The Fall of "Rey": Inside the Unraveling of the ShinyHunters Cybercrime Syndicate

Main page › Cyber Security & Privacy › The Fall of "Rey": Inside…
From ZizzMedia, the free news encyclopedia
The Fall of "Rey": Inside the Unraveling of the ShinyHunters Cybercrime Syndicate
The Fall of "Rey": Inside the Unraveling of the ShinyHunters Cybercrime Syndicate
Published: 8 October 2026
Author: Layla Zulfa
Category: Cyber Security & Privacy
Read time: 8 min read
Words: 1,491

Executive Overview

The high-stakes underworld of international cyber extortion has suffered a major disruption with the detention of a key teenage suspect in Amman, Jordan. Identified by cyber intelligence investigators as Saif Al-din Khader—better known by his hacker handle “Rey”—the young man is reportedly cooperating with the Federal Bureau of Investigation (FBI). Khader’s apprehension marks a pivotal development in the ongoing international crackdown on ShinyHunters, a prolific and destructive data-theft syndicate responsible for billions of compromised records over half a decade.

The dragnet tightened around Khader as ShinyHunters executed a series of brazen, high-profile attacks, including breaching an FBI recruitment database and attempting to extort a navigation and digital aviation unit recently divested by aerospace giant Boeing. This latest chapter in the ShinyHunters saga highlights the evolving nature of modern cybercrime: no longer a monolithic organization, the syndicate operates more like a decentralized franchise, sustained by young, freelance digital mercenaries who adopt established criminal brands to optimize their extortion leverage.

Simultaneously, parallel investigations in Europe have shattered the illusion of reformation surrounding other key figures linked to the ecosystem, exposing a dark intersection of data theft, international cyberwarfare, and even alleged murder-for-hire plots. As the infrastructure of ShinyHunters flickers offline under sustained global law enforcement pressure, security analysts are left dissecting how a loose collective of digital natives managed to rattle some of the world’s most secure corporate and government networks.


Detailed Chronology of Events

The Zero-Day Breach and the Oracle PeopleSoft Exploitation

The modern escalation of ShinyHunters’ campaign traces back to June, when the group began exploiting a critical zero-day vulnerability (CVE-2026-35273) affecting PeopleSoft, a widely deployed enterprise software-as-a-service (SaaS) platform from tech giant Oracle. Designed to manage human resources, recruitment, payroll, and benefits, PeopleSoft deployments across diverse industries—ranging from higher education and healthcare to agriculture, technology, and government—suddenly became prime targets.

Although Oracle rapidly issued a security patch, and security firm Mandiant released stopgap web application firewall (WAF) rules, ShinyHunters proved resilient. Leveraging a well-documented URL-encoding technique to bypass Mandiant’s WAF restrictions, the hackers conducted mass-exploitation campaigns across dozens of corporate networks. According to reports from Mandiant and the Google Threat Intelligence Group (GTIG), the primary ambition behind these attacks was initially aimed at the FBI’s own PeopleSoft database.

While direct infiltration of the bureau’s primary infrastructure proved challenging initially, the attackers successfully compromised the recruitment portal used by the FBI. This breach—facilitated by an unpatched vulnerability left exposed by an Accenture contractor—eventually led to the exposure of sensitive data belonging to more than 5,000 FBI personnel, including specialized units, medical records, and psychiatric evaluations.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The Rise and Fall of "Rey" in Amman

In November 2025, security journalist Brian Krebs profiled "Rey," identifying him as a prominent administrator operating within the overlapping circles of "Scattered Lapsus" and ShinyHunters affiliate networks. Khader, whose father’s employer (Royal Jordanian Airlines) operates a fleet built entirely by Boeing, cultivated a distinct online persona. His handle, "Rey"—meaning king in Spanish—mirrored his ambitions in the cybercrime ecosystem.

The investigation into Khader intensified dramatically following the arrest of 24-year-old Dutch cybercriminal Pepijn van der Stap (formerly known by the hacker alias “Umbreon”) by Dutch police on September 15. In the wake of Van der Stap’s dramatic pre-dawn arrest—which involved flash-bang grenades in an Amsterdam residential neighborhood—Rey abruptly seized control of the ShinyHunters brand.

Seeking to deflect law enforcement attention, Rey launched a public relations and psychological warfare campaign on Twitter/X and Telegram. He posted mocking memes targeting the FBI and the Cl0p ransomware syndicate, while intentionally embedding images of Van der Stap’s old "Umbreon" avatar to frame the Dutch national for the newly executed attacks. However, this bravado was short-lived. Following inquiries directed at his family—including his father, whose credentials had previously been exposed via malware on a shared home computer—Rey began systematically purging his digital footprint. Despite deleting his social media profiles, a legacy cybersecurity blog hosted on GitHub remained active, revealing Rey’s fixation on unmasking the core developers of the Cl0p ransomware group.

