Executive Overview
In the high-stakes theater of global cybersecurity, the boundaries between state-sponsored espionage, ransomware syndicates, and teenage bravado frequently blur. Recent international law enforcement operations have struck a heavy blow against the infrastructure of ShinyHunters, a prolific data theft and extortion collective responsible for multi-year campaigns compromising billions of records across industries ranging from higher education and government to healthcare and transportation.
At the center of this unfolding drama is a teenager from Amman, Jordan, known by the hacker handle “Rey.” Identified by security researchers as Saif Al-din Khader, the young man was recently detained by Jordanian authorities and is reportedly cooperating with the Federal Bureau of Investigation (FBI). His apprehension occurred while ShinyHunters was actively attempting to extort a navigation and digital aviation unit recently divested by aerospace titan Boeing—a corporate target with a striking geographical and professional proximity to Khader’s immediate family.
The collapse of Rey’s operational safety net follows a string of high-profile developments, including the dramatic Dutch police raid and arrest of 24-year-old convicted cybercriminal Pepijn van der Stap (“Umbreon”) in Amsterdam. As law enforcement closes in on decentralized networks of freelancers and affiliates, the ShinyHunters name has morphed from a tight-knit core of French actors into a decentralized cybercrime franchise—complete with proxy actors, stolen PGP keys, bitter infighting, and brazen attempts to weaponize web application zero-days against international law enforcement.
This report provides a comprehensive examination of the investigation, the technical exploits underpinning the group’s latest wave of attacks, the geopolitical ripples of targeting aviation and national security infrastructure, and the alarming escalation into violent physical threats.
Detailed Chronology of an Escalating Cyber War
The current chapter of the ShinyHunters saga represents a rapid escalation in the cat-and-mouse game between elite threat actors and global law enforcement agencies. The timeline of key events maps out how a loose affiliation of digital extortionists overplayed their hand, culminating in international arrests and cooperation agreements.
June 2026: The Oracle PeopleSoft Zero-Day Campaign
The technical foundation for ShinyHunters’ mid-2026 campaign relied heavily on the mass exploitation of CVE-2026-35273, a critical vulnerability in PeopleSoft, an Oracle software-as-a-service (SaaS) platform widely utilized for human resources, payroll, and recruitment management.
Disclosed and rapidly patched by Oracle in June, the vulnerability was initially seized upon by ShinyHunters as a zero-day exploit. According to communications with security media outlets like BleepingComputer, the primary objective of this specific campaign was to breach the FBI’s own PeopleSoft database. While direct penetration of the bureau’s internal system proved difficult initially, the actors pivoted to a widespread harvesting campaign.

When Mandiant and the Google Threat Intelligence Group (GTIG) issued web application firewall (WAF) mitigation rules to protect unpatched networks, the hackers engineered a URL-encoding bypass trick. By late September, GTIG confirmed that ShinyHunters had successfully compromised dozens of enterprise and institutional environments across technology, agriculture, healthcare, and government sectors.
May – September 2026: The FBI Flash Notice and Retaliation
The friction between the hackers and federal investigators reached a boiling point on May 15, 2026, when the FBI’s Internet Crime Complaint Center (IC3) issued a scathing public service announcement warning organizations against paying ransoms to ShinyHunters. The advisory detailed the group’s aggressive harassment tactics—including direct phone calls, text message intimidation, and swatting incidents—while noting that their threats of possessing sensitive media often amounted to bluffs.
In a move calculated to disrupt the narrative, ShinyHunters launched a retaliatory cyber assault against the FBI’s own recruitment portal. The breach exposed sensitive records of more than 5,000 bureau personnel, including unit assignments, specializations, and confidential medical and psychiatric disclosures. Investigative reporting later revealed that the FBI had contracted Accenture to manage elements of the recruitment infrastructure; the failure to apply critical security patches resulted in the immediate removal of the responsible Accenture contractor.
September 15 – 29, 2026: The Dutch Raid and the Rise of "Rey"
On the evening of September 15, 2026, the operation against ShinyHunters shifted to Europe. Dutch law enforcement, utilizing flash-bang grenades and specialized tactical units, raided the Amsterdam residence of Pepijn van der Stap, a 24-year-old cybercriminal previously convicted of large-scale data extortion.
Immediately following Van der Stap’s arrest, Rey assumed control of the active ShinyHunters channels, launching a public relations campaign that included posting mocking memes on Twitter/X targeting both the FBI and the rival ransomware syndicate Cl0p. In an apparent bid to frame Van der Stap—whose former hacker alias was “Umbreon”—Rey embedded the avatar of the Pokémon character into his taunting graphics.
However, Rey’s digital footprint proved fatal to his anonymity. On September 28, investigative reporting linked Rey directly to Saif Al-din Khader of Amman. Days later, Jordanian authorities detained Khader, cutting short his tenure as the self-appointed ringleader of the franchise. By September 30, following an ultimatum and an unheeded FBI deadline, the primary ShinyHunters darknet portal went offline.
Technical Exploitation and the "Franchising" of Extortion
To understand how a teenager sitting in Amman could seize control of a globally recognized cybercrime brand, security analysts point to the evolution of modern ransomware and extortion groups. No longer centralized cartels with strict membership criteria, modern groups operate on franchise models.

