A teenager from Amman, Jordan, suspected of acting as a central figure in the prolific data theft and extortion syndicate known as ShinyHunters, has been detained by local authorities and is reportedly cooperating with the FBI to help unmask other members of the hacking collective.
Security journalism outlet KrebsOnSecurity has identified the suspect as Saif Al-din Khader, a young man who operates under the hacker handle "Rey." Investigators discovered that Khader’s apprehension coincided with a high-stakes extortion campaign targeting a business unit recently divested by the global aerospace giant Boeing. Notably, Boeing manufactures the aircraft utilized by the employer of Rey’s father, Royal Jordanian Airlines.
The detention follows a series of international law enforcement actions aimed at dismantling the modern iterations of the notorious cybercriminal brand. On October 3, Reuters cited three unnamed sources confirming that an individual named Saif Al-din Khader had been taken into custody by Jordanian authorities and was actively assisting federal investigators. This development builds upon a November 2025 profile by KrebsOnSecurity, which first linked "Rey" to Khader and noted the young hacker’s own admissions regarding his collaboration with multiple ransomware operations.
The scrutiny surrounding Rey intensified following an exclusive report on September 28 detailing the arrest of 24-year-old convicted cybercriminal Pepijn van der Stap by Dutch police. Van der Stap, a Dutch national, is suspected of aiding ShinyHunters in various data theft and extortion schemes. According to cybersecurity analysts, the moment Van der Stap was arrested on the evening of September 15, Rey seized control of the ShinyHunters moniker. The teenager immediately began publicly boasting about infiltrating the FBI and extorting the notorious Cl0p ransomware gang.

In an effort to throw investigators off track or frame his peers, Rey taunted both federal agents and the Cl0p syndicate using memes posted to his long-standing Twitter/X account. These posts prominently featured the avatar of "Umbreon," the former hacker alias utilized by Van der Stap, attempting to pin responsibility for the high-profile breaches squarely on the newly arrested Dutchman.
The technical vector behind these breaches involved the mass exploitation of a critical vulnerability, tracked as CVE-2026-35273, affecting Oracle PeopleSoft. PeopleSoft is a widely used software-as-a-service platform utilized by corporations and government agencies worldwide for human resources, recruitment, payroll, and benefits management. Oracle swiftly issued a patch after ShinyHunters began weaponizing the vulnerability as a zero-day exploit in June. Cybersecurity firm Mandiant also released temporary web application firewall (WAF) rules for organizations unable to apply the security update immediately.
While initial reports indicated that the group’s primary objective in targeting PeopleSoft was breaching the FBI’s internal databases—an effort that initially proved unsuccessful—the hackers later adapted their methods. Security reports released in late September by Mandiant and the Google Threat Intelligence Group confirmed that the syndicate had successfully utilized URL-encoding tricks to bypass defensive WAF rules. They harvested sensitive data from dozens of organizations across sectors such as healthcare, transportation, technology, higher education, agriculture, and government.
The fallout from these compromises has triggered significant administrative consequences. Reuters reported on October 5 that the FBI dismissed an Accenture contractor following revelations that a failure to patch the compromised FBI recruitment portal led to the exposure of personal and sensitive medical and psychiatric records belonging to more than 5,000 bureau personnel, including specific unit specializations.

