{"id":26305,"date":"2026-10-07T11:00:32","date_gmt":"2026-10-07T19:00:32","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/10\/07\/shinyhunters-extorted-boeing-spin-off-prior-to-arrests\/"},"modified":"2026-10-07T11:00:32","modified_gmt":"2026-10-07T19:00:32","slug":"shinyhunters-extorted-boeing-spin-off-prior-to-arrests","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/10\/07\/shinyhunters-extorted-boeing-spin-off-prior-to-arrests\/","title":{"rendered":"ShinyHunters Extorted Boeing Spin-off Prior to Arrests"},"content":{"rendered":"<p>A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group <strong>ShinyHunters<\/strong> has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle \u201c<strong>Rey<\/strong>,\u201d was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company <strong>Boeing<\/strong>, which manufactures the fleet of planes used by the employer of Rey\u2019s father \u2014 <strong>Royal Jordanian Airlines<\/strong>.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74418\" style=\"width: 760px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74418\" height=\"679\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/10\/Jeppesen.png\" width=\"750\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74418\">The logo for Jeppesen ForeFlight, a business unit divested last year by the aerospace firm Boeing.<\/p>\n<\/div>\n<p>On October 3, <strong>Reuters<\/strong> <a href=\"https:\/\/www.reuters.com\/world\/middle-east\/key-shinyhunters-hacker-detained-jordan-is-cooperating-sources-say-2026-10-03\/\" rel=\"noopener\" target=\"_blank\">cited<\/a> three unnamed sources saying a suspected ShinyHunters member in Amman named <strong>Saif Al-din Khader<\/strong> was detained by Jordanian authorities and was cooperating with the FBI. KrebsOnSecurity identified Rey as Khader in <a href=\"https:\/\/krebsonsecurity.com\/2025\/11\/meet-rey-the-admin-of-scattered-lapsus-hunters\/\" rel=\"noopener\" target=\"_blank\">a November 2025 profile<\/a>, in which the young man admitted working with multiple ransomware groups.<\/p>\n<p>Rey was featured again in <a href=\"https:\/\/krebsonsecurity.com\/2026\/09\/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation\/\" rel=\"noopener\" target=\"_blank\">a September 28 exclusive<\/a> about the Dutch police arresting 24-year-old convicted cybercriminal <strong>Pepijn van der Stap<\/strong> on suspicion of aiding in data thefts and extortions by ShinyHunters. The story noted that immediately following the Dutchman\u2019s arrest on the evening of September 15, Rey assumed control over the ShinyHunters brand and boasted publicly about stealing highly sensitive data from the <strong>FBI<\/strong> and extorting the ransomware group <strong>Cl0p<\/strong>.<\/p>\n<p>Rey taunted both the FBI and Cl0p with memes posted to his longtime account on Twitter\/X, while simultaneously including images of the avatar used by Van Der Stap\u2019s former hacker alias \u201c<strong>Umbreon<\/strong>\u201d in an apparent attempt to frame the Dutchman for both hacks.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74362\" style=\"width: 637px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"size-full wp-image-74362\" height=\"843\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/09\/rey-cl0p-fbi.png\" width=\"627\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74362\">A taunting meme uploaded to Twitter\/X by Rey on Sept. 22. A giant sized version of the Pokemon character Umbreon can be seen in the bottom left.<\/p>\n<\/div>\n<p>As noted in our September 28 report, ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability (CVE-2026-35273) in <strong>PeopleSoft<\/strong>, a software-as-a-service platform from the tech giant <strong>Oracle<\/strong> that is broadly used by companies to manage hiring and human resources, benefits and payroll. Oracle quickly issued a fix for CVE-2026-35273, which ShinyHunters first began exploiting as a zero-day in June, and at the time Mandiant released web application firewall rules intended for organizations that couldn\u2019t apply the security update quickly enough.<\/p>\n<p>ShinyHunters <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks\/\" rel=\"noopener\" target=\"_blank\">told BleepingComputer in June<\/a> that the original goal behind exploiting the PeopleSoft vulnerability was to breach the FBI\u2019s own PeopleSoft database, but the hackers said those attacks were unsuccessful for some reason. In recent weeks, however, ShinyHunters <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks\/\" rel=\"noopener\" target=\"_blank\">turned to a well-known URL-encoding trick<\/a> to bypass Mandiant\u2019s suggested web application firewall rules.