A teenager from Amman, Jordan, suspected of leading the prolific data theft and extortion syndicate known as ShinyHunters, has been detained by local authorities and is reportedly cooperating with the FBI to identify other members of the notorious hacking gang.
Investigative journalist Brian Krebs has learned that the suspect, who operates online under the hacker handle “Rey,” was taken into custody just as the decentralized cybercriminal group was actively attempting to extort a business unit recently divested by global aerospace giant Boeing. Intricately tying the local context to the digital investigation, Boeing manufactures the fleet of aircraft utilized by the employer of Rey’s father—Royal Jordanian Airlines.
The developments follow a series of international law enforcement actions and high-profile breaches that have brought renewed global scrutiny to the modern operational model of cybercrime syndicates.
The Arrests and the "Rey" Persona
On October 3, Reuters cited three unnamed sources confirming that a suspected ShinyHunters member in Amman named Saif Al-din Khader had been detained by Jordanian authorities and was actively assisting the FBI. KrebsOnSecurity previously identified Rey as Khader in a November 2025 profile, wherein the young man admitted to collaborating with multiple ransomware operations.
Rey’s activities captured headlines once again following a September 28 exclusive detailing the Dutch police arrest of 24-year-old convicted cybercriminal Pepijn van der Stap. Authorities suspect Van der Stap aided in data thefts and extortion plots orchestrated by ShinyHunters. According to investigators, immediately following the Dutchman’s dramatic arrest on the evening of September 15, Rey seized control of the ShinyHunters brand. He publicly boasted about compromising highly sensitive data belonging to the FBI and extorting the rival ransomware group Cl0p.
Using his long-standing account on Twitter/X, Rey taunted both the FBI and Cl0p with custom memes. Simultaneously, he embedded images of the avatar previously utilized by Van der Stap under his former hacker alias, “Umbreon,” in an apparent false-flag operation designed to pin the intrusions on the Dutch suspect.
As established in previous reports, ShinyHunters managed to breach the FBI recruitment portal and other corporate victims by exploiting a critical zero-day vulnerability, cataloged as CVE-2026-35273, within PeopleSoft. This software-as-a-service platform, developed by tech giant Oracle, is widely deployed across enterprises globally for human resources, recruitment, payroll, and benefits management. Oracle swiftly patched the vulnerability after ShinyHunters began mass exploitation in June. Around the same time, Mandiant published web application firewall (WAF) rules designed to protect organizations unable to immediately apply the official vendor patch.

While ShinyHunters admitted to BleepingComputer in June that their initial ambition was to compromise the FBI’s proprietary PeopleSoft database—an attempt that initially failed—the group later pivoted. In subsequent weeks, the threat actors employed a well-known URL-encoding technique to successfully bypass the mitigation rules recommended by Mandiant.
A joint threat intelligence report released on September 25 by experts at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had leveraged the vulnerability in a mass-exploitation campaign. The attacks targeted dozens of systems spanning diverse industry verticals, including technology, higher education, healthcare, transportation, agriculture, and government sectors.
Further compounding the fallout within federal agencies, Reuters reported on October 5 that the FBI dismissed an Accenture contractor following failures to properly patch the compromised recruitment website. That breach exposed sensitive information belonging to more than 5,000 current and former FBI personnel, including individual unit assignments, specializations, and confidential medical and psychiatric records.
“Rey” Means King, As in Royal
According to two sources familiar with the ongoing international investigation into ShinyHunters, a digital navigation and aviation business unit recently divested by Boeing was directly targeted in the extortion campaign underway at the time of Rey’s apprehension.
Investigators familiar with the case noted that the FBI’s pursuit of ShinyHunters gained unprecedented urgency when the group targeted the former Boeing unit. The stolen data allegedly posed severe operational safety and security risks.
In a brief statement provided to KrebsOnSecurity, Boeing acknowledged the extortion attempts directed against its former subsidiary, Jeppesen ForeFlight, which Boeing sold in November 2025 to private equity firm Thoma Bravo for $10.55 billion.
“We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight,” a Boeing spokesperson stated. “Estamos actively reviewing the matter with the Jeppesen ForeFlight team.”