"Rey" Means King, as in Royal
According to sources close to the ongoing international investigation, the FBI’s urgency in locating and neutralizing Rey skyrocketed when the group targeted a digital navigation and aviation unit recently divested by Boeing. The extortion attempt involved stolen data that investigators feared could pose serious operational security and safety risks.
In a statement provided to security researchers, Boeing acknowledged the extortion attempts concerning data stolen from Jeppesen ForeFlight, a subsidiary that Boeing sold in November 2025 to private equity firm Thoma Bravo for $10.55 billion. Representatives for Jeppesen ForeFlight maintained that an internal investigation revealed no operational or product impact resulting from the incident.
The connection between the suspect and the aviation industry adds a curious dynamic to the case. Evidence indicates that Khader’s father is employed by Royal Jordanian Airlines, a carrier predominantly controlled by the Jordanian government that operates long-haul flights using Boeing aircraft. Although Khader claimed on Telegram in early 2025 that his father worked as an airline pilot, that specific detail could not be independently verified. However, forensic analysis of malware logs from a compromised family computer revealed that Khader’s father utilized identical credentials to log into multiple employee portals for Royal Jordanian Airlines.
Royal Jordanian Airlines has not issued a public statement regarding the situation. Following inquiries from journalists, Rey began rapidly deleting his various social media footprints, including the Twitter/X account used to mock law enforcement and rival cybercriminal syndicates. Nevertheless, a cybersecurity blog maintained by Rey on GitHub remained active, featuring a detailed investigative post published in March 2026 that attempted to dox two Russian individuals alleged to be the core developers and operators behind the Cl0p ransomware enterprise.

Murder-for-Hire Allegations in the Netherlands
While developments unfolded in Jordan and the United States, Dutch media outlets brought to light startling new allegations concerning Pepijn van der Stap. Despite his public portrayal as a reformed hacker who had successfully transitioned into a legitimate cybersecurity career—most recently claiming the title of "offensive security lead" at Amsterdam-based Neo Security—investigators in the Netherlands revealed explosive suspicions.
According to a report by Dutch daily RTL, law enforcement suspects Van der Stap of orchestrating at least two murders intended to be carried out abroad. Van der Stap had previously served the majority of a four-year prison sentence for data theft and extortion schemes that prosecutors estimated generated between €1.5 million and €2.7 million.
The Dutch police raided Van der Stap’s residence on September 15 using flash-bang grenades, leading to his arrest. Neo Security owner Benjamin Korper told reporters that an independent firm had been hired to audit the company’s networks and determine whether the suspect had compromised internal systems or client data. Investigators reported finding no evidence of malicious activity directed against the employer, though the murder-for-hire allegations cast a dark shadow over his purported rehabilitation.
Prior to his initial 2023 conviction, Van der Stap worked as a software engineer for a cybersecurity startup while simultaneously volunteering with the Dutch Institute for Vulnerability Disclosure, all while participating in corporate extortion rings. When interviewed prior to his September arrest regarding skepticism over his rehabilitation, Van der Stap maintained that his actions toward repaying victims were the only metrics that mattered.

Franchising and Burning a Brand
Cybersecurity experts point out that the individuals operating under the ShinyHunters banner today represent a stark departure from the group’s original members, most of whom were French nationals previously arrested for cybercrime activities. Over the years, ShinyHunters has evolved into a franchise model akin to the legendary "Dread Pirate Roberts" persona, where succession is driven by law enforcement interventions rather than death.
Investigators note that federal agencies are focusing on a remaining network of freelance cybercriminals who feed stolen corporate credentials to various affiliates in exchange for a percentage of any collected ransoms. Following Van der Stap’s arrest and the sudden disappearance of the ShinyHunters darknet portal, online chat servers erupted with criticism directed at Rey. Commentators accused the teenager of purchasing legacy PGP keys and forum credentials to larp as the famous group, driving corporate extortion campaigns solely for personal financial gain while generating roughly $200 million in cumulative damages through various affiliated cells.
In recent interviews with tech publications, representatives of the modern ShinyHunters network claimed that their decision to target the FBI was a public relations maneuver intended to counter a May 2026 advisory warning victims against paying ransoms. The FBI’s flash notice had highlighted the group’s aggressive tactics, which historically ranged from threatening phone calls and text messages to targeted swatting incidents against uncooperative executives.
As investigations continue across multiple continents, the detention of Saif Al-din Khader marks a significant disruption to the decentralized network of young affiliates who sought to inherit and monetize one of the most destructive cybercriminal brands of the decade.
Leave a Reply