Executive Overview
The shadowy infrastructure of ShinyHunters—one of the most prolific and destructive data theft and extortion syndicates of the digital age—is rapidly crumbling. In an international enforcement sweep that bridges the Middle East and Western Europe, authorities have successfully targeted key figures anchoring the gang’s modern reincarnation.
At the center of this storm is a teenager operating out of Amman, Jordan, known by the hacker handle “Rey.” Identified by cybersecurity investigations as Saif Al-din Khader, the young threat actor was recently detained by Jordanian authorities and is reportedly cooperating extensively with the Federal Bureau of Investigation (FBI).
Khader’s capture coincides with a chaotic period for the cybercrime collective. The group recently launched a high-risk mass-exploitation campaign targeting Oracle PeopleSoft vulnerabilities, breached high-profile organizations including the FBI, and attempted to extort a major global aerospace spinoff. The fallout from these aggressive attacks has exposed internal fractures, triggered dramatic physical raids in Europe, and exposed the fragile, franchise-like nature of modern cyber extortion rings.
Detailed Chronology: The Fall of ‘Rey’ and the Amsterdam Raids
The Ascent and Hubris of a Teenage Mastermind
Khader’s journey from a fringe threat actor to a self-appointed kingpin of the modern cyber underground was charted across several months of deep-dive intelligence work. First profiled by security researcher Brian Krebs in November 2025, Rey admitted to operating alongside various ransomware and extortion vectors, orchestrating data theft campaigns under several different aliases.
The investigation into Khader’s operations gained intense momentum following the September 15, 2025, arrest of 24-year-old Dutch cybercriminal Pepijn van der Stap (formerly known by the hacker handle “Umbreon”). Following Van der Stap’s dramatic apprehension by Dutch police—which involved the use of flash-bang grenades in an Amsterdam raid—Khader aggressively seized control of the defunct ShinyHunters brand.

Seeking to capitalize on the notorious moniker, Rey immediately began boasting about breaching FBI infrastructure and extorting the notorious Cl0p ransomware operation. In a calculated attempt to misdirect law enforcement, Khader uploaded taunting memes to Twitter/X, embedding visual signatures tied to Van der Stap’s old "Umbreon" avatar in an amateur effort to frame the imprisoned Dutchman for the attacks.
The Boeing Extortion and Family Ties
The audacity of the campaign ultimately proved to be Khader’s undoing. According to sources familiar with the investigation, Rey’s final undoing was tied to an attempt to extort a navigation and digital aviation unit recently divested by global aerospace giant Boeing.
The investigation took a deeply personal turn when authorities analyzed Khader’s operational security footprint. Strong evidence indicated that Khader’s father worked for Royal Jordanian Airlines, an enterprise operating long-haul fleets manufactured by Boeing and predominantly controlled by the Jordanian government. Security data revealed that the family’s shared personal computer had been previously compromised by password-stealing malware. Logs showed the father utilized identical credentials across multiple employee portals for Royal Jordanian Airlines, giving investigators critical pivot points into the household’s digital footprint.
When reached for comment by journalists prior to his detention, Khader’s father failed to respond. However, within hours of the inquiry being sent, Rey began rapidly purging his digital footprint, scrubbing social media profiles and abandoning the Twitter/X handles used to taunt global law enforcement. Despite the purge, his public GitHub blog remained active, notably featuring a detailed doxing post published in March 2026 identifying two Russian men as the core developers behind the Cl0p ransomware platform.
Supporting Context & Metrics: The PeopleSoft Campaign and Supply Chain Vulnerabilities
The operational backbone of ShinyHunters’ 2026 resurgence relied not on novel zero-days discovered by the gang itself, but on the ruthless mass exploitation of enterprise software infrastructure.

