The volatile landscape of international cybercrime experienced a seismic shift following a series of high-profile arrests, geopolitical overlaps, and high-stakes digital confrontations involving the prolific data-theft and extortion collective known as ShinyHunters.
At the center of this unfolding saga is a teenager from Amman, Jordan, operating under the hacker handle "Rey"—subsequently identified by investigators as Saif Al-din Khader. Khader, suspected of orchestrating a sprawling wave of extortion campaigns and weaponizing the infamously notorious "ShinyHunters" moniker, has been detained by Jordanian authorities and is reportedly cooperating extensively with the Federal Bureau of Investigation (FBI).
The dragnet closing around Rey follows a coordinated international crackdown, which includes the dramatic arrest in Amsterdam of 24-year-old Dutch cybercriminal Pepijn van der Stap (formerly known as "Umbreon"). While Van der Stap faces extraordinary new allegations in the Netherlands regarding the orchestration of transnational contract murders, the digital ecosystem continues to grapple with the fallout of the hackers’ primary vector: a mass-exploitation campaign targeting Oracle PeopleSoft infrastructure. This vulnerability allowed the threat actors to breach critical systems, including an FBI recruitment portal that exposed sensitive background data on thousands of federal personnel.
This investigative report examines the convergence of state-level law enforcement, the operational "franchising" of elite cybercrime brands, the curious intersection of a young hacker’s operations with his family’s ties to Royal Jordanian Airlines and aerospace giant Boeing, and the evolving tactical responses of global intelligence agencies.
Detailed Chronology: From Zero-Day Exploitation to Global Arrests
The sequence of events leading to the dismantling of this specific faction of the ShinyHunters brand reads like a cyber-thriller, moving rapidly from technical exploits in enterprise software to midnight raids and diplomatic interventions.
June 2026: The Oracle PeopleSoft Zero-Day Campaign
The roots of the current crisis stretch back to June, when threat actors operating under the ShinyHunters banner began mass-exploiting a critical vulnerability—tracked as CVE-2026-35273—within Oracle PeopleSoft. Widely deployed across global enterprises, higher-education institutions, and government agencies for human resources, payroll, and hiring management, PeopleSoft servers became a prime target.
While security firm Mandiant rapidly issued web application firewall (WAF) rules and Oracle released emergency patches, the hackers engineered sophisticated URL-encoding bypass techniques. Their initial ambition, as communicated to security journalists, was audacious: a direct breach of the FBI’s internal PeopleSoft database. While that specific target initially resisted direct compromise, the broader campaign netted massive caches of proprietary data across technology, healthcare, agriculture, and government sectors.
September 15, 2026: The Amsterdam Raid
On the evening of September 15, Dutch law enforcement executed a dramatic raid involving flash-bang grenades in Amsterdam’s Rivierenbuurt neighborhood, apprehending Pepijn van der Stap. Van der Stap, previously convicted for large-scale data extortion netting between €1.5 million and €2.7 million, had publicly cultivated an image as a reformed hacker, recently taking a position as an "offensive security lead" at a Dutch cybersecurity firm named Neo Security.
September 22–30, 2026: Rey’s Desperate Diversions
Following Van der Stap’s arrest, "Rey" (Saif Al-din Khader) moved quickly to seize total administrative control of the ShinyHunters brand. In a brazen attempt to frame the freshly arrested Dutchman, Rey deployed a series of taunting memes on Twitter/X, mocking both the FBI and the rival ransomware group Cl0p. The posts prominently featured the avatar of Van der Stap’s former alias, "Umbreon," designed to mislead both researchers and investigators.
However, the pressure intensified exponentially. On September 28, Dutch media outlet RTL reported that investigators suspected Van der Stap of an even graver crime: attempting to orchestrate at least two contract murders abroad. Simultaneously, the FBI issued an ultimatum, culminating in the sudden offline transition of the ShinyHunters darknet infrastructure on September 30.
October 3–6, 2026: The Detainment in Amman and Contractor Fallout
On October 3, Reuters confirmed via multiple intelligence sources that Saif Al-din Khader had been detained by authorities in Amman, Jordan, and was actively cooperating with the FBI.
Shortly thereafter, cascading administrative consequences hit institutional partners. On October 5, Reuters reported that the FBI had terminated a contractor at global consultancy Accenture following revelations that a failure to apply critical security patches left the FBI recruitment portal vulnerable. The resulting breach exposed sensitive identifying data—including specialties, unit assignments, and psychiatric and medical records—for over 5,000 FBI personnel.
