Executive Overview
The sprawling, high-stakes cybercrime ecosystem surrounding the notorious data theft and extortion syndicate ShinyHunters has suffered a catastrophic series of blows. Saif Al-din Khader—a teenager operating from Amman, Jordan, under the hacker handle “Rey”—has been detained by Jordanian authorities and is reportedly cooperating extensively with the Federal Bureau of Investigation (FBI).
Khader’s arrest coincides with the final, frantic stages of an extortion campaign targeting Jeppesen ForeFlight, a digital aviation and navigation unit recently divested by aerospace giant Boeing. Intriguingly, intelligence indicates that Khader’s father is employed by Royal Jordanian Airlines, a carrier whose long-haul fleet relies heavily on Boeing aircraft. The juxtaposition of a young cybercriminal targeting aviation supply chains from his father’s home turf underscores the complex, often bizarre intersections of modern geopolitical crime and familial exposure.
At the same time, international law enforcement agencies are dismantling the broader infrastructure that sustained ShinyHunters. In the Netherlands, Dutch police arrested 24-year-old convicted cybercriminal Pepijn van der Stap—known previously by the alias “Umbreon”—following a dramatic raid involving flash-bang grenades. Beyond data theft and extortion, Van der Stap now faces chilling allegations of orchestrating murder-for-hire plots.
This multi-jurisdictional crackdown highlights a fundamental evolution in cybercrime: the shift from tight-knit, ideological hacker collectives to decentralized, franchise-like syndicates. Much like the literary concept of the Dread Pirate Roberts, the ShinyHunters brand has been weaponized by successive generations of cybercriminals, surviving through succession-by-arrest rather than operational continuity.

Detailed Chronology: From Zero-Day Exploitation to Global Detentions
The Oracle PeopleSoft Zero-Day Campaign
The current chapter of the ShinyHunters saga began in earnest in June, when the group—operating through a decentralized network of freelance affiliates—began mass-exploiting a critical vulnerability (CVE-2026-35273) in Oracle PeopleSoft. Widely deployed across corporate enterprises, government agencies, and higher-education institutions for human resources, benefits, and payroll management, PeopleSoft became a goldmine for the threat actors.
While Oracle rapidly issued patches and Mandiant deployed web application firewall (WAF) rules, ShinyHunters bypassed these defensive layers by utilizing sophisticated URL-encoding tricks. By September, threat intelligence reports from Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that the group had compromised dozens of high-profile networks across critical infrastructure sectors, ranging from healthcare and agriculture to transportation and government services.
The FBI Breach and Public Relations War
The group’s ambitions stretched beyond corporate targets. Admitting their goals to tech publication BleepingComputer, ShinyHunters confessed that an initial objective of the PeopleSoft zero-day exploitation was to breach the FBI’s own recruitment databases.
Although direct penetration of the agency’s core systems proved difficult initially, subsequent investigations revealed that a contractor at Accenture had failed to patch the specific vulnerability on the FBI’s recruitment portal. This oversight allowed the threat actors to siphon sensitive personal data belonging to more than 5,000 FBI personnel, exposing specialized unit assignments, medical histories, and psychiatric records.

In May, the FBI retaliated by publishing a scathing Flash Notice advising victims never to pay ransoms to ShinyHunters. Describing the group’s tactics—which included doxing, harassment phone calls, and swatting—the advisory severely damaged the syndicate’s leverage. In a bizarre PR maneuver, ShinyHunters hacked the FBI’s portal explicitly to "refute misinformation" and prove their technical dominance, effectively treating a federal law enforcement breach as a marketing campaign.
The Arrest of "Umbreon" and Rey’s Desperate Framing
The house of cards began to collapse in mid-September. On the evening of September 15, Dutch law enforcement conducted a high-impact tactical raid in Amsterdam, arresting Pepijn van der Stap.
Sensing the net closing, "Rey" (Saif Al-din Khader) scrambled to secure control over the fractured ShinyHunters digital infrastructure. Operating from Amman, Khader seized the group’s legacy PGP keys, Telegram channels, and breach forums. In an attempt to divert suspicion, Rey launched a public relations blitz on Twitter/X, mocking the FBI and the Cl0p ransomware group while deliberately embedding avatars associated with Van der Stap’s former alias, "Umbreon," to frame the Dutchman for the attacks.
The diversion failed. On September 28, Dutch media dropped an even more explosive bombshell: investigators suspected Van der Stap of ordering at least two foreign-directed assassinations. By October 3, international sources confirmed that Jordanian authorities had closed in on Khader in Amman, detaining the teenager and securing his cooperation with the FBI.