The "Dread Pirate Roberts" Phenomenon
As noted by threat intelligence professionals, the original core members of ShinyHunters—predominantly French nationals arrested in prior international crackdowns—have largely been neutralized by law enforcement. Yet the brand persists.
Operating similarly to the mythical pirate moniker from The Princess Bride, succession in modern cybercrime frequently occurs via arrest rather than death. Independent actors purchase legacy PGP keys, take over archived forums, and adopt established monikers to instantly secure institutional fear and brand recognition.
[Original ShinyHunters Core (French Nationals)]
│
▼ (Arrested / Imprisoned)
[Decentralized Freelancers / Affiliates]
│
▼ (Acquisition of PGP Keys & Infrastructure)
[Saif Al-din Khader ("Rey") / Proxy Operators]
Rey’s operation followed this exact playbook. According to disclosures on underground Telegram channels monitored by security researchers, Khader utilized acquired keys and resurrected forum identities to run a brokerage service. He partnered with 5 to 6 affiliate cells, providing SaaS credentials and negotiating extortion demands in exchange for a 25% to 30% cut of incoming ransom payments.
The Jeppesen ForeFlight Extortion and Aviation Links
The turning point in the FBI’s investigation into Rey was not merely the defacement of federal recruitment sites, but the targeted extortion of Jeppesen ForeFlight, a digital aviation and navigation subsidiary previously owned by Boeing. Boeing sold the unit in November 2025 to private equity firm Thoma Bravo for $10.55 billion.
The involvement of Khader in this specific attack carried profound personal irony. Evidence uncovered during prior profiling of the young hacker revealed that his family’s shared computer had been compromised by infostealer malware. The exfiltrated logs demonstrated that Khader’s father—reportedly an employee of Royal Jordanian Airlines, a carrier reliant on Boeing widebody aircraft—frequently used identical credentials across multiple corporate portals.
When investigators realized that an extortionist operating under the moniker "Rey" (derived from the Spanish word for king, akin to "royal") was targeting aviation navigation systems while sitting in the home of an airline employee, the digital and physical realms collided. The FBI’s pursuit gained immediate geopolitical urgency, culminating in Jordanian authorities taking the suspect into custody.
Supporting Context and Threat Metrics
The scope of damage wrought by the loose collective of actors operating under the ShinyHunters umbrella is staggering.

| Metric / Indicator | Detail | Source / Context |
|---|---|---|
| Estimated Damages | Over $200 million in cumulative damages attributed to recent franchise iterations. | Underground Telegram intelligence & security analysts |
| Exposed Records | Billions of stolen consumer and corporate records since 2019. | Global threat intelligence tracking |
| FBI Breach Impact | 5,000+ personnel records exposed, including medical histories and operational specializations. | Reuters / Investigative reports |
| Zero-Day Vulnerability | Oracle PeopleSoft (CVE-2026-35273) mass-exploited across government, education, and health sectors. | Mandiant / Google Threat