Executive Overview
The landscape of international cybercrime has long operated on shifting alliances, pseudonymous handles, and fluid criminal networks. However, the recent detention of a teenager in Amman, Jordan—operating under the alias “Rey”—has exposed a dramatic, high-stakes chapter in the ongoing war between global law enforcement and the data extortion collective known as ShinyHunters.
Identified by cybersecurity researchers as Saif Al-din Khader, the young suspect was detained by Jordanian authorities and is reportedly cooperating with the Federal Bureau of Investigation (FBI). This pivotal arrest occurred while Khader and his network were actively attempting to extort a recently divested business unit of global aerospace giant Boeing. Intriguingly, Khader’s father works for Royal Jordanian Airlines, a carrier whose long-haul fleet relies heavily on Boeing aircraft, adding a stark layer of geographical and familial irony to an already labyrinthine investigation.
The takedown of “Rey” is not an isolated event; it coincides with a broader, coordinated international crackdown. Dutch law enforcement recently apprehended 24-year-old convicted cybercriminal Pepijn van der Stap (formerly known by the hacker alias “Umbreon”), who is suspected of facilitating ShinyHunters’ data thefts. Adding a chilling twist to the Dutch investigation, local media reports indicate that Van der Stap is also suspected by prosecutors of orchestrating murder-for-hire plots abroad.
Together, these developments underscore a fundamental evolution in cybercrime: the transformation of notorious hacker collectives from centralized syndicates into decentralized franchises. Much like the literary concept of the "Dread Pirate Roberts," modern hacker brands are continually resurrected, co-opted, and burned by ambitious newcomers seeking quick profits and notoriety. This comprehensive report explores the timeline of the ShinyHunters resurgence, the vulnerabilities that enabled high-profile breaches—including an infiltration of the FBI’s own recruitment portal—and the chaotic underworld dynamics that ultimately brought Rey and his associates down.
Detailed Chronology of the ShinyHunters Resurgence
To understand how a teenager from Amman came to rattle the highest levels of American law enforcement and global aerospace, one must trace the recent trajectory of the ShinyHunters brand through the summer and fall of 2026.
The Zero-Day Exploitation and the FBI Infiltration
The technical foundation of ShinyHunters’ 2026 campaign relied on the mass exploitation of PeopleSoft, a software-as-a-service (SaaS) platform from Oracle widely deployed across corporate and government sectors for human resources, payroll, and recruitment management. Tracked as CVE-2026-35273, the vulnerability was first weaponized as a zero-day by the group in June 2026.

While Oracle swiftly issued a patch and security firm Mandiant released stopgap web application firewall (WAF) rules, ShinyHunters bypassed these defenses using sophisticated URL-encoding tricks. Threat intelligence teams from Google and Mandiant confirmed that the group used this exploit to harvest data from dozens of organizations spanning healthcare, higher education, technology, and government.
Crucially, the hackers admitted to BleepingComputer in June that their primary target was the FBI’s internal PeopleSoft database. While that specific database breach proved unsuccessful, the group successfully compromised an FBI recruitment website. This oversight exposed sensitive data on more than 5,000 FBI personnel, including specializations, unit assignments, and confidential medical and psychiatric records. Consequently, the FBI took the rare step of removing an Accenture contractor responsible for managing and patching the compromised portal.
The Arrest of Pepijn van der Stap and the Rise of "Rey"
On September 15, 2026, Dutch police executed a dramatic flash-bang raid in Amsterdam, arresting Pepijn van der Stap. Widely covered in tech media as a "reformed hacker" who had transitioned to a role as an offensive security lead at Dutch firm Neo Security, Van der Stap was actually harboring a dark double life.
Immediately following Van der Stap’s arrest, Saif Al-din Khader (“Rey”) seized control of the defunct ShinyHunters brand identity. Recognizing a vacuum, Rey assumed leadership of the group’s public channels and launched an audacious disinformation and extortion campaign. He publicly boasted about stealing FBI data and extorting the notorious Cl0p ransomware syndicate.
In a calculated attempt to frame Van der Stap, Rey published mocking memes on Twitter/X that prominently featured "Umbreon," the Pokémon avatar previously used by Van der Stap during his early cybercriminal exploits. However, Rey’s bravado proved short-lived. Following mounting pressure from international law enforcement—and automated inquiries from investigative journalists—Rey rapidly purged his social media accounts, though his technical blog on GitHub documenting Cl0p operators remained online.
The Boeing Extortion and Amman Detention
According to sources familiar with the investigation, the FBI’s pursuit of Rey gained critical momentum when the teenager targeted Jeppesen ForeFlight, a digital aviation and navigation unit previously owned by Boeing. The extortion attempt involved sensitive stolen data that authorities feared posed legitimate operational safety and security risks.