The Oracle PeopleSoft Zero-Day (CVE-2026-35273)
Beginning in June 2026, ShinyHunters began weaponizing CVE-2026-35273, a critical vulnerability in Oracle’s PeopleSoft software-as-a-service (SaaS) platform. PeopleSoft is deployed globally by enterprises, governments, and educational institutions to manage human resources, payroll, recruitment, and benefits.
While Oracle moved quickly to issue security patches, and firms like Mandiant released interim Web Application Firewall (WAF) mitigation rules, the hackers adapted. Utilizing a well-known URL-encoding bypass technique, ShinyHunters sidestepped WAF protections, scaling their attacks across dozens of corporate networks spanning healthcare, agriculture, higher education, technology, and government sectors.
The FBI Breach and Accenture Fallout
The group’s most damaging operational strike occurred when they breached an FBI recruitment portal utilizing the PeopleSoft exploit. According to reports by Reuters, the breach exposed sensitive dossiers on more than 5,000 FBI personnel, including psychiatric and medical records, as well as specific specializations and unit assignments.
The security failure had immediate real-world repercussions. The FBI subsequently terminated an Accenture contractor responsible for managing and maintaining the compromised recruitment infrastructure due to their failure to apply critical security patches in a timely manner.
The "Dread Pirate Roberts" Franchise Model
Security analysts emphasize that the individuals operating under the ShinyHunters banner in 2026 bear little resemblance to the original French nationals who founded the group around 2019. Today, ShinyHunters operates less like a cohesive gang and more like a decentralised franchise model.

Comparing the structure to the "Dread Pirate Roberts" persona from The Princess Bride, intelligence analysts note that when one set of operators is arrested, new cybercriminal freelancers inherit the brand. These affiliates feed stolen SaaS credentials into the collective machinery in exchange for a 25% to 30% cut of any subsequent extortion payouts.
Official Statements and Industry Reactions
The fallout from the dual takedowns in Jordan and the Netherlands has prompted a wave of corporate and agency responses.
- Boeing and Jeppesen ForeFlight: A Boeing spokesperson acknowledged the threat actor’s claims regarding data stolen from Jeppesen ForeFlight, a subsidiary Boeing sold to private equity firm Thoma Bravo for $10.55 billion in November 2025. "We are actively reviewing the matter with the Jeppesen ForeFlight team," Boeing stated. Meanwhile, Jeppesen ForeFlight issued a reassuring response: "Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."
- Neo Security: Pepijn van der Stap’s employer at the time of his arrest—Dutch cybersecurity firm Neo Security—faced intense scrutiny. Company owner Benjamin Korper confirmed that forensic investigators searched his offices during the September 15 raid. Korper noted that an independent audit found no evidence that Van der Stap compromised Neo Security or its clients during his tenure as "offensive security lead."
- The FBI Flash Notice: The federal response to the syndicate’s aggressive tactics culminated in a May 2026 FBI Flash Notice (IC3 PSA260515). The warning detailed the psychological harassment campaigns deployed by ShinyHunters affiliates, which ranged from targeted phone calls and text messages to victims and their families, to dangerous "swatting" incidents and false claims regarding sensitive compromising media.
Future Outlook: The Doxxing Wars and the Death of a Brand
Even as law enforcement systematically rounds up the human nodes of the ShinyHunters collective, the underground ecosystem has turned on its own.
A newly emerged Telegram monitoring channel dubbed "The Battle" has spent weeks ruthlessly doxxing and ridiculing Rey and his associates. According to these tracker channels, Khader single-handedly caused over $200 million in cumulative damages while orchestrating extortion deals for multiple freelance cybercriminal cells. Analysts note that by trying to wear the heavy mantle of the original ShinyHunters brand, Rey invited intense counter-intelligence scrutiny from rival threat actors, security researchers, and Western law agencies alike.
With Saif Al-din Khader cooperating with the FBI in Amman, Pepijn van der Stap facing explosive additional charges in the Netherlands—including allegations of orchestrating murder-for-hire plots abroad—and the core infrastructure of the group’s darknet presence driven offline, the ShinyHunters brand has effectively been burned to the ground.

Yet, cybersecurity experts warn that the underlying market dynamics remain unchanged. As long as SaaS misconfigurations, unpatched enterprise platforms like PeopleSoft, and lucrative corporate extortion payouts exist, new actors will inevitably step forward to inherit the digital spoils, proving that while individual cybercriminals can be captured, the systemic vulnerabilities of the modern digital economy require continuous, proactive defense.