Jeppesen ForeFlight echoed this sentiment in a written statement, asserting that its defensive posture shielded core systems from damage. “Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products.”
Rey’s alleged involvement in the extortion attempt against the former Boeing unit carries unique ironic weight given evidence pointing to his father’s employment with Royal Jordanian Airlines. The airline, largely controlled by the Jordanian government, operates long-haul passenger flights on Boeing aircraft. Rey claimed on Telegram in early 2025 that his father worked as an airline pilot, though this detail could not be independently verified.
However, forensic analysis from a previous profile revealed that a shared family computer was compromised by password-stealing malware. Data harvested by the malware demonstrated that Rey’s father utilized identical credentials across multiple administrative portals for Royal Jordanian Airlines employees.
Royal Jordanian Airlines has not responded to requests for comment. Prior to publication, inquiries were also sent to Rey’s father to apprise him of his son’s alleged illegal activities. Neither of the Khaders responded. However, within hours of that outreach, Rey initiated a digital purge, deleting various social media accounts, including the Twitter/X profile he used to mock federal law enforcement agencies, the Cl0p ransomware syndicate, and corporate victims alike.
Despite scrubbing his presence from mainstream platforms, Rey’s technical blog hosted on GitHub remained active. The posts reveal an obsessive focus on the operators behind the Cl0p ransomware group. A lengthy investigative post published in March 2026 on the blog attempted to dox two Russian nationals identified as the core developers and hackers running Cl0p.
Murder-for-Hire Allegations in the Netherlands
Meanwhile, Dutch media outlets have surfaced explosive new allegations concerning Pepijn van der Stap, whose narrative of personal rehabilitation and transition into legitimate cybersecurity work had previously earned sympathetic press coverage. The Dutch daily RTL reported on September 29 that investigators suspect Van der Stap attempted to commission at least two murders to be carried out abroad.
Van der Stap had recently completed the majority of a four-year prison sentence handed down for historical data theft and extortion activities that prosecutors estimated generated between €1.5 million and €2.7 million. In an interview on September 9, Van der Stap claimed he was working as an "offensive security lead" at Neo Security, a Dutch cybersecurity firm where his responsibilities purportedly included authorized penetration testing.

Neo Security owner Benjamin Korper told Reuters that an independent forensic firm was hired to audit Neo Security’s networks and client logs following Van der Stap’s arrest. To date, investigators have found no indication that Van der Stap compromised his employer or clients. Korper confirmed that Dutch forensic teams descended on his offices on September 15—the night Van der Stap was captured during a high-risk police raid that reportedly involved the use of flash-bang grenades.
Before his initial 2023 arrest, Van der Stap maintained a dual life, working as a software engineer for Amsterdam-based cybersecurity startup Hadrian and volunteering with the Dutch Institute for Vulnerability Disclosure (DIVD), even while orchestrating extortion attacks against major global organizations.
When questioned about how the public could trust a self-described reformed hacker who maintained a double life for years, Van der Stap maintained that his actions would ultimately speak for themselves. "You can throw a bunch of nice words at someone, but you can’t convince them if they don’t want to be convinced," he said. "I’m doing what I can to repay victims, and that’s all I can do."
Franchising and Burning a Brand
Cybercriminals associated with the ShinyHunters moniker have been linked to dozens of major data breaches resulting in the exposure of billions of records, with roots tracing back to at least 2019. Security experts emphasize, however, that the individuals currently operating under the banner do not represent the original core membership—most of whom are French citizens who have faced multiple arrests and prosecutions.
Instead, ShinyHunters has evolved into a franchise model akin to the "Dread Pirate Roberts" persona from The Princess Bride, where succession is driven by law enforcement arrests rather than death, and multiple operators can claim the identity simultaneously. Sources close to the investigation indicate that the FBI is focusing heavily on a remaining network of freelance affiliates who feed stolen software-as-a-service credentials to the brand in exchange for a percentage of subsequent ransom payments.
In the wake of Van der Stap’s arrest, a Telegram chat server allegedly managed by Rey became a hub of criticism. Community members ridiculed the teenage hacker after he backed down from public threats against law enforcement and rival gangs, particularly after the primary ShinyHunters darknet portal abruptly went offline.
Commentators on underground channels accused Rey of co-opting an established cybercriminal brand after its original members were neutralized, running it into the ground for personal profit. "He bought the old forum PGP key and used it to make new Breachforum websites and Telegram channels larping as ShinyHunters to ransom companies and then sell the used data or resell his forum when he goes broke," one user observed.

A separate tracking channel on Telegram dubbed "The Battle" has spent weeks doxing and criticizing Rey and other alleged associates. Administrators of the channel noted that Rey’s decision to adopt the legacy brand proved to be a fatal miscalculation. According to community estimates, Rey generated millions in damages by allowing splinter groups to leverage the ShinyHunters identity in exchange for a cut of the ransoms.
In a prior interview with The Register, representatives for ShinyHunters claimed their decision to target the FBI was a direct response to a May 2026 public service announcement warning victims against paying ransoms. The hackers argued that the advisory undermined their business model, describing their operations as a public relations campaign designed to counter federal narratives.
The FBI’s May 15 flash notice detailed aggressive harassment tactics deployed by the group, including direct phone calls, threatening text messages to victims and their relatives, and occasional swatting incidents. The bureau also warned that the collective frequently fabricates claims regarding the possession of sensitive multimedia or compromising personal information to coerce compliance.
With Rey detained and reportedly cooperating with federal investigators, along with the arrest of key European associates, the decentralized infrastructure surrounding the modern iteration of ShinyHunters continues to unravel under coordinated international pressure.
Leave a Reply