Alleged ShinyHunters Leader Detained in Jordan as FBI Investigation Into Data Theft Syndicate Intensifies

A teenager from Amman, Jordan, suspected of orchestrating the operations of the prolific data theft and extortion syndicate known as "ShinyHunters," has been detained by local authorities. Sources indicate the suspect is now cooperating with the Federal Bureau of Investigation (FBI) to help identify other key members of the hacking collective.

The suspect, who operates under the hacker handle "Rey," was apprehended during a sensitive period for the group: ShinyHunters was actively engaged in an extortion campaign targeting a business unit recently divested by the global aerospace giant Boeing. The irony of the target has not been lost on investigators, as the suspect’s father is reportedly employed by Royal Jordanian Airlines, a carrier that relies on a fleet of aircraft manufactured by Boeing.

The Identification of "Rey"

On October 3, Reuters reported that a suspect in Amman, identified as Saif Al-din Khader, had been taken into custody by Jordanian authorities. This development follows a detailed investigation by KrebsOnSecurity, which first identified "Rey" as Khader in a November 2025 profile. In that report, the young man openly discussed his involvement with several prominent ransomware organizations.

The arrest of Khader comes on the heels of a significant September 28 operation by Dutch law enforcement. Police in the Netherlands arrested 24-year-old Pepijn van der Stap, a convicted cybercriminal suspected of providing critical support for ShinyHunters’ data theft and extortion activities.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

According to security analysts, "Rey" assumed de facto control over the ShinyHunters brand immediately following Van der Stap’s arrest on September 15. In an attempt to solidify his position and project power, Khader publicly boasted about breaching the FBI and extorting the infamous ransomware group "Cl0p." His behavior during this time was characterized by intense, inflammatory taunting on the platform X (formerly Twitter). In a bizarre strategic move, Khader included images of an avatar previously used by Van der Stap—a hacker alias known as "Umbreon"—in his posts, clearly attempting to frame the Dutch national for the very hacks he was orchestrating himself.

Exploiting the PeopleSoft Vulnerability

The recent wave of activity linked to ShinyHunters is largely predicated on the exploitation of a critical vulnerability, designated CVE-2026-35273, within Oracle’s PeopleSoft software. This platform is a ubiquitous service for large enterprises, handling essential functions such as human resources, recruitment, payroll, and benefits management.

ShinyHunters began weaponizing this vulnerability as a zero-day exploit as early as June. Although Oracle acted swiftly to issue a patch, the group proved resilient. When security firm Mandiant released web application firewall (WAF) rules designed to mitigate the threat for organizations unable to immediately deploy the update, the hackers simply pivoted. According to reports from BleepingComputer, the group successfully bypassed these security measures by employing a well-known URL-encoding technique.

A joint report released on September 25 by Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had utilized this exploit to compromise a wide array of sectors, including healthcare, education, government, technology, and agriculture. The reach of these breaches has been severe; on October 5, Reuters reported that the FBI had terminated a contractor at Accenture. The decision followed a damaging security breach of an FBI recruitment website, which exposed the sensitive personal, medical, and psychiatric records of over 5,000 agency personnel.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The Boeing Connection and Family Ties

The investigation into "Rey" took a more serious turn when it was revealed that his recent activities included the attempted extortion of a navigation and digital aviation unit formerly owned by Boeing. The FBI’s interest in the case intensified significantly when it was discovered that the stolen data included information posing potential operational safety and security risks.

The unit in question, Jeppesen ForeFlight, was sold by Boeing to the private equity firm Thoma Bravo in November 2025 for $10.55 billion. While a Boeing spokesperson acknowledged that the company is "actively reviewing the matter" alongside the Jeppesen ForeFlight team, the subsidiary maintained that its own operations and products remained unaffected by the incident.

The connection to the suspect’s family life remains a point of interest for investigators. The young hacker previously claimed on Telegram that his father was an airline pilot for Royal Jordanian Airlines. While this could not be independently verified, digital forensic evidence from a prior compromise of a family computer showed that the suspect’s father used identical credentials to access multiple employee portals for the airline. Despite attempts by KrebsOnSecurity to reach out to the elder Khader for comment, no response was provided. Notably, shortly after the inquiry was sent, "Rey" began purging his social media presence, including the account used to taunt the FBI and other victims.

Allegations of Murder-for-Hire

The situation surrounding Pepijn van der Stap, the Dutchman arrested in the raid involving flash-bang grenades, has taken an even darker turn. Beyond the charges of cybercrime, Dutch media outlet RTL reported on September 29 that investigators are probing allegations that Van der Stap attempted to coordinate at least two murders abroad.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

These allegations stand in stark contrast to the persona Van der Stap attempted to cultivate after his initial release from a four-year prison sentence. In a September 9 interview, he insisted that he was a "reformed" hacker now serving as an "offensive security lead" at Neo Security, a Dutch cybersecurity firm. Benjamin Korper, the owner of Neo Security, has since hired an external firm to audit the company for any signs of internal sabotage, though no evidence has yet surfaced suggesting Van der Stap compromised his employer.

The Evolution of the ShinyHunters "Brand"

Security experts suggest that the current iteration of ShinyHunters bears little resemblance to its original, French-led collective that gained notoriety around 2019. The group has effectively morphed into a decentralized franchise. Much like the "Dread Pirate Roberts" character from The Princess Bride, the name "ShinyHunters" is now a moniker utilized by various threat actors, with the brand living on through a succession of arrests and new recruits.

The FBI is currently focusing its efforts on a network of freelance cybercriminals who contribute stolen credentials to these platforms in exchange for a percentage of the ransom proceeds. However, the brand’s reputation has suffered under "Rey." Within the clandestine chat rooms of Telegram, many seasoned cybercriminals have openly ridiculed Khader for his amateurish antics and his failure to maintain the group’s historical standards of operational security.

One Telegram channel, "The Battle," has been particularly vocal in its campaign to expose the teenager, portraying him as a "greenhorn" who recklessly resurrected a defunct brand to serve his own financial interests. According to the administrators of this channel, Khader claimed responsibility for over $200 million in damages while facilitating extortion deals for several other criminal groups.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

A PR War with the FBI

The decision to target the FBI was, by the hackers’ own admission, a desperate public relations stunt. In an interview with The Register, members of the group claimed they breached the bureau to counter the agency’s official advisory from May 2026, which warned victims against paying ransoms.

The FBI’s advisory had highlighted the group’s increasingly aggressive tactics, which have included swatting, harassment of victims’ families, and the threat to leak sensitive personal media. By attacking the FBI, the group sought to project an image of technical superiority and defiance. However, the move may have ultimately backfired, as the increased scrutiny from law enforcement and the subsequent loss of credibility within the cybercrime community likely contributed to the group’s infrastructure—including their darknet site—being driven offline. As "Rey" remains in custody, the fragmented remnants of the ShinyHunters franchise appear to be struggling to maintain their relevance in an increasingly hostile landscape.

Share:

Nana Muazin writes for Tech Maze.

Leave a comment