Supporting Context & Metrics: The Anatomy of a Cybercrime Franchise
To understand how a teenager in Jordan and a supposedly "reformed" security consultant in Amsterdam came to command one of the world’s most prolific data extortion brands, one must examine the operational structure of modern threat groups.
[Core Infrastructure / Zero-Day Exploits (Oracle PeopleSoft)]
│
┌───────────┴───────────┐
▼ ▼
[Freelance Affiliates] [Franchise Operators]
(Stolen SaaS Credentials) (Rey / Saif Al-din Khader)
│ │
└───────────┬───────────┘
▼
[Extortion & Ransom Demands]
(Jeppesen ForeFlight, FBI Recruitment Portal, Cl0p)
The "Dread Pirate Roberts" Model of Cybercrime
The original core members of ShinyHunters—primarily French nationals linked to prior high-profile breaches dating back to 2019—are largely behind bars. However, the brand survived. Security researchers describe the current iteration of ShinyHunters as a franchise operation. Independent hackers and "friend groups" purchase old forum credentials, acquire legacy PGP keys, and adopt the ShinyHunters moniker to extract high-value ransoms, keeping a 25% to 30% cut of the profits.
According to intelligence gathered by adversarial tracking groups on Telegram—such as the channel "The Battle"—Rey was a relative greenhorn who managed to leverage the infamous name to coordinate cyberattacks resulting in over $200 million in cumulative damages.
Key Stakeholders and Impact Metrics
- Jeppesen ForeFlight Extortion Value: Multi-million-dollar demands targeting data from Boeing’s former aviation navigation subsidiary (sold to Thoma Bravo in November 2025 for $10.55 billion).
- FBI Personnel Compromised: Over 5,000 records exposed via an unpatched Accenture-managed recruitment portal.
- Pepijn van der Stap’s Historic Gains: Previous prosecution pegged his criminal proceeds between €1.5 million and €2.7 million before his initial 2023 conviction and subsequent release.
Official Statements and Corporate Responses
The fallout from these coordinated law enforcement actions has prompted careful statements from corporate and aviation giants caught in the crosshairs:

- Boeing: Acknowledged awareness of threat actor claims regarding data associated with Jeppesen ForeFlight. In a formal statement, the company noted, "We are actively reviewing the matter with the Jeppesen ForeFlight team."
- Jeppesen ForeFlight: Emphasized operational resilience, stating, "Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."
- Neo Security: The Dutch cybersecurity firm that employed Van der Stap as an "offensive security lead" confirmed that external investigators found no evidence that Van der Stap had turned his employer’s networks against clients, despite the shocking nature of his subsequent arrest.
Future Outlook
The simultaneous neutralization of key operatives in Amman and Amsterdam signals a fundamental turning point in the global fight against ransomware and data extortion cartels.
- Erosion of Brand Shields: The rapid unmasking of figures like Rey and Umbreon demonstrates that operating under historic, fear-inducing cybercriminal monikers no longer grants anonymity. Law enforcement and threat intelligence groups are increasingly adept at mapping digital breadcrumbs—such as compromised family computers, leaked credentials, and stylistic social media taunts—back to physical identities.
- Scrutiny of Supply Chain Contractors: The Accenture-FBI breach highlights the systemic risk posed by third-party contractors. Expect federal agencies and Fortune 500 companies to drastically tighten patch management compliance, specifically regarding widely targeted enterprise software-as-a-service platforms like Oracle PeopleSoft.
- The Fragmentation of Extortion Syndicates: As franchise models fracture under pressure from international police coordination, extortion groups will likely become more paranoid, insular, and unpredictable. However, the willingness of detained juveniles like Khader to cooperate with federal investigators suggests that the internal code of silence among cybercriminal affiliates is increasingly fragile.