Skip to content
CYBERSECURITY & DATA PRIVACY

Key ShinyHunters Suspect Detained in Jordan and Cooperating with the FBI Amid Escalating Extortion Probe

A teenager from Amman, Jordan, suspected of leading the prolific data theft and extortion syndicate known as ShinyHunters, has been detained by local authorities and is reportedly cooperating with the Federal Bureau of Investigation (FBI) to help identify other members of the hacking collective.

According to information obtained by KrebsOnSecurity, the suspect—who operates under the hacker handle "Rey"—was taken into custody just as ShinyHunters was in the middle of executing an aggressive extortion campaign targeting a business unit recently divested by global aerospace giant Boeing. Coincidentally, this targeted aerospace entity manufactures the fleet of aircraft utilized by the employer of Rey’s father, Royal Jordanian Airlines.

The international cybersecurity landscape shifted significantly when Reuters cited three unnamed sources confirming that a suspected ShinyHunters operative in Amman named Saif Al-din Khader had been detained by Jordanian law enforcement and was actively assisting the FBI. KrebsOnSecurity had previously identified Rey as Khader in an investigative profile published in November 2025, during which the young man openly admitted to collaborating with multiple ransomware operations.

Rey’s name surfaced again in an exclusive report published on September 28 detailing the arrest of 24-year-old Dutch convicted cybercriminal Pepijn van der Stap by Dutch police. Van der Stap was apprehended on suspicion of facilitating data thefts and extortion schemes orchestrated by ShinyHunters. Immediately following the dramatic raid on the Dutchman’s residence on the evening of September 15, Rey seized operational control of the ShinyHunters brand, publicly boasting about breaching sensitive systems belonging to the FBI and extorting the notorious ransomware organization Cl0p.

In an effort to deflect law enforcement attention and complicate ongoing investigations, Rey taunted both the FBI and Cl0p by publishing a series of memes on his long-standing Twitter/X account. These posts incorporated images of the avatar previously utilized by Van der Stap under his former hacker alias, "Umbreon," in an apparent framing attempt designed to pin the high-profile hacks directly on the Dutch national.

As detailed in previous security briefings, ShinyHunters gained unauthorized access to the FBI’s recruitment infrastructure and other corporate targets by aggressively exploiting a zero-day vulnerability tracked as CVE-2026-35273. This critical flaw resided within PeopleSoft, a widely deployed software-as-a-service (SaaS) platform from Oracle utilized by enterprises globally to manage recruitment, human resources, payroll, and employee benefits.

Oracle swiftly issued security patches after ShinyHunters began weaponizing the vulnerability in June. Simultaneously, cybersecurity firm Mandiant released specialized web application firewall (WAF) rules to protect organizations unable to immediately deploy Oracle’s security updates.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

While ShinyHunters initially told industry media outlets in June that their primary objective was to infiltrate the FBI’s internal PeopleSoft database—an initial attempt that reportedly failed—the hackers eventually adapted their tactics. In subsequent weeks, the collective bypassed Mandiant’s defensive firewall rules by employing a well-known URL-encoding evasion technique.

A comprehensive threat intelligence report released by Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters carried out a mass exploitation campaign targeting the PeopleSoft vulnerability. This wave of attacks compromised data across dozens of organizations operating in diverse sectors, including higher education, technology, healthcare, agriculture, transportation, and government agencies.

Further compounding the fallout, Reuters reported that the FBI terminated a contractor working through Accenture following revelations of a severe security lapse. The contractor failed to apply patches to the FBI recruitment portal compromised by ShinyHunters, resulting in the exposure of sensitive records detailing more than 5,000 personnel, including individual unit specializations alongside confidential medical and psychiatric records.

"Rey" Means King, as in Royal

Investigators close to the matter revealed that among the victims actively being extorted by ShinyHunters at the time of Rey’s arrest was a navigation and digital aviation unit recently divested by Boeing. The involvement of this specific aviation subsidiary lent immediate urgency to the FBI’s investigation, as the stolen data carried potential implications for operational safety and security.

In a brief statement provided to KrebsOnSecurity, Boeing acknowledged the attempted extortion by the threat actor, confirming that the incident centered on data linked to Jeppesen ForeFlight. Boeing previously sold this specialized subsidiary in November 2025 to private equity firm Thoma Bravo for $10.55 billion.

"We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight," a Boeing spokesperson stated, adding that the corporation is actively reviewing the situation alongside the Jeppesen ForeFlight team.

Representatives for Jeppesen ForeFlight issued a written response maintaining that their day-to-day operations remained uncompromised. "Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products," the company affirmed.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Rey’s alleged role in targeting the former Boeing subsidiary carries additional weight due to compelling evidence indicating his father is employed by Royal Jordanian Airlines. The airline is primarily government-controlled and operates long-haul passenger fleets built exclusively by Boeing. Although Rey claimed on Telegram early last year that his father worked as an airline pilot—a detail that could not be independently verified—digital forensic evidence told a clearer story.

During an earlier profile of Rey, researchers analyzed data recovered from his family’s shared computer after it was infected by password-stealing malware. The compromised logs showed Rey’s father utilizing identical authentication credentials across multiple online employee portals belonging to Royal Jordanian Airlines.

