ShinyHunters Suspect Tied to Boeing Unit Extortion
A detained Jordanian teen accused of leading ShinyHunters allegedly extorted a former Boeing unit before his arrest, sources say.
The arrest of a suspected ShinyHunters leader in Jordan did not happen in a quiet window. According to KrebsOnSecurity, the detention of a teenager in Amman who used the hacker handle "Rey" coincided with the group's active extortion of a business unit recently divested by Boeing — a unit whose data, sources said, could carry operational safety and security risks. The account, drawn from two sources familiar with the investigation and the outlet's own reporting, adds a layer of consequence to a case that has mostly been framed around data theft and taunting.
Who Rey Is Alleged to Be
KrebsOnSecurity reported that the suspect detained in Amman is Saif Al-din Khader, identified by the outlet as "Rey" in a November 2025 profile in which the young man admitted working with multiple ransomware groups. The arrest itself was first reported by Reuters on October 3, which cited three unnamed sources saying a suspected ShinyHunters member in Amman named Saif Al-din Khader was detained by Jordanian authorities and was cooperating with the FBI.
KrebsOnSecurity had previously tied the handle to Khader, and its reporting places him at the center of the group's recent activity. According to the outlet, after the Dutch police arrested 24-year-old convicted cybercriminal Pepijn van der Stap on suspicion of aiding ShinyHunters, Rey assumed control over the ShinyHunters brand and publicly boasted about stealing sensitive data from the FBI and extorting the ransomware group Cl0p.
The outlet also reported that Rey taunted both the FBI and Cl0p with memes, while including images of the avatar used by Van der Stap's former hacker alias "Umbreon" in what KrebsOnSecurity described as an apparent attempt to frame the Dutchman for both hacks.
The Boeing Spin-off in the Crosshairs
The extortion attempt that overlapped with the arrest involved Jeppesen ForeFlight, a navigation and digital aviation unit that Boeing sold in November 2025 to the private equity firm Thoma Bravo for $10.55 billion. According to two sources familiar with the ShinyHunters investigation, that unit was among the victims the group was in the process of extorting when Rey was apprehended.
Those sources said the FBI's investigation gained renewed urgency with the attempted extortion of the former Boeing unit, which allegedly included the theft of sensitive information that the sources said could pose operational safety and security risks. The framing is notable because it moves the allegation beyond routine data theft into territory with physical and operational dimensions.
Boeing acknowledged the extortion attempts in a brief statement to KrebsOnSecurity, saying the incident concerned data stolen from the subsidiary. "We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight," a Boeing spokesperson said. "We are actively reviewing the matter with the Jeppesen ForeFlight team."
A spokesperson for Jeppesen ForeFlight said the company has seen no impact on its end. "Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."
Why the Father's Employer Matters
KrebsOnSecurity noted that Rey's alleged involvement in attempting to extort the former Boeing unit is noteworthy because there is strong evidence his father works for Royal Jordanian Airlines. According to the outlet, the airline is mostly controlled by the Jordanian government and operates its long-haul fleet on passenger planes built by Boeing. Rey claimed on Telegram in early 2025 that his father was an airline pilot, though the outlet said that could not be independently confirmed.
The outlet's earlier profile reported that the family's shared computer was at one point compromised by password-stealing malware, and the data collected by that malware clearly showed Rey's father used the same credentials to log in at multiple online portals for Royal Jordanian Airlines employees.
Royal Jordanian Airlines did not respond to a request for comment, according to KrebsOnSecurity. The outlet said that before its September 28 story it again emailed Rey's father to seek comment and update him on his son's alleged activities, and that neither of the Khaders responded. Just hours after that request was sent, the outlet reported, Rey began deleting various social media accounts, including the Twitter/X account he had used to taunt the FBI, Cl0p, and other ShinyHunters victims.
The PeopleSoft Flaw Behind the Campaign
KrebsOnSecurity reported that ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability tracked as CVE-2026-35273 in PeopleSoft, a software-as-a-service platform from Oracle broadly used by companies to manage hiring and human resources, benefits and payroll. Oracle issued a fix for the flaw, which ShinyHunters began exploiting as a zero-day in June. At the time, Mandiant released web application firewall rules intended for organizations that could not apply the security update quickly enough.
