Skip to content
CYBERSECURITY & DATA PRIVACY

Alleged Leader of ShinyHunters Detained in Jordan and Cooperating with FBI Following High-Profile Extortion Attempt

A teenager from Amman, Jordan, suspected of operating as a key leader of the prolific and aggressive data theft and extortion syndicate known as ShinyHunters, has been detained by local authorities and is reportedly cooperating with the Federal Bureau of Investigation (FBI). According to intelligence gathered by cybersecurity journalist Brian Krebs, the suspect—who operates under the hacker handle "Rey"—was taken into custody just as the hacking collective was actively engaged in extorting a business unit recently divested by global aerospace giant Boeing.

The suspect’s arrest marks a major development in an escalating international law enforcement sweep against modern cybercrime franchises. Intriguingly, the Boeing subsidiary targeted in the extortion plot, Jeppesen ForeFlight, operates in the digital aviation space, while Boeing itself manufactures the long-haul aircraft utilized by Royal Jordanian Airlines—the employer of Rey’s father.

The Investigation Closes In on "Rey"

The first public confirmations of the arrest surfaced on October 3, when Reuters cited three confidential sources confirming that a suspected ShinyHunters member named Saif Al-din Khader had been detained in Amman and was actively assisting the FBI. This revelation aligned directly with a November 2025 profile published by KrebsOnSecurity, which had identified Khader as "Rey," a young cybercriminal who previously admitted to working alongside multiple ransomware operations.

Rey’s notoriety surged again following a September 28 investigative report regarding the Dutch police’s arrest of 24-year-old convicted cybercriminal Pepijn van der Stap. Authorities suspected van der Stap of facilitating data thefts and extortions for ShinyHunters. Immediately following van der Stap’s dramatic arrest on the evening of September 15, Rey seized control of the ShinyHunters brand, taking to social media to publicly boast about infiltrating the FBI and extorting the notorious Cl0p ransomware group.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Using a long-standing account on Twitter/X, Rey taunted both federal law enforcement and the Cl0p syndicate using memes. In a calculated maneuver, he embedded images of the avatar utilized by van der Stap’s former hacker alias, "Umbreon," appearing to frame the Dutch national for the brazen digital intrusions.

The technical foundation behind these breaches relied on the mass exploitation of a zero-day vulnerability, tracked as CVE-2026-35273, within PeopleSoft. PeopleSoft is a widely deployed software-as-a-service platform owned by technology giant Oracle, used extensively by enterprises for human resources, recruitment, benefits, and payroll management. Although Oracle swiftly patched the vulnerability after its exploitation began in June, and security firm Mandiant issued temporary web application firewall (WAF) rules, ShinyHunters managed to circumvent these defenses using standard URL-encoding bypass tricks.

Security researchers from Mandiant and the Google Threat Intelligence Group (GTIG) confirmed in a late September joint report that the group had leveraged the PeopleSoft flaw to compromise dozens of organizations across healthcare, transportation, technology, higher education, agriculture, and government sectors. The fallout extended to federal contractors, with Reuters reporting that the FBI removed an Accenture contractor after a failure to patch the recruitment portal led to the exposure of sensitive data belonging to more than 5,000 FBI personnel, including specialized unit assignments and medical files.

"Rey" Means King, As in Royal

Sources familiar with the ongoing international investigation revealed that Jeppesen ForeFlight—a digital aviation navigation unit that Boeing sold to private equity firm Thoma Bravo in November 2025 for $10.55 billion—was squarely in ShinyHunters’ crosshairs for extortion when Rey was captured. The FBI elevated the priority of the case due to concerns that the stolen operational data could pose physical security and aviation safety risks.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Boeing acknowledged the extortion threats, confirming that the incident involved data linked to its former subsidiary. In a statement, a Boeing spokesperson said the company was actively reviewing the matter alongside the Jeppesen ForeFlight team. Meanwhile, Jeppesen ForeFlight maintained that its investigation found no operational disruption or product impact.

Rey’s alleged role in targeting the aviation sector drew heightened scrutiny due to his family connections. Investigators found strong evidence that his father was employed by Royal Jordanian Airlines, a government-backed carrier operating fleet models manufactured by Boeing. Although Rey claimed on Telegram in early 2025 that his father worked as an airline pilot, security logs analyzed from malware infections on the family’s shared computer demonstrated that his father utilized identical credentials across multiple employee portals for the airline.

Following inquiries sent to the Khader family, Rey abruptly purged his social media presence, deleting the Twitter/X account used to taunt law enforcement. However, a cybersecurity blog maintained by Rey on GitHub remained active, featuring a March 2026 post that doxxed two Russian men alleged to be the core developers behind the Cl0p ransomware operation.

Murder-for-Hire Allegations Surface in the Netherlands

While the investigation into the ShinyHunters network developed in the Middle East, legal proceedings in the Netherlands revealed explosive accusations against Pepijn van der Stap. Dutch daily newspaper RTL reported on September 29 that investigators suspect van der Stap of orchestrating at least two murders to be carried out abroad.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Van der Stap had previously served the majority of a four-year prison sentence for large-scale data theft and extortion, crimes prosecutors estimated yielded between €1.5 million and €2.7 million. Following his release, he secured employment as an "offensive security lead" at Neo Security, a Dutch cybersecurity firm. Benjamin Korper, the owner of Neo Security, stated that an independent forensic audit found no evidence that van der Stap had compromised the firm or its clients, though Dutch police had raided his residence using flash-bang grenades on September 15.

Before his initial 2023 conviction, van der Stap worked as a software engineer at Amsterdam-based startup Hadrian while volunteering for the Dutch Institute for Vulnerability Disclosure (DIVD), quietly exploiting corporate networks all the while. When questioned about his credibility regarding his claimed rehabilitation, van der Stap maintained that his actions going forward would have to speak for themselves.

Franchising and Burning a Brand

Security experts note that the individuals operating under the modern ShinyHunters banner are distinct from the original French nationals who founded the group around 2019 and have since faced arrest and imprisonment. Instead, the collective has evolved into a decentralized franchise model, functioning similarly to the "Dread Pirate Roberts" persona where operatives succession-plan through arrests rather than death.

Federal investigators are primarily focusing on a network of freelance affiliates who feed stolen SaaS credentials to the group in exchange for a percentage of any ransom payouts. In the wake of van der Stap’s arrest and Rey’s detention, chat rooms on Telegram erupted with criticism from rival cybercriminals. Many accused Rey of cheapening the ShinyHunters moniker by mimicking past operations, launching amateur dark web sites, and ultimately folding under pressure from law enforcement.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The group’s recent public relations stunts—including the high-profile hack of the FBI—were allegedly executed to counter a May 2026 public advisory issued by the bureau warning victims against paying ransoms. While ShinyHunters claimed their intrusion into federal systems successfully demonstrated their technical prowess and refuted official warnings, security analysts agree that the intense law enforcement focus, international cooperation, and simultaneous arrests in Jordan and the Netherlands have severely fractured the syndicate’s operational capabilities.

Leave a Reply

Your email address will not be published. Required fields are marked *