Royal Jordanian Airlines did not immediately respond to requests for comment regarding the incident. Prior to the September 28 publication, inquiries were sent directly to Rey’s father to apprise him of his son’s cybercriminal activities. Neither of the Khaders replied; however, within hours of that outreach, Rey began systematically scrubbing his digital footprint, deleting numerous social media profiles—including the Twitter/X account used to mock law enforcement and rival cyber syndicates.

Despite the social media purge, Rey’s cybersecurity blog hosted on GitHub remained active, revealing a persistent obsession with the leadership of the Cl0p ransomware operation. A lengthy post published on the blog in March doled out detailed investigative claims doxing two Russian nationals alleged to be the core developers and masterminds behind Cl0p.

Murder-for-Hire Allegations Surface in the Netherlands

Meanwhile, legal proceedings in the Netherlands introduced explosive new allegations against Van der Stap, whose narrative of rehabilitation following a previous conviction had garnered considerable media attention. Dutch daily newspaper RTL reported that investigators suspect Van der Stap attempted to orchestrate at least two murders. According to the reports, these planned attacks were directed to take place abroad, and authorities uncovered indications that Van der Stap issued the direct orders.

Van der Stap had recently completed the majority of a four-year prison sentence for data theft and extortion operations that prosecutors estimated netted between 1.5 million and 2.7 million euros. Speaking with KrebsOnSecurity shortly before his arrest, Van der Stap described his professional reintegration as an "offensive security lead" at Dutch cybersecurity firm Neo Security, claiming his responsibilities included vulnerability assessments for corporate clients.

Neo Security owner Benjamin Korper told reporters that he hired an independent forensic firm to investigate whether Van der Stap had compromised internal systems or client networks, though no evidence of malicious activity directed against the firm has been uncovered thus far. Korper confirmed that Dutch law enforcement officers visited his office on the night of September 15 during the tactical raid that led to Van der Stap’s arrest.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Before his initial arrest in 2023, Van der Stap worked as a software engineer at Amsterdam-based security startup Hadrian while volunteering with the Dutch Institute for Vulnerability Disclosure (DIVD), all while secretly infiltrating and extorting major corporate entities. When questioned about how the public could trust a self-described reformed hacker who deceived colleagues and researchers for years, Van der Stap maintained that his actions would ultimately speak for themselves.

"You can throw a bunch of nice words at someone, but you can’t convince them if they don’t want to be convinced," Van der Stap remarked. "I’m doing what I can to repay victims, and that’s all I can do. If someone doesn’t want to believe me, then that’s on them."

Franchising and Burning a Brand

Cybercriminals operating under the ShinyHunters banner have been linked to dozens of major data breaches spanning billions of stolen records, with campaigns dating back to at least 2019. However, security researchers emphasize that the individuals controlling the ShinyHunters moniker today bear little relation to the original core members—mostly French nationals who have faced arrest and imprisonment for prior cyber offenses.

In practice, ShinyHunters has evolved into an illicit franchise model. Analysts compare the dynamic to the fictional "Dread Pirate Roberts" from cultural lore, where succession is driven by law enforcement arrests rather than death, allowing multiple individuals to wield the brand simultaneously. Investigators note that current enforcement efforts focus on a network of freelance cybercriminals and affiliates who supply stolen SaaS platform credentials to the group in exchange for a percentage of subsequent ransom payments.

Following the announcement of Van der Stap’s arrest, underground Telegram channels allegedly operated by Rey became arenas for intense backlash. Syndicate participants ridiculed the teenager after he retreated from public threats against the FBI and Cl0p, particularly as the primary ShinyHunters darknet portal abruptly went offline. Critics accused Rey of commercializing the dormant brand name for personal financial gain following the arrest of the original French operators.

"He bought the old forum PGP key and used it to make new Breachforum websites and Telegram channels larping as ShinyHunters to ransom companies and then sell the used data or resell his forum when he goes broke," one forum participant noted.

A specialized Telegram channel dubbed "The Battle" has systematically doxed and targeted Rey alongside other alleged ShinyHunters associates, gaining significant traction within the underground cybercrime community. Administrators of the channel characterized Rey as an inexperienced newcomer attempting to capitalize on a notorious brand known for ruthlessly punishing uncooperative victim organizations.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

"Rey made a serious mistake when he started pretending to be a member of ShinyHunters," administrators of The Battle wrote. "That group had already been dismantled… yet Rey still chose to use its name while carrying out his crimes. We’re aware of claims that he caused over $200 million in damages and helped around five to six friend groups make money by using ShinyHunters group aliases to negotiate deals for a 25 to 30 percent cut over the past few months."

In an interview with industry publication The Register, representatives for the active iteration of ShinyHunters claimed their intrusion into FBI infrastructure was designed to counter the agency’s advisory published in May. That public safety alert strongly discouraged victims from submitting ransom payments and detailed the group’s aggressive harassment tactics, which have historically included threatening phone calls, text messages, and swatting incidents directed at victims and their families.

While the hackers asserted that their breach of federal systems served to "demonstrate our technical capabilities and directly refute misinformation," they also conceded that the FBI’s public warnings severely damaged their negotiating leverage, acknowledging that the digital intrusion functioned primarily as a high-stakes public relations maneuver for their extortion business.

Leave a Reply

Your email address will not be published. Required fields are marked *