ShinyHunters told BleepingComputer in June that the original goal behind exploiting the PeopleSoft vulnerability was to breach the FBI's own PeopleSoft database, but the hackers said those attacks were unsuccessful for some reason. In the weeks since, according to the outlet, ShinyHunters turned to a well-known URL-encoding trick to bypass Mandiant's suggested web application firewall rules.
In a report released Sept. 25, security experts at Mandiant and the Google Threat Intelligence Group confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
Reuters reported October 5 that the FBI removed a contractor at Accenture over their failure to patch the FBI recruitment website hacked by ShinyHunters, which exposed sensitive data on more than 5,000 FBI personnel. That data included each person's unit and specialization, as well as medical and psychiatric records, according to the outlet.
The Dutch Arrest and New Allegations
The ShinyHunters thread also runs through the Netherlands, where Van der Stap was arrested on the evening of September 15 in a police raid that reportedly involved flash-bang grenades. KrebsOnSecurity's September 28 exclusive reported that Dutch police arrested the 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by ShinyHunters.
Van der Stap was released from prison after serving the better part of a four-year sentence for data theft and extortion activity that prosecutors said netted between €1.5 million and €2.7 million. In an interview with KrebsOnSecurity on September 9, he described his new role as "offensive security lead" at the Dutch cybersecurity company Neo Security, saying the job involved probing client networks for security vulnerabilities.
Neo Security's owner Benjamin Korper told Reuters he has hired an outside firm to investigate whether Van der Stap had hacked Neo Security or its customers, but that so far investigators have found no evidence he acted against his employer or clients. Korper said Dutch forensic investigators visited his office on September 15, the night Van der Stap was arrested.
Separately, news outlets in the Netherlands reported new allegations against Van der Stap. The Dutch daily RTL reported on Sept. 29 that investigators suspect Van der Stap tried to orchestrate at least two murders, allegedly to be committed abroad, with indications he gave the order for the attacks.
Asked in a recent interview why anyone should believe the word of a self-described "reformed" cybercriminal who had casually deceived friends, co-workers and journalists for years, Van der Stap said his work spoke for itself and that there was nothing he could say to convince his worst critics.
"You can throw a bunch of nice words at someone, but you can't convince them if they don't want to be convinced. I'm doing what I can to repay victims, and that's all I can do. If someone doesn't want to believe me, then that's on them."
— Pepijn van der Stap, speaking to KrebsOnSecurity on Sept. 9
ShinyHunters as a Franchise
Cybercriminals aligned with ShinyHunters have been responsible for dozens of data breaches involving billions of stolen records, and breaches claimed by the group stretch back to at least 2019. But experts told the outlet that the people recently operating behind the ShinyHunters name are not the same core members who populated the group in its early days, most of whom are French citizens who have been arrested, if not also imprisoned, on at least one prior occasion for alleged cybercrime activity.
According to the outlet, ShinyHunters has become something of a franchise, comparing it to the Dread Pirate Roberts character in "The Princess Bride," only with succession by arrest instead of by death, and with the possibility of multiple simultaneous Dread Pirate Robertses. Sources close to the investigation said the FBI is focusing on a remaining handful of cybercriminal freelancers or affiliates who have been feeding the group stolen credentials to various software-as-a-service platforms used by major companies in exchange for a cut of any data ransoms later paid by victims.
In the days after news broke of Van der Stap's arrest, a cybercrime-focused chat server on Telegram allegedly operated by Rey erupted with hot takes, with most participants heaping ridicule on the teenage hacker after he publicly backed down from threats against the FBI and Cl0p, and again when the ShinyHunters darknet website suddenly went offline. Several commentators accused Rey of resurrecting the ShinyHunters brand after its core members were rounded up in France, and making a mockery of the group's name and reputation ever since.
