Unmasking "Rey": The Fall of the Teenage Mastermind Behind the ShinyHunters Extortion Franchise

Main page › Cyber Security & Privacy › Unmasking "Rey": The Fall of…
From ZizzMedia, the free news encyclopedia
Unmasking "Rey": The Fall of the Teenage Mastermind Behind the ShinyHunters Extortion Franchise
Unmasking "Rey": The Fall of the Teenage Mastermind Behind the ShinyHunters Extortion Franchise
Published: 7 October 2026
Author: Pevita Pearce
Category: Cyber Security & Privacy
Read time: 7 min read
Words: 1,332

Executive Overview

The sprawling, volatile ecosystem of global cybercrime has suffered yet another seismic shock. A teenager operating out of Amman, Jordan, under the hacker handle “Rey” has been detained by local authorities and is reportedly cooperating extensively with the Federal Bureau of Investigation (FBI). Identified by investigative cybersecurity journalists as Saif Al-din Khader, this young operative is believed to have assumed control of the notorious data theft and extortion collective known as ShinyHunters.

Khader’s capture occurred precisely as the syndicate was deep into an aggressive extortion campaign targeting a recently divested business unit of global aerospace titan Boeing. This development adds an ironic personal dimension to the saga: investigators note that Khader’s father is employed by Royal Jordanian Airlines, a carrier whose long-haul passenger fleet relies entirely on Boeing aircraft.

The takedown of “Rey” follows a tumultuous chain of international law enforcement actions, including the high-profile Dutch police raid that netted 24-year-old cybercriminal Pepijn van der Stap. Together, these events lay bare the modern reality of cybercrime syndicates: once centralized hacker crews have mutated into decentralized franchises. In this new landscape, cybercriminal monikers operate like corporate brands—bought, sold, and co-opted by freelance actors operating across loose digital confederations.


Detailed Chronology: From Zero-Day Exploits to International Arrests

The Oracle PeopleSoft Campaign

The current chapter of the ShinyHunters saga began in earnest in June, when the group started exploiting a critical zero-day vulnerability (tracked as CVE-2026-35273) within Oracle PeopleSoft, a widely deployed software-as-a-service (SaaS) platform utilized by global enterprises for human resources, recruitment, payroll, and benefits management.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Oracle quickly issued a security patch, while Mandiant and other threat intelligence firms rushed out web application firewall (WAF) rules to protect organizations unable to immediately update their servers. However, the hackers adapted quickly. In subsequent weeks, ShinyHunters utilized a well-known URL-encoding trick to successfully bypass Mandiant’s WAF defenses, executing a mass-exploitation campaign that compromised systems across higher education, healthcare, technology, agriculture, transportation, and government sectors.

Targeting the FBI and the Accenture Fallout

According to statements made by the hackers to technology outlets like BleepingComputer and The Register, the primary initial motivation behind exploiting the PeopleSoft flaw was to breach the FBI’s own recruitment database. While initial attempts against the bureau’s core infrastructure proved difficult, the campaign ultimately succeeded in penetrating peripheral portals.

The breach of the FBI recruitment website exposed sensitive files detailing personal information, unit specializations, and even confidential medical and psychiatric records for more than 5,000 FBI personnel. The fallout was immediate: investigative reports confirmed that the FBI subsequently terminated an Accenture contractor over failures to properly patch the vulnerable recruitment portal.

The FBI responded on May 15 with an official Flash Notice advising organizations never to pay ransoms demanded by the group. The bureau’s advisory highlighted ShinyHunters’ aggressive harassment tactics—which include direct phone calls, threatening text messages, swatting incidents, and the false claims of possessing compromising personal media.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

According to statements given by the threat actors to The Register, the hack on the FBI was explicitly executed as a "public relations and marketing initiative" designed to undermine the bureau’s credibility after the advisory warned victims against negotiating.

The Arrest of Pepijn van der Stap

The pressure on the network intensified significantly on September 15. In a dramatic police raid in Amsterdam utilizing flash-bang grenades, Dutch law enforcement arrested 24-year-old Pepijn van der Stap (formerly known by the hacker alias “Umbreon”). Van der Stap had recently cultivated a public image as a reformed criminal, securing a position as an "offensive security lead" at a Dutch cybersecurity firm named Neo Security.

