A teen from Amman, Jordan suspected of main the prolific knowledge theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to establish different members of the hacking gang. KrebsOnSecurity has realized that the suspect, who makes use of the hacker deal with “Rey,” was detained as ShinyHunters was within the strategy of extorting a enterprise unit not too long ago divested by the worldwide aerospace firm Boeing, which manufactures the fleet of planes utilized by the employer of Rey’s father — Royal Jordanian Airways.
The emblem for Jeppesen ForeFlight, a enterprise unit divested final yr by the aerospace agency Boeing.
On October 3, Reuters cited three unnamed sources saying a suspected ShinyHunters member in Amman named Saif Al-din Khader was detained by Jordanian authorities and was cooperating with the FBI. KrebsOnSecurity recognized Rey as Khader in a November 2025 profile, by which the younger man admitted working with a number of ransomware teams.
Rey was featured once more in a September 28 unique concerning the Dutch police arresting 24-year-old convicted cybercriminal Pepijn van der Stap on suspicion of aiding in knowledge thefts and extortions by ShinyHunters. The story famous that instantly following the Dutchman’s arrest on the night of September 15, Rey assumed management over the ShinyHunters model and boasted publicly about stealing extremely delicate knowledge from the FBI and extorting the ransomware group Cl0p.
Rey taunted each the FBI and Cl0p with memes posted to his longtime account on Twitter/X, whereas concurrently together with photos of the avatar utilized by Van Der Stap’s former hacker alias “Umbreon” in an obvious try to border the Dutchman for each hacks.
A taunting meme uploaded to Twitter/X by Rey on Sept. 22. A large sized model of the Pokemon character Umbreon might be seen within the backside left.
As famous in our September 28 report, ShinyHunters gained entry to the FBI web site and different victims by exploiting a vulnerability (CVE-2026-35273) in PeopleSoft, a software-as-a-service platform from the tech big Oracle that’s broadly utilized by corporations to handle hiring and human assets, advantages and payroll. Oracle rapidly issued a repair for CVE-2026-35273, which ShinyHunters first started exploiting as a zero-day in June, and on the time Mandiant launched internet utility firewall guidelines supposed for organizations that couldn’t apply the safety replace rapidly sufficient.
ShinyHunters advised BleepingComputer in June that the unique aim behind exploiting the PeopleSoft vulnerability was to breach the FBI’s personal PeopleSoft database, however the hackers stated these assaults had been unsuccessful for some motive. In latest weeks, nevertheless, ShinyHunters turned to a widely known URL-encoding trick to bypass Mandiant’s prompt internet utility firewall guidelines.
In a report launched Sept. 25, safety consultants at Mandiant and the Google Menace Intelligence Group (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal knowledge from dozens of techniques throughout a spread of industries, together with larger schooling, expertise, healthcare, agriculture, transportation and authorities.
Reuters reported October 5 that the FBI has eliminated a contractor at Accenture over their failure to patch the FBI recruitment web site hacked by ShinyHunters, which uncovered delicate knowledge on greater than 5,000 FBI personnel, together with every’s individual’s unit and specialization, in addition to medical and psychiatric data.
‘REY’ MEANS KING, AS IN ROYAL
Based on two sources aware of the ShinyHunters investigation, a navigation and digital aviation unit not too long ago divested by the worldwide aerospace firm Boeing was among the many victims that ShinyHunters was within the strategy of extorting when Rey was apprehended by Jordanian authorities.
These sources stated the FBI’s investigation into ShinyHunters gained renewed urgency with the group’s tried extortion of the previous Boeing unit, which allegedly included the theft of delicate data that sources stated might pose operational security and safety dangers.
In a quick assertion shared with KrebsOnSecurity, Boeing acknowledged the extortion makes an attempt by ShinyHunters, and stated the incident involved knowledge stolen from Jeppesen ForeFlight, a subsidiary that Boeing bought in November 2025 to the non-public fairness agency Thoma Bravo for $10.55 billion.
“We’re conscious of claims by a risk actor relating to knowledge allegedly related to Boeing and our former subsidiary Jeppesen ForeFlight,” a Boeing spokesperson shared. “We’re actively reviewing the matter with the Jeppesen ForeFlight workforce.”
A spokesperson for Jeppesen ForeFlight shared a written assertion in response to questions, saying the corporate has seen no affect on their finish. “Primarily based on our investigation so far into this declare and proactive safety posture, there was no affect to our operations or merchandise.”
Rey’s alleged involvement in making an attempt to extort the previous Boeing unit is noteworthy as a result of there may be sturdy proof that his father works for Royal Jordanian Airways, which is generally managed by the Jordanian authorities and operates its long-haul fleet on passenger planes constructed by Boeing. Rey claimed on Telegram in early 2025 that his father was an airline pilot, though that would not be independently confirmed.
Nevertheless, as famous in our November 2025 profile of Rey, his household’s shared pc was at one level compromised by password-stealing malware, and the info collected by that malware clearly exhibits Rey’s father used the identical credentials to log in at a number of on-line portals for Royal Jordanian Airways staff.
Royal Jordanian Airways has not but responded to a request for remark. Prematurely of our September 28 story, KrebsOnSecurity as soon as once more emailed Rey’s father to hunt remark and replace him on his son’s alleged actions. Neither of the Khaders have responded. However simply hours after that request was despatched, Rey started deleting his varied social media accounts, together with the Twitter/X account he beforehand used to taunt the FBI, Cl0p, and different ShinyHunters victims.
Rey might have nixed lots of his social media profiles, however his cybersecurity weblog on GitHub one way or the other escaped the purge, and it exhibits that Rey was fixated on the leaders of the Cl0p ransomware group. In March 2026, Rey’s weblog featured a prolonged publish that recognized two Russian males because the core builders and hackers behind Cl0p.
Rey’s weblog on GitHub. This publish doxes two Russian males because the core operators behind Cl0p, one of many oldest and most established ransomware teams nonetheless in operation immediately.
MURDER FOR HIRE?
In the meantime, information shops within the Netherlands reported explosive new allegations leveled at Van der Stap, whose supposed private transformation from convicted to reformed hacker has been extensively lined within the tech information media. The Dutch every day RTL reported on Sept. 29 that investigators suspect Van der Stap tried to orchestrate not less than two murders. Based on RTL, the murders had been allegedly to be dedicated overseas, and there are indications Van der Stap gave the order for these assaults.
Van der Stap was launched from jail after serving the higher a part of a 4 yr sentence for knowledge theft and extortion exercise that prosecutors stated netted between €1.5 million and €2.7 million. In an interview with KrebsOnSecurity on September 9, Van der Stap described his new function as “offensive safety lead” on the Dutch cybersecurity firm Neo Safety, saying the job concerned probing shopper networks for safety vulnerabilities.
Neo Safety’s proprietor Benjamin Korper advised Reuters he has employed an outdoor agency to research whether or not Van der Stap had hacked Neo Safety or its clients, however that to this point investigators have discovered no proof he acted in opposition to his employer or purchasers. Korper stated Dutch forensic investigators visited his workplace on September 15, the evening Van der Stap was arrested in a dramatic police raid that reportedly concerned flash bang grenades.
A screenshot of a Sept 16 story by the Dutch information outlet at5.nl, describing a police raid on Van Der Stap’s residence that reportedly used flash-bang grenades.
Previous to his first arrest in 2023, Van der Stap was working as a software program engineer on the Amsterdam-based cybersecurity startup Hadrian, whereas volunteering on the Dutch Institute for Vulnerability Disclosure (DIVD) — whilst he was hacking into and extorting quite a lot of giant organizations.
When requested in a latest interview why anybody ought to imagine the phrase of a self-described “reformed” cybercriminal who had so casually deceived numerous mates, co-workers and journalists for years, Van der Stap replied that his work spoke for itself and there was nothing he might say that may persuade his worst critics.
“You may throw a bunch of good phrases at somebody, however you possibly can’t persuade them in the event that they don’t need to be satisfied,” Van der Stap advised KrebsOnSecurity on Sept. 9. “I’m doing what I can to repay victims, and that’s all I can do. If somebody doesn’t need to imagine me, then that’s on them.”
FRANCHISING AND BURNING A BRAND
Cybercriminals aligned with ShinyHunters have been accountable for dozens of knowledge breaches involving billions of stolen data, and breaches claimed by the group stretch again to not less than 2019. However consultants say the individuals not too long ago working behind the ShinyHunters title will not be the identical core members that populated the group in its early days, most of whom are French residents who’ve been arrested (if not additionally imprisoned) on not less than one prior event for alleged cybercrime exercise.
Extra to the purpose, ShinyHunters has develop into one thing of a franchise. Suppose the Dread Pirate Roberts character within the Eighties cult film basic “The Princess Bride,” solely succession by demise is changed with succession by arrest, and there might be a number of simultaneous Dread Pirate Robertses. Sources near the investigation say the FBI is specializing in a remaining handful of cybercriminal freelancers or associates who’ve been feeding the group stolen credentials to varied software-as-a-service (SaaS) platforms utilized by main corporations in alternate for a lower of any knowledge ransoms later paid by victims.
Within the days after the information broke of Van der Stap’s arrest, a cybercrime-focused chat server on Telegram that was allegedly operated by Rey erupted with scorching takes, with most individuals heaping ridicule on the teenage hacker after he publicly backed down from threats in opposition to the FBI and Cl0p, and once more when the ShinyHunters’s darknet web site all of a sudden went offline. A number of commentators accused Rey of resurrecting the ShinyHunters model after its core members had been rounded up in France, and making a mockery of the group’s title and repute ever since.
“He purchased the previous discussion board PGP key and used it to make new Breachforum web sites and Telegram channels larping as ShinyHunters to ransom corporations after which promote the used knowledge or resell his discussion board when he goes broke,” one member recounted.
A comparatively new Telegram channel known as “The Battle” has been doxing and needling Rey and different alleged ShinyHunters members for a number of weeks, and it has gained a substantial readership among the many cybercrime communities working on Telegram. One of many coordinators of that harassment marketing campaign repeatedly portrayed Rey as clueless greenhorn who sought to trip the coattails of a cybercriminal model that has lengthy loved a repute for ruthlessly promoting or publishing knowledge stolen from sufferer corporations who refuse to present in to extortion calls for.
“Rey (Saif Al-Din Khader) made a critical mistake when he began pretending to be a member of ShinyHunters,” wrote the directors of The Battle server on Telegram. “That group had already been dismantled, with lots of its members both arrested or imprisoned, but Rey nonetheless selected to make use of its title whereas finishing up his crimes. We’re conscious of claims that [Rey] induced over $200 million in damages and helped round 5–6 buddy teams locally make cash through the use of Shiny Hunters group aliases to barter offers for a 25–30% lower over the previous few months.”
In an interview with The Register, ShinyHunters claimed they hacked the FBI to counter the company’s narrative in a Might 2026 alert that suggested victims in opposition to paying a ransom to the group, which got here off trying unprofessional and capricious within the FBI’s advisory.
A flash discover on ShinyHunters launched by the FBI on Might 15, 2026.
The general public discover warned the group has been recognized to pursue quite a lot of totally different sufferer harassment methods, from sending threatening textual content messages and cellphone calls to victims and their members of the family to in some circumstances swatting victims. The FBI warned ShinyHunters members “may falsely declare to have delicate or compromising data, together with embarrassing images or movies of victims, which often don’t exist.”
The hackers advised The Register their assault on the FBI “demonstrated our technical capabilities and instantly refuted the misinformation disseminated by the FBI, journalists, and business researchers.” On the identical time, the group’s leaders appeared to acknowledge that the FBI’s warning materially harmed their prospects for convincing victims to pay, saying “this was basically a public relations and advertising initiative for our enterprise.”