Supporting Context & Metrics: The Franchise Model of Cybercrime
To understand how a teenager in Amman could command global headlines, security analysts emphasize that modern cybercrime syndicates no longer operate as monolithic, centralized hierarchies.
The "Dread Pirate Roberts" Phenomenon of Hacking
The original core of ShinyHunters—primarily French nationals linked to earlier historic breaches dating back to 2019—has largely been neutralized through successive waves of international arrests and imprisonment. Consequently, "ShinyHunters" has evolved into a decentralized franchise. Much like the mythical Dread Pirate Roberts from The Princess Bride, where the title and reputation are passed down or assumed by successors, the ShinyHunters brand name is adopted by independent operators.
Investigators indicate that the modern iteration functions as a loose network of freelancers. These affiliates feed stolen enterprise credentials from Software-as-a-Service (SaaS) platforms into a shared ecosystem, outsourcing extortion demands and negotiating ransom splits ranging from 25% to 30%.
Financial and Operational Impact Metrics
€1.5M – €2.7M: Estimated historical proceeds amassed by Pepijn van der Stap during his initial criminal campaigns prior to his 2023 conviction.
$10.55 Billion: The valuation of Boeing’s November 2025 divestiture of Jeppesen ForeFlight, a digital aviation navigation unit that became a primary target of ShinyHunters’ final extortion attempts under Rey.
5,000+: The number of FBI personnel whose recruitment, background, and medical records were exposed due to unpatched Oracle PeopleSoft servers.
$200 Million: Estimated cumulative damages attributed by online threat-intelligence trackers to the network of young affiliates operating under the borrowed ShinyHunters alias over a multi-month span.
Official Statements and Institutional Responses
The fallout from these coordinated attacks has prompted formal declarations from major aerospace enterprises, cybersecurity firms, and law enforcement entities.
Boeing and Jeppesen ForeFlight
With investigative sources confirming that ShinyHunters was actively extorting a recently divested Boeing business unit at the time of Rey’s arrest, corporate communications teams moved quickly to manage the disclosures. Boeing acknowledged the extortion threat targeting Jeppesen ForeFlight—the aviation navigation subsidiary sold to private equity firm Thoma Bravo in late 2025.
"আমরা Boeing এবং আমাদের সাবেক সহযোগী Jeppesen ForeFlight সম্পর্কিত হুমিকদাতা পক্ষের দাবিগুলো সম্পর্কে অবগত রয়েছি," a Boeing spokesperson noted. "আমরা Jeppesen ForeFlight দলের সাথে বিষয়টি সক্রিয়ভাবে পর্যালোচনা করছি।"
In a separate statement, Jeppesen ForeFlight maintained that their proactive defense measures insulated core systems from operational disruption:
"Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."
The FBI Flash Notice
The cyber-attacks prompted a rare retaliatory public relations battle. In May 2026, the FBI’s Internet Crime Complaint Center (IC3) issued a scathing Flash Notice warning organizations against yielding to ShinyHunters’ extortion demands. The notice highlighted the group’s aggressive harassment strategies, which frequently included swatting, threatening phone calls to executives’ families, and fabricating the existence of compromising personal media.
In interviews with tech publications, the hackers admitted that their breach of the FBI recruitment infrastructure was executed primarily as a "marketing initiative" to undermine the credibility of federal warnings and reassert their technical dominance.
Future Outlook: The Crumbling Infrastructure of Extortion Networks
The detention of Saif Al-din Khader in Jordan and the imprisonment of Pepijn van der Stap in the Netherlands signal a decisive turning point in how law enforcement targets cybercrime supply chains.
Erosion of Safe Havens: The cooperation of teenage and young-adult operators with the FBI demonstrates that regional jurisdictions in the Middle East and Europe are increasingly willing to cooperate with Western intelligence to neutralize cross-border digital extortionists.
The Stigmatization of "Brand" Heists: As underground tracker groups (such as the Telegram channel "The Battle") systematically dox and ridicule individuals who "LARP" as legendary hacking collectives, the utility of buying old PGP keys and reusing legacy hacker brands is rapidly diminishing.
Heightened SaaS and Supply Chain Hardening: Following the massive exploitation of Oracle PeopleSoft vulnerabilities, organizations across transport, healthcare, and defense sectors are accelerating zero-trust architectures, mandatory multi-factor authentication audits, and automated patch-management verification for third-end contractors.
While the "ShinyHunters" banner may resurface under new iterations, the comprehensive dismantling of its most visible modern operators—from the cyber-cafes of Amman to the streets of Amsterdam—underscores the reality that the digital underground offers diminishing insulation for those who trade in corporate extortion and state-level data theft.