The Fall of ‘Rey’: Inside the Collapse of the Modern ShinyHunters Cybercrime Syndicate

Main page › Cyber Security & Privacy › The Fall of ‘Rey’: Inside…
From ZizzMedia, the free news encyclopedia
The Fall of ‘Rey’: Inside the Collapse of the Modern ShinyHunters Cybercrime Syndicate
The Fall of ‘Rey’: Inside the Collapse of the Modern ShinyHunters Cybercrime Syndicate
Published: 8 October 2026
Author: Laily UPN
Category: Cyber Security & Privacy
Read time: 8 min read
Words: 1,557

Executive Overview

The sprawling, decentralized architecture of modern international cybercrime has suffered a severe structural blow following the detention of a key teenage operative in Amman, Jordan. The suspect, widely known within underground threat intelligence circles by the hacker handle “Rey”—subsequently identified by investigators and journalistic outlets as Saif Al-din Khader—has reportedly begun cooperating with the Federal Bureau of Investigation (FBI). Khader’s apprehension coincides with a chaotic period of succession, brand franchising, and reckless public bravado that ultimately fractured what remained of the once-prolific data extortion collective ShinyHunters.

For years, ShinyHunters has operated as a shadow franchise, a cybercriminal enterprise resembling the literary concept of the "Dread Pirate Roberts" from The Princess Bride. As law enforcement agencies systematically incarcerated its core French-national founders, opportunistic successors stepped into the vacuum. Khader’s ascent to self-appointed administrator of the brand culminated in a high-stakes campaign of mass exploitation leveraging a zero-day vulnerability in Oracle PeopleSoft platforms. This campaign ultimately targeted high-profile entities, including the FBI itself and a critical aerospace asset recently divested by Boeing.

However, Khader’s aggressive tactics—including erratic social media taunts, fabricated operational flags, and an ill-fated attempt to extort a navigation division with direct ties to his father’s employer, Royal Jordanian Airlines—triggered an international dragnet. Compounded by parallel developments in the Netherlands involving the dramatic arrest and sensational murder-for-hire allegations against Dutch national Pepijn van der Stap, the house of cards has finally collapsed. This report examines the technical methodologies, geopolitical implications, and unfolding human dynamics behind the dismantling of one of the cyber underground’s most notorious extortion engines.


Detailed Chronology: From PeopleSoft Zero-Days to the Amman Raid

The unraveling of the modern ShinyHunters apparatus began in earnest in mid-2025, but accelerated into a high-intensity crisis throughout the summer and autumn of 2026.

The Oracle PeopleSoft Attack Vector (June – September 2026)

In June 2026, threat actors operating under the ShinyHunters banner began weaponizing a critical security flaw—tracked as CVE-2026-35273—affecting Oracle PeopleSoft, a globally ubiquitous software-as-a-service (SaaS) platform relied upon by major enterprises for human resources, payroll, and applicant tracking. While Oracle scrambled to issue a patch and security firm Mandiant deployed emergency web application firewall (WAF) rules, the hackers adapted quickly. Utilizing sophisticated URL-encoding bypass techniques, ShinyHunters orchestrated a mass-exploitation campaign across diverse sectors, harvesting confidential data from higher education, healthcare, agriculture, transportation, and government systems.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

According to communications with security researchers, the initial primary objective of the PeopleSoft exploitation was breaching the FBI’s internal recruitment databases. While direct penetration of the bureau’s core PeopleSoft database proved resilient, subsequent collateral damage was catastrophic. A third-party contractor at Accenture, tasked with managing the FBI recruitment portal, failed to apply timely patches. This oversight left a portal vulnerable that subsequently exposed sensitive files concerning more than 5,000 FBI personnel, including specialized unit assignments, medical records, and psychiatric evaluations. The breach prompted the immediate termination of the Accenture contractor by federal authorities.

The Arrest of Pepijn van der Stap (September 15, 2026)

On the evening of September 15, 2026, Dutch national security forces—reportedly employing flash-bang grenades and specialized tactical units in Amsterdam’s Rivierenbuurt—raided the residence of Pepijn van der Stap. Van der Stap, a 24-year-old convicted cybercriminal who had recently cultivated a public persona as a "reformed hacker" and "offensive security lead" at a Dutch cybersecurity firm named Neo Security, was taken into custody. Prosecutors and investigators suspected him of providing critical infrastructure support and data-theft facilitation to ShinyHunters.

Rey’s Desperate Takeover and Frame-Up Strategy

Immediately following Van der Stap’s arrest, the teenager known as "Rey" (Saif Al-din Khader) moved swiftly to seize total control of the dormant ShinyHunters infrastructure, PGP keys, and communication channels. Recognizing an opportunity to consolidate power within the cybercrime underground, Khader initiated an aggressive public relations campaign. He boasted openly on X (formerly Twitter) about breaching the FBI and extorting the notorious Russian-linked ransomware group Cl0p.

In a Machiavellian twist, Khader embedded visual signatures and avatars associated with Van der Stap’s former hacker alias, "Umbreon," into public memes mocking the FBI and Cl0p. The transparent objective was to deceive law enforcement and rival underground factions into believing that Van der Stap was orchestrating these high-profile attacks from behind the scenes, thereby framing the recently jailed Dutchman for an entirely new wave of federal offenses.

