate career at Neo Security, his arrest on September 15—which involved a high-stakes raid by police utilizing flash-bang grenades—suggests that authorities viewed his activities as a severe threat.

When questioned about his past, Van der Stap had consistently maintained that his current work in cybersecurity was his way of making amends. "You can throw a bunch of nice words at someone, but you can’t convince them if they don’t want to be convinced," he stated shortly before his arrest. "I’m doing what I can to repay victims, and that’s all I can do."

A Fragmented Franchise

The modern incarnation of ShinyHunters is far removed from its origins. While the brand carries the weight of years of notoriety, the current operators are largely seen by industry experts as a collection of freelancers and opportunistic affiliates. The group has effectively transitioned into a "franchise" model, where the brand name is used as a vehicle for profit-sharing.

The FBI’s focus has shifted to identifying the various affiliates who feed stolen credentials to the group in exchange for a percentage of the ransom payments. Following the arrest of Van der Stap and the subsequent removal of the ShinyHunters darknet site, the group’s internal communication channels on Telegram were flooded with criticism. Many within the cybercrime community accused Rey of being a "larper"—a novice hacker who adopted the ShinyHunters name to ride the coattails of a more capable, original group that had already been dismantled by law enforcement.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The backlash was severe. A Telegram channel known as "The Battle" emerged as a focal point for this frustration, actively doxing Rey and ridiculing his claims of professional-level hacking. The administrators of this channel alleged that Rey was responsible for massive financial damages, yet they dismissed his technical prowess, characterizing him as a greenhorn who sought to exploit a reputation he had not earned.

Ultimately, the hackers’ attempts to use the media—including interviews with outlets like The Register—to frame their attacks on the FBI as a "public relations initiative" largely backfired. The FBI’s own warnings, which cautioned that the group often resorts to harassment and swatting, served to solidify the agency’s position against the group. As the investigation continues, the downfall of Rey and his associates highlights the precarious nature of the cybercriminal landscape, where reputations are often as fleeting as the digital footprints they leave behind.

Share:

Sagoh writes for Tech Maze.

Leave a comment