By October 3, international news outlets, including Reuters, confirmed that Jordanian authorities had detained Khader in Amman and that he had begun cooperating with the FBI.

The Boeing Extortion Catalyst

According to sources familiar with the federal investigation, the FBI’s pursuit of Rey gained immediate urgency when ShinyHunters targeted Jeppesen ForeFlight, a digital aviation and navigation unit previously owned by Boeing and sold in November 2025 to private equity firm Thoma Bravo for $10.55 billion.

The theft of sensitive aviation data from the former Boeing subsidiary posed immediate operational safety and regulatory concerns, prompting federal investigators to accelerate their international cooperation. While Boeing acknowledged the extortion attempt and stated it was actively reviewing the claims alongside Jeppesen ForeFlight leadership, representatives for the aviation subsidiary maintained that their operational integrity and products remained unaffected.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Supporting Context & Metrics

The "Dread Pirate Roberts" Franchise Model

Security analysts emphasize that the individuals currently operating under the ShinyHunters banner bear little resemblance to the original French nationals who founded the group around 2019 and have since faced arrest and imprisonment. Instead, ShinyHunters has morphed into a franchising model—reminiscent of the fictional "Dread Pirate Roberts" from The Princess Bride, where the moniker is continuously inherited by successive waves of cybercriminals.

Rather than operating as a tight-knit hacking crew, today’s ShinyHunters ecosystem is driven by freelance affiliates and underground brokers. These individuals feed stolen corporate credentials into shared pools, execute targeted SaaS platform extortions, and split payouts—typically extracting a 25% to 30% cut of any ransoms paid by panicked corporate victims.

Financial Impact and Technical Capabilities

The scale of damage inflicted by this decentralized network is immense. Underground chat server leaks and investigative disclosures suggest that over the span of a few months, Rey and his immediate associates helped broker extortion deals that generated massive payouts while causing hundreds of millions of dollars in cumulative corporate damages.

Their motivation was not solely financial; it was deeply tied to brand reputation and ego. Following a May 15 flash notice published by the FBI advising organizations against paying ransoms to ShinyHunters—a notice that portrayed the group as erratic and prone to swatting or harassment—the hackers retaliated. In interviews with industry tech publications, the group admitted that hacking the FBI was primarily a PR and marketing initiative designed to reassert their technical dominance and undermine official government advisories.


Official Statements

The fallout from the coordinated law enforcement actions has prompted formal responses from major corporate entities, cybersecurity firms, and government contractors:

  • Boeing Statement:

    ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

    "We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter with the Jeppesen ForeFlight team."

  • Jeppesen ForeFlight Statement:

    "Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."

  • Neo Security (on Pepijn van der Stap):
    Neo Security owner Benjamin Korper confirmed that external forensic investigators were brought in to audit the firm following Van der Stap’s arrest. Korper noted that initial audits found no evidence that Van der Stap had acted maliciously against the cybersecurity firm or its clients during his brief tenure as an "offensive security lead."

  • The Battle (Telegram Doxing Group) Commentary:

    "Rey (Saif Al-Din Khader) made a serious mistake when he started pretending to be a member of ShinyHunters. That group had already been dismantled… [He] caused over $200 million in damages and helped around 5–6 friend groups in the community make money by using Shiny Hunters group aliases to negotiate deals for a 25–30% cut over the past few months."

    ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Future Outlook

The simultaneous neutralization of Saif Al-din Khader in Amman and Pepijn van der Stap in Amsterdam marks a watershed moment in the disruption of modern cybercrime syndicates. However, the dismantling of these high-profile figures does not signal the eradication of the threat.

The structural evolution of groups like ShinyHunters into decentralized franchise networks ensures that opportunistic freelancers will continue to emerge, eager to adopt infamous monikers for quick financial gains. Law enforcement agencies, led by the FBI and bolstered by international partners in Jordan, the Netherlands, and across Europe, are shifting their strategic focus toward dismantling the underlying infrastructure—such as illicit credential marketplaces, Telegram-based broker rings, and zero-day exploitation forums.

For corporations and government contractors, the episode serves as a sobering reminder of supply chain vulnerabilities. As long as enterprise platforms like Oracle PeopleSoft remain targets for automated mass-exploitation, and as long as young cybercriminals find glory and profit in inheriting toxic digital brands, the digital battleground will remain volatile. The downfall of "Rey" may have stripped the crown from one self-proclaimed king, but the systemic incentives that created him guarantee that the hunt for the next digital pretender has already begun.

Related News

Leave a Reply / Join Discussion

Your email address will not be published. Required fields are marked with *