The Amman Detention and Boeing Extortion Nexus

Khader’s tactical miscalculations ultimately sealed his fate. Threat intelligence sources revealed that at the time of his apprehension by Jordanian authorities in Amman, the young hacker was actively engaged in the extortion of Jeppesen ForeFlight—a digital aviation and navigation unit recently divested by Boeing.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The involvement of Boeing’s former subsidiary elevated the investigation from a standard corporate data theft case to an urgent national security matter. Investigators noted that the stolen aviation navigation data posed potential operational safety risks to the aerospace sector. This heightened urgency directly catalyzed cooperation between the FBI and Jordanian law enforcement, leading to Khader’s swift detention in Amman.


Supporting Context & Metrics: The Franchise Model and Underground Dynamics

To understand how a teenager from Amman assumed control of a global cybercrime juggernaut, security analysts point to the fundamental evolution of modern ransomware and extortion groups.

The "Dread Pirate Roberts" Cyber Franchise

The original core of ShinyHunters—predominantly French citizens who have since faced arrest and incarceration—built a fearsome reputation between 2019 and 2023, orchestrating massive data thefts impacting billions of individual records. However, rather than operating as a centralized corporate hierarchy, the modern iteration functions as an open-source franchise. Freelance affiliates and credential brokers feed stolen SaaS access tokens to whoever holds the administrative keys, negotiating ransoms in exchange for a 25% to 30% cut of the illicit proceeds.

When federal law enforcement dismantle one layer of leadership, opportunistic actors step into the void, purchasing PGP keys and spinning up new Telegram channels to "larp" as the original collective. Analysts estimate that Khader’s reboot of the ShinyHunters brand generated upwards of $200 million in calculated economic damages across multiple collaborative friend groups over a compressed operational window.

The Cl0p Dossier and Social Media Purge

Despite his youth and tactical errors, Khader demonstrated a high degree of technical curiosity. Before scrubbing his digital footprint, his GitHub-hosted cybersecurity blog featured an extensive, deep-dive investigative report published in March 2026. This post successfully doxed two Russian nationals identified as the core developers behind Cl0p—one of the longest-standing and most aggressive ransomware operations in history.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

When law enforcement closed in and inquiries from journalists reached Khader’s family—specifically targeting his father, an employee of Royal Jordanian Airlines whose corporate credentials had been compromised via password-stealing malware on a shared home computer—Khader initiated a panic-driven purge. He deleted his X accounts and dismantled primary communication channels, though the damage to his operational security had already been done.


Official Statements and Industry Responses

The cascading fallout from the ShinyHunters campaigns and subsequent arrests prompted formal statements from major corporations, aerospace entities, and regulatory bodies worldwide.

  • Boeing Corporate Communications:

    "Estamos al tanto de las afirmaciones de un actor malicioso sobre datos supuestamente asociados con Boeing y nuestra antigua subsidiaria Jeppesen ForeFlight. Estamos revisando activamente el asunto con el equipo de Jeppesen ForeFlight." (Translation: We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter with the Jeppesen ForeFlight team.)

  • Jeppesen ForeFlight Management:

    ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

    "Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."

  • The FBI (May 2026 Flash Notice #PSA260515):
    The bureau formally warned organizations against capitulating to ShinyHunters extortion demands, noting the group’s history of psychological harassment tactics—including harassing phone calls, text messages, swatting, and the fabrication of nonexistent compromising media to coerce victims into paying ransoms.


Future Outlook: The Death Knell for Autonomous Extortion Brands?

The simultaneous neutralization of Pepijn van der Stap in the Netherlands—further complicated by explosive domestic reports from Dutch media outlets regarding suspected murder-for-hire plots—and the detention of Saif Al-din Khader in Jordan mark a watershed moment for the cybersecurity landscape.

Several critical trajectories emerge from these dual developments:

  1. Erosion of Underground Impunity: The rapid intelligence sharing between European, Middle Eastern, and North American law enforcement demonstrates that geopolitical boundaries offer diminishing shelter for youthful cybercriminals who draw the ire of critical infrastructure operators.
  2. The Fragility of the Franchise Model: As brands like ShinyHunters become toxic to operate due to intense federal scrutiny, splinter groups and adolescent copycats will find it increasingly difficult to monetize stolen data without triggering immediate international warrants.
  3. Heightened Scrutiny on SaaS Security: The Oracle PeopleSoft zero-day campaign serves as a stark reminder that legacy enterprise platforms remain primary targets. Organizations must accelerate zero-trust architectures and rigorous patch management protocols to prevent third-party contractor negligence from exposing sensitive national security assets.

Ultimately, the downfall of "Rey" and his associates signals that while the hydra of cybercrime will continue to sprout new heads, the cost of operating under legendary, highly targeted monikers has become dangerously high. For Saif Al-din Khader and his contemporaries, the game of digital extortion has transitioned from an online playground of impunity to an austere reality of federal cooperation and indefinite detention.

Related News

Leave a Reply / Join Discussion

Your email address will not be published. Required fields are marked with *