However, investigators allege that Van der Stap’s reformation was a facade. Dutch media outlets reported explosive allegations that investigators suspect Van der Stap of attempting to orchestrate at least two murders abroad. Simultaneously, cybercrime analysts linked him to ongoing data thefts conducted under the ShinyHunters banner.

Rey’s Final Gambit and Downfall

Immediately following Van der Stap’s arrest, "Rey" (Saif Al-din Khader) stepped into the power vacuum, seizing control of the ShinyHunters brand assets. In a brazen attempt to frame his detained contemporary, Rey launched a campaign on Twitter/X, posting taunting memes directed at both the FBI and the rival ransomware group Cl0p. The posts prominently featured images of Umbreon, Van der Stap’s former avatar, in an explicit attempt to pin the latest hacks on the Dutchman.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Rey’s control proved short-lived. Following inquiries sent by journalists to his family home in Amman—coupled with mounting international law enforcement pressure—Rey began frantically purging his social media footprint. By early October, Jordanian authorities had detained Khader, and reports surfaced confirming his active cooperation with the FBI to map out the remaining nodes of the ShinyHunters enterprise.


Supporting Context & Metrics: The "Dread Pirate Roberts" Cyber Model

Security analysts emphasize that the individuals operating under the ShinyHunters banner today bear little resemblance to the group’s original core members—mostly French citizens who were rounded up and prosecuted in prior international sweeps. Instead, ShinyHunters has evolved into a franchise model.

[Original French Core] ---> (Arrested / Imprisoned)
                                      |
                                      v
[Decentralized Freelance Network] ---> (Supplies stolen SaaS credentials)
                                      |
                                      v
[Franchise Operators ("Rey")] --------> (Co-opts brand, executes extortions for a 25-30% cut)

This structural shift mirrors the fictional "Dread Pirate Roberts" from The Princess Bride: when one leader is arrested or killed, another steps into the role, keeping the brand alive. According to intelligence gathered by investigative trackers and chat servers on Telegram, Rey operated as a freelance coordinator. He allegedly purchased old PGP keys and forum credentials, using them to launch clone websites and Telegram channels. Over the preceding months, Rey reportedly helped five to six cybercriminal cell networks negotiate extortion demands in exchange for a 25% to 30% cut of the illicit proceeds, accumulating damages estimated by community trackers to exceed $200 million.

Despite purging his social media presence, Rey’s GitHub-hosted cybersecurity blog survived the purge. The archive reveals a deep obsession with rival syndicates, including a lengthy investigative post published in March that successfully doxed two Russian nationals accused of running the elite Cl0p ransomware operation.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Official Statements and Corporate Responses

The multi-pronged extortion campaign has triggered formal responses from major corporate entities caught in the crosshairs:

  • Boeing: Acknowledged awareness of threat actor claims regarding data stolen from Jeppesen ForeFlight, a digital aviation and navigation unit that Boeing sold to private equity firm Thoma Bravo in November 2025 for $10.55 billion. Boeing confirmed it is actively reviewing the incident alongside the Jeppesen ForeFlight team.
  • Jeppesen ForeFlight: Issued a formal statement maintaining that proactive security postures insulated the company from disaster: "Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."
  • Neo Security: Founder Benjamin Korper confirmed that external auditors were brought in to investigate whether Pepijn van der Stap compromised internal networks or client environments. While investigators found no evidence of insider sabotage against Neo Security clients, Korper acknowledged the severe disruption caused by the mid-September flash-bang raid on Van der Stap’s residence.

Future Outlook

The simultaneous neutralization of Pepijn van der Stap in Amsterdam and Saif Al-din Khader in Amman marks a critical turning point in the disruption of modern ransomware and extortion franchises. By targeting both the technical facilitators of credential theft and the young operational middlemen who co-opt legendary hacker brands for quick financial gains, international law enforcement agencies are steadily dismantling the infrastructure supporting mass data extortion.

Nevertheless, the structural vulnerabilities remain. As long as software-as-a-service platforms like Oracle PeopleSoft contain exploitable zero-day flaws, and as long as corporate networks rely on fragile credential management systems, decentralized cybercrime cells will continue to find willing recruits. The fall of "Rey" and "Umbreon" proves that while individual kingpins can be boxed in by global task forces, the franchise model of cybercrime will continue to regenerate until systemic software security catches up with the ingenuity of digital extortionists.

Related News

Leave a Reply / Join Discussion

Your email address will not be published. Required fields are marked with *