"He bought the old forum PGP key and used it to make new Breachforum websites and Telegram channels larping as ShinyHunters to ransom companies and then sell the used data or resell his forum when he goes broke."
— a member of the Telegram chat server, as recounted by KrebsOnSecurity
A relatively new Telegram channel called "The Battle" has been doxing and needling Rey and other alleged ShinyHunters members for several weeks, and it has gained a considerable readership among the cybercrime communities operating on Telegram. One coordinator of that harassment campaign repeatedly portrayed Rey as a clueless greenhorn seeking to ride the coattails of a cybercriminal brand that has long enjoyed a reputation for ruthlessly selling or publishing data stolen from victim companies that refuse to give in to extortion demands.
"Rey (Saif Al-Din Khader) made a serious mistake when he started pretending to be a member of ShinyHunters. That group had already been dismantled, with many of its members either arrested or imprisoned, yet Rey still chose to use its name while carrying out his crimes. We're aware of claims that [Rey] caused over $200 million in damages and helped around 5–6 friend groups in the community make money by using Shiny Hunters group aliases to negotiate dea"
— the administrators of The Battle server on Telegram
The Blog That Survived the Purge
Rey may have removed many of his social media profiles, but according to the outlet his cybersecurity blog on GitHub escaped the purge. KrebsOnSecurity reported that the blog shows Rey was fixated on the leaders of the Cl0p ransomware group. In March 2026, the blog featured a lengthy post that identified two Russian men as the core developers and hackers behind Cl0p, one of the oldest and most established ransomware groups still in operation.
The doxing post is one of the more unusual artifacts of the case, tying the teenager's public activity to a long-running ransomware operation rather than just the extortion attempts attributed to him. It also underscores how much of the investigative trail now runs through material the suspects themselves posted publicly before going dark.
What the Case Means for Defenders
For organizations running PeopleSoft or similar SaaS platforms, the mechanics described in the source are the practical takeaway: a single vulnerability tracked as CVE-2026-35273 was exploited as a zero-day, patched by Oracle, and then worked around via a URL-encoding trick that bypassed the suggested web application firewall rules. That sequence suggests that applying a vendor patch and relying solely on generic WAF rules can leave a gap when attackers adapt.
The scale described by Mandiant and the Google Threat Intelligence Group — mass exploitation against dozens of systems across higher education, technology, healthcare, agriculture, transportation and government — indicates the targeting was broad rather than narrowly focused on one sector. For defenders, that argues for treating SaaS platforms that hold HR, payroll and benefits data as high-value targets in their own right, not as back-office tools outside the security perimeter.
The Boeing case adds a different dimension. According to the sources cited by KrebsOnSecurity, the data allegedly stolen from the former Boeing unit could carry operational safety and security risks — a category of exposure that moves beyond privacy harm and into questions about how aviation-adjacent systems and data are protected. Jeppesen ForeFlight has said its investigation found no impact to operations or products, and Boeing has said it is reviewing the matter. Those statements leave the underlying claim contested rather than confirmed.
The arrest itself, if the reporting holds, may do little to settle the broader problem. The source material describes ShinyHunters less as a fixed group and more as a brand that outlives any individual operator, with affiliates feeding stolen credentials in exchange for a cut of ransoms. That structure means arrests can disrupt operations without dismantling the underlying model — a pattern the outlet's sources describe as a succession of operators rather than a single organization. Businesses should read the case less as a closed chapter and more as a reminder that identity is easy to inherit and hard to retire.
Sources
- Krebs on Security Original source
Continue Reading
MALFEX npm Campaign Hidden in Eight Packages
CloudSEK and Checkmarx say a lone actor shipped 12 npm packages since 2023, eight flagged malicious and downloaded 40,767 times.
States sue TP-Link over China ties, security claims
Florida, Iowa, Montana, and Nebraska allege TP-Link misled buyers about router security and undisclosed reliance on Chinese suppliers.
FortiBleed Credential Theft Still Active, FBI Says
The FBI and Secret Service say the FortiBleed campaign remains active, with 86,644 Fortinet device credentials amassed across 194 countries.