<\/p>\n<p>In <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft\" rel=\"noopener\" target=\"_blank\">a report<\/a> released Sept. 25, security experts at <strong>Mandiant<\/strong> and the <strong>Google Threat Intelligence Group<\/strong> (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.<\/p>\n<p>Reuters <a href=\"https:\/\/www.reuters.com\/technology\/accenture-contractor-removed-fbi-following-damaging-data-breach-sources-say-2026-10-06\/\" rel=\"noopener\" target=\"_blank\">reported October 5<\/a> that the FBI has removed a contractor at <strong>Accenture<\/strong> over their failure to patch the FBI recruitment website hacked by ShinyHunters, which exposed sensitive data on more than 5,000 FBI personnel, including each\u2019s person\u2019s unit and specialization, as well as medical and psychiatric records.<\/p>\n<h2>\u2018REY\u2019 MEANS KING, AS IN ROYAL<\/h2>\n<p>According to two sources familiar with the ShinyHunters investigation, a navigation and digital aviation unit recently divested by the global aerospace company <strong>Boeing<\/strong> was among the victims that ShinyHunters was in the process of extorting when Rey was apprehended by Jordanian authorities.<\/p>\n<p>Those sources said the FBI\u2019s investigation into ShinyHunters gained renewed urgency with the group\u2019s attempted extortion of the former Boeing unit, which allegedly included the theft of sensitive information that sources said could pose operational safety and security risks.<\/p>\n<p>In a brief statement shared with KrebsOnSecurity, Boeing acknowledged the extortion attempts by ShinyHunters, and said the incident concerned data stolen from <strong>Jeppesen ForeFlight<\/strong>, a subsidiary that Boeing <a href=\"https:\/\/www.reuters.com\/business\/aerospace-defense\/buyout-firm-thoma-bravo-nears-deal-boeings-jeppesen-unit-bloomberg-news-reports-2025-04-22\/\" rel=\"noopener\" target=\"_blank\">sold in November 2025<\/a> to the private equity firm Thoma Bravo for $10.55 billion.<\/p>\n<p>\u201cWe are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight,\u201d a Boeing spokesperson shared. \u201cWe are actively reviewing the matter with the Jeppesen ForeFlight team.\u201d<\/p>\n<p>A spokesperson for Jeppesen ForeFlight shared a written statement in response to questions, saying the company has seen no impact on their end. \u201cBased on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products.\u201d<\/p>\n<p>Rey\u2019s alleged involvement in attempting to extort the former Boeing unit is noteworthy because there is strong evidence that his father works for <strong>Royal Jordanian Airlines<\/strong>, which is mostly controlled by the Jordanian government and operates its long-haul fleet on passenger planes built by Boeing. Rey claimed on Telegram in early 2025 that his father was an airline pilot, although that could not be independently confirmed.<\/p>\n<p>However, as noted in <a href=\"https:\/\/krebsonsecurity.com\/2025\/11\/meet-rey-the-admin-of-scattered-lapsus-hunters\/\" rel=\"noopener\" target=\"_blank\">our November 2025 profile of Rey<\/a>, his family\u2019s shared computer was at one point compromised by password-stealing malware, and the data collected by that malware clearly shows Rey\u2019s father used the same credentials to log in at multiple online portals for Royal Jordanian Airlines employees.<\/p>\n<p>Royal Jordanian Airlines has not yet responded to a request for comment. In advance of our September 28 story, KrebsOnSecurity once again emailed Rey\u2019s father to seek comment and update him on his son\u2019s alleged activities. Neither of the Khaders have responded. But just hours after that request was sent, Rey began deleting his various social media accounts, including the Twitter\/X account he previously used to taunt the FBI, Cl0p, and other ShinyHunters victims.<\/p>\n<p>Rey may have nixed many of his social media profiles, but his cybersecurity blog on GitHub somehow escaped the purge, and it shows that Rey was fixated on the leaders of the Cl0p ransomware group. In March 2026, Rey\u2019s blog featured <a href=\"https:\/\/rmoskovy.github.io\/posts\/who-runs-clop-ransomware-investigation\/\" rel=\"noopener\" target=\"_blank\">a lengthy post<\/a> that identified two Russian men as the core developers and hackers behind Cl0p.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74407\" style=\"width: 758px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74407\" height=\"462\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/10\/rey-cl0p.png\" width=\"748\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74407\">Rey\u2019s blog on GitHub. This post doxes two Russian men as the core operators behind Cl0p, one of the oldest and most established ransomware groups still in operation today.<\/p>\n<\/div>\n<p><span id=\"more-74398\"><\/span><\/p>\n<h2>MURDER FOR HIRE?