Alleged Leader of ShinyHunters Hacking Collective Detained in Jordan

A teenage hacker from Amman, Jordan, suspected of serving as the central figure behind the notorious data theft and extortion syndicate known as "ShinyHunters," has been taken into custody. Sources indicate that the suspect, who operates under the online handle "Rey," is currently cooperating with the Federal Bureau of Investigation (FBI) to assist in the identification and apprehension of other members within the global hacking collective.

The detention of the suspect, identified in previous investigations as Saif Al-din Khader, marks a significant turning point in the pursuit of a group that has plagued major organizations for years. According to information obtained by KrebsOnSecurity, the arrest occurred at a critical juncture: ShinyHunters was in the midst of an aggressive extortion campaign targeting a business unit recently divested by the aerospace giant Boeing. The irony of the target is notable, as the suspect’s father is reportedly employed by Royal Jordanian Airlines, a carrier that relies on a fleet of Boeing aircraft.

The Rise and Fall of ‘Rey’

The international law enforcement interest in Saif Al-din Khader is the culmination of years of digital surveillance and investigative reporting. In a November 2025 profile, KrebsOnSecurity identified Khader as the individual behind the "Rey" handle, a moniker the teenager used to navigate the shadowy corners of the internet. During that period, Khader openly acknowledged his involvement with multiple ransomware groups, establishing himself as a prolific, if reckless, actor in the cybercrime ecosystem.

The scope of his activity became even clearer in late September 2026, following the arrest of 24-year-old Dutch national Pepijn van der Stap. Authorities in the Netherlands apprehended Van der Stap on September 15, accusing him of facilitating data theft and extortion for the ShinyHunters brand. In the chaotic hours immediately following the Dutchman’s arrest, Rey attempted to consolidate power. He publicly boasted about stealing sensitive information from the FBI and extorting the infamous ransomware gang "Cl0p."

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

To distract investigators, Rey engaged in a sophisticated disinformation campaign. He utilized his Twitter/X account to post memes taunting both the FBI and Cl0p, while simultaneously incorporating the specific avatar formerly used by Van der Stap under his own alias, "Umbreon." The maneuver was a calculated attempt to frame the imprisoned Dutchman for the new wave of attacks, creating a digital smokescreen to protect his own identity.

Exploiting the Oracle PeopleSoft Vulnerability

The operational success of ShinyHunters during this period was largely predicated on the exploitation of a single, critical vulnerability: CVE-2026-35273. This flaw existed within PeopleSoft, a widely deployed software-as-a-service (SaaS) platform developed by Oracle. Because PeopleSoft is a staple for corporate functions such as human resources, payroll, and benefits management, its compromise granted the hackers access to sensitive data across a vast array of industries, including healthcare, government, technology, and transportation.

Although Oracle issued a patch for the vulnerability, ShinyHunters had been using it as a zero-day exploit since June. Even after security firms like Mandiant released web application firewall (WAF) rules to help organizations defend their systems, the hackers proved resilient. They pivoted to a well-known URL-encoding technique that effectively bypassed the security measures, allowing them to continue their data harvesting efforts.

A report released on September 25 by Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that the group had mass-exploited this vulnerability to compromise dozens of systems. The fallout was significant. In early October, reports emerged that the FBI had been forced to terminate a contractor at Accenture. The decision followed a damaging breach of an FBI recruitment website, where the failure to patch the PeopleSoft vulnerability exposed the personal, medical, and psychiatric records of more than 5,000 FBI personnel.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The Boeing Connection and Family Ties

The investigation into "Rey" took a more personal turn due to the nature of his targets. Sources familiar with the ongoing probe confirmed that at the time of his arrest, the teenager was actively extorting a navigation and digital aviation unit divested by Boeing. This unit, Jeppesen ForeFlight, was sold to the private equity firm Thoma Bravo for $10.55 billion in late 2025.

The FBI viewed the extortion of this specific entity with extreme urgency, as the stolen data reportedly contained information that could jeopardize operational safety and aviation security. When approached for comment, Boeing acknowledged the incident, stating, "We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter with the Jeppesen ForeFlight team."

For its part, Jeppesen ForeFlight maintained that their internal systems remained secure, stating that their proactive security posture ensured there was no impact on their core operations or products.

The suspect’s choice of target remains a point of intense scrutiny. Given the strong evidence linking his father to Royal Jordanian Airlines, the attempted extortion of a Boeing-related entity appears particularly reckless. Evidence from a previous security compromise involving a family computer showed that the suspect’s father used identical credentials to access multiple internal portals for Royal Jordanian employees, suggesting a lack of basic digital hygiene within the household that may have facilitated the son’s early access to sensitive credentials. Neither the suspect nor his father responded to multiple requests for comment. Shortly after these inquiries were made, Rey began a rapid scrubbing of his online presence, deleting the social media accounts he had used to taunt law enforcement.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The Van der Stap Murder Allegations

While Rey’s situation in Jordan is unfolding, the legal circumstances surrounding the Dutch suspect, Pepijn van der Stap, have grown increasingly dire. Initially framed as a "reformed" hacker who had transitioned into an "offensive security lead" at the Dutch firm Neo Security, Van der Stap is now facing explosive allegations. According to the Dutch media outlet RTL, investigators suspect that Van der Stap did not merely limit his activity to digital extortion; he is now accused of orchestrating at least two murders abroad.

The revelation has cast doubt on his public narrative of redemption. Before his arrest, Van der Stap had successfully convinced many in the tech industry that he had turned his back on crime, even as he was allegedly performing unauthorized "probing" of client networks. The dramatic nature of his arrest—which involved flash-bang grenades during a raid on his residence—suggests that Dutch authorities took the threat posed by the former hacker very seriously.

Franchising the ShinyHunters Brand

The current state of ShinyHunters is perhaps best described as a decentralized franchise. The original core members of the group, who were primarily French nationals, were largely neutralized by law enforcement years ago. In their absence, the "ShinyHunters" name has been co-opted by a revolving door of opportunistic cybercriminals.

Much like the fictional "Dread Pirate Roberts," the title is now a mantle passed down through arrests and exits. The FBI’s current investigation is focused on a network of freelance hackers who supply stolen credentials to these platforms in exchange for a percentage of the eventual ransom payments.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The reputation of the brand, however, has suffered under the stewardship of individuals like Rey. Within the underground Telegram communities where these hackers congregate, Rey has been widely mocked for his inability to maintain the group’s "ruthless" persona. Following the FBI’s May 2026 public notice advising against ransom payments, the hackers’ business model began to struggle.

In a desperate bid to reassert their dominance, the group attempted to hack the FBI itself. While the technical breach was a matter of public record, the move was widely viewed as a public relations blunder. By engaging in a high-profile feud with the agency, the hackers essentially broadcast their own vulnerability, leading to a decline in their ability to extort corporate victims. As the "The Battle" Telegram channel—a group dedicated to tracking and shaming these hackers—noted, Rey’s choice to operate under the defunct ShinyHunters name was a strategic failure that ultimately led to his downfall. With the darknet site offline and the primary actors under investigation, the saga of the modern ShinyHunters appears to be drawing to a close.

Share:

Nana Muazin writes for Tech Maze.

Leave a comment