By October 3, 2026, Reuters confirmed that Jordanian authorities had detained Khader in Amman. Sources indicated that he quickly began cooperating with the FBI, providing critical intelligence on the remaining decentralized cells operating under the ShinyHunters banner.
Supporting Context & Metrics: The Franchise Model of Cybercrime
The modern iteration of ShinyHunters bears little resemblance to the original core group of French nationals who operated under the banner between 2019 and 2023, most of whom were eventually rounded up by European law enforcement. Today, the name functions as a decentralized franchise.
The "Dread Pirate Roberts" Phenomenon of Cybercrime
In this ecosystem, successful monikers and PGP keys are bought, sold, or stolen by younger, less disciplined operators. Security analysts describe a loose network of cybercriminal freelancers who harvest SaaS platform credentials and sell them to regional syndicates or set up independent extortion rings, kicking back a 25% to 30% cut to the brand’s current controller.
[SaaS Platform Vulnerabilities (e.g., Oracle PeopleSoft)]
│
▼
[Freelance Credential Harvesters]
│
┌──────────────────┴──────────────────┐
▼ ▼
[Independent Extortion] [Franchise Brand Co-optation]
(e.g., "Rey" assuming ShinyHunters)
The financial damage caused by these decentralized cells is immense. Investigative channels on Telegram—most notably a watchdog server titled "The Battle"—have documented that Rey alone allegedly facilitated over $200 million in cumulative corporate damages over the past several months, orchestrating ransomware and data-theft negotiations across multiple independent affiliate groups.
The Cl0p Fixation and Doxing Operations
Despite his youth, Rey demonstrated advanced reconnaissance capabilities. His GitHub blog featured an extensive, deep-dive investigation published in March 2026 that successfully doxed two Russian nationals operating as the core developers behind Cl0p, one of history’s most persistent ransomware operations. This unusual targeting of a rival ransomware group highlighted the volatile, hyper-competitive nature of modern cybercrime syndicates, where extortionists routinely turn their tools against one another for clout and leverage.
Official Statements and Corporate Responses
The convergence of aviation giants, federal law enforcement, and transnational hacking syndicates has prompted carefully coordinated responses from corporate entities and security agencies.

-
Boeing Statement:
"We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter with the Jeppesen ForeFlight team."
-
Jeppesen ForeFlight Statement:
"Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."
-
The FBI Flash Notice (May 2026):
In the wake of ongoing psychological harassment tactics deployed by ShinyHunters—which have historically included swatting, threatening phone calls to victims’ families, and false claims regarding compromising personal media—the FBI issued a formal flash notice warning organizations against paying ransoms.
In subsequent interviews with tech publication The Register, ShinyHunters leadership openly admitted that their cyberattack on the FBI was primarily a "public relations and marketing initiative." They claimed the hack was designed to counter what they viewed as unprofessional government advisories that threatened their bottom line.

Future Outlook: The Unraveling of Decentralized Extortion
The simultaneous neutralization of Pepijn van der Stap in the Netherlands and Saif Al-din Khader in Jordan marks a major turning point in the containment of modern data extortion.
- Erosion of Brand Immunity: Cybercrime syndicates rely heavily on the aura of untouchability. When figures like Rey—who traded heavily on internet memes, public taunts, and borrowed identities—are rapidly identified, detained, and turned into government informants, the psychological deterrent value of extortion brands collapses.
- Stricter SaaS Governance: The massive fallout from the Oracle PeopleSoft exploitation (CVE-2026-35273) has forced global enterprises and government contractors to re-evaluate their patch-management cadences and Zero Trust architecture. Third-party vendors can no longer treat human resources and payroll systems as secondary endpoints.
- The Murder-For-Hire Investigation in Europe: As Dutch prosecutors dig deeper into Van der Stap’s alleged ties to transnational murder-for-hire plots, the boundary between digital extortion and violent physical crime is blurring. Future cybersecurity prosecutions will likely see increased cross-border cooperation between cybercrime units and homicide investigators.
Ultimately, the downfall of "Rey" and his co-conspirators serves as a cautionary tale for the digital underground. While decentralized franchising allows modern hackers to scale their operations quickly, it also creates vast attack surfaces for law enforcement. As Khader sits in Amman cooperating with federal agents, and Van der Stap faces extraordinary criminal charges in Amsterdam, the mythos of the untouchable cyber-extortionist continues to fracture.