<\/h2>\n<p>Meanwhile, news outlets in the Netherlands reported explosive new allegations leveled at Van der Stap, whose supposed personal transformation from convicted to reformed hacker has been widely covered in the tech news media. The Dutch daily <a href=\"https:\/\/www.rtl.nl\/nieuws\/binnenland\/artikel\/5656154\/pepijn-van-der-s-verdacht-van-opdracht-geven-moorden\" rel=\"noopener\" target=\"_blank\">RTL reported on Sept. 29<\/a> that investigators suspect Van der Stap tried to orchestrate at least two murders. According to RTL, the murders were allegedly to be committed abroad, and there are indications Van der Stap gave the order for these attacks.<\/p>\n<p>Van der Stap was released from prison after serving the better part of a four year sentence for data theft and extortion activity that prosecutors said netted between \u20ac1.5 million and \u20ac2.7 million. In an interview with KrebsOnSecurity on September 9, Van der Stap described his new role as \u201coffensive security lead\u201d at the Dutch cybersecurity company <strong>Neo Security<\/strong>, saying the job involved probing client networks for security vulnerabilities.<\/p>\n<p>Neo Security\u2019s owner <strong>Benjamin Korper<\/strong> told Reuters he has hired an outside firm to investigate whether Van der Stap had hacked Neo Security or its customers, but that so far investigators have found no evidence he acted against his employer or clients. Korper said Dutch forensic investigators visited his office on September 15, the night Van der \u2060Stap was arrested in a dramatic police raid that reportedly involved <a href=\"https:\/\/www.at5.nl\/artikelen\/239945\/speciale-eenheid-rivierenbuurt-amsterdam\" rel=\"noopener\" target=\"_blank\">flash bang grenades<\/a>.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74408\" style=\"width: 776px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"size-full wp-image-74408\" height=\"628\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/10\/at5-nl.png\" width=\"766\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74408\">A screenshot of a Sept 16 story by the Dutch news outlet at5.nl, describing a police raid on Van Der Stap\u2019s residence that reportedly used flash-bang grenades.<\/p>\n<\/div>\n<p>Prior to his first arrest in 2023, Van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian, while volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD) \u2014 even as he was hacking into and extorting a number of large organizations.<\/p>\n<p>When asked in a recent interview why anyone should believe the word of a self-described \u201creformed\u201d cybercriminal who had so casually deceived countless friends, co-workers and journalists for years, Van der Stap replied that his work spoke for itself and there was nothing he could say that would convince his worst critics.<\/p>\n<p>\u201cYou can throw a bunch of nice words at someone, but you can\u2019t convince them if they don\u2019t want to be convinced,\u201d Van der Stap told KrebsOnSecurity on Sept. 9. \u201cI\u2019m doing what I can to repay victims, and that\u2019s all I can do. If someone doesn\u2019t want to believe me, then that\u2019s on them.\u201d<\/p>\n<h2>FRANCHISING AND BURNING A BRAND<\/h2>\n<p>Cybercriminals aligned with ShinyHunters have been responsible for <a href=\"https:\/\/en.wikipedia.org\/wiki\/ShinyHunters\" rel=\"noopener\" target=\"_blank\">dozens of data breaches<\/a> involving billions of stolen records, and breaches claimed by the group stretch back to at least 2019. But experts say the people recently operating behind the ShinyHunters name are not the same core members that populated the group in its early days, most of whom are French citizens who have been arrested (if not also imprisoned) on <a href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/10\/k3l0t3x.png\" rel=\"noopener\" target=\"_blank\">at least one prior occasion<\/a> for alleged cybercrime activity.<\/p>\n<p>More to the point, ShinyHunters has become something of a franchise. Think the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Dread_Pirate_Roberts\" rel=\"noopener\" target=\"_blank\">Dread Pirate Roberts<\/a> character in the 1980s cult movie classic \u201cThe Princess Bride,\u201d only succession by death is replaced with succession by arrest, and there can be multiple simultaneous Dread Pirate Robertses. Sources close to the investigation say the FBI is focusing on a remaining handful of cybercriminal freelancers or affiliates who have been feeding the group stolen credentials to various software-as-a-service (SaaS) platforms used by major companies in exchange for a cut of any data ransoms later paid by victims.<\/p>\n<p>In the days after the news broke of Van der Stap\u2019s arrest, a cybercrime-focused chat server on Telegram that was allegedly operated by Rey erupted with hot takes, with most participants heaping ridicule on the teenage hacker after he publicly backed down from threats against the FBI and Cl0p, and again when <a href=\"https:\/\/www.reuters.com\/legal\/government\/shinyhunters-website-goes-offline-after-fbi-deadline-expires-2026-09-30\/\" rel=\"noopener\" target=\"_blank\">the ShinyHunters\u2019s darknet website suddenly went offline<\/a>. Several commentators accused Rey of resurrecting the ShinyHunters brand after its core members were rounded up in France, and making a mockery of the group\u2019s name and reputation ever since.<\/p>\n<p>\u201cHe bought the old forum PGP key and used it to make new Breachforum websites and Telegram channels larping as ShinyHunters to ransom companies and then sell the used data or resell his forum when he goes broke,\u201d one member recounted.<\/p>\n<p>A relatively new Telegram channel called \u201cThe Battle\u201d has been doxing and needling Rey and other alleged ShinyHunters members for several weeks, and it has gained a considerable readership among the cybercrime communities operating on Telegram. One of the coordinators of that harassment campaign repeatedly portrayed Rey as clueless greenhorn who sought to ride the coattails of a cybercriminal brand that has long enjoyed a reputation for ruthlessly selling or publishing data stolen from victim companies who refuse to give in to extortion demands.<\/p>\n<p>\u201cRey (Saif Al-Din Khader) made a serious mistake when he started pretending to be a member of ShinyHunters,\u201d wrote the administrators of The Battle server on Telegram. \u201cThat group had already been dismantled, with many of its members either arrested or imprisoned, yet Rey still chose to use its name while carrying out his crimes. We\u2019re aware of claims that [Rey] caused over $200 million in damages and helped around 5\u20136 friend groups in the community make money by using Shiny Hunters group aliases to negotiate deals for a 25\u201330% cut over the past few months.\u201d<\/p>\n<p>In an interview with <a href=\"https:\/\/www.theregister.com\/cyber-crime\/2026\/09\/25\/shinyhunters-tells-the-reg-we-hacked-the-fbi-to-protect-our-business\/5299250\" rel=\"noopener\" target=\"_blank\">The Register<\/a>, ShinyHunters claimed they hacked the FBI to counter the agency\u2019s narrative in <a href=\"https:\/\/www.ic3.gov\/PSA\/2026\/PSA260515\" rel=\"noopener\" target=\"_blank\">a May 2026 alert<\/a> that advised victims against paying a ransom to the group, which came off looking unprofessional and capricious in the FBI\u2019s advisory.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74409\" style=\"width: 758px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74409\" height=\"742\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/10\/fbi-sh-flashnotice.png\" width=\"748\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74409\">A flash notice on ShinyHunters released by the FBI on May 15, 2026.<\/p>\n<\/div>\n<p>The public notice warned the group has been known to pursue a number of <a href=\"https:\/\/krebsonsecurity.com\/2026\/02\/please-dont-feed-the-scattered-lapsus-shiny-hunters\/\" rel=\"noopener\" target=\"_blank\">different victim harassment strategies<\/a>, from sending threatening text messages and phone calls to victims and their family members to in some cases <a href=\"https:\/\/krebsonsecurity.com\/tag\/swatting\/\" rel=\"noopener\" target=\"_blank\">swatting<\/a> victims. The FBI warned ShinyHunters members \u201cmay also falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.\u201d<\/p>\n<p>The hackers told The Register their attack on the FBI \u201cdemonstrated our technical capabilities and directly refuted the misinformation disseminated by the FBI, journalists, and industry researchers.\u201d At the same time, the group\u2019s leaders seemed to acknowledge that the FBI\u2019s warning materially harmed their prospects for convincing victims to pay, saying \u201cthis was fundamentally a public relations and marketing initiative for our business.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion groupShinyHuntershas been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle \u201cRey,\u201d was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace companyBoeing, which manufactures the fleet of planes used by the employer of Rey\u2019s fat<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10642],"tags":[],"class_list":["post-26305","post","type-post","status-publish","format-standard","hentry","category-krebs"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26305","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26305"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26305\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26305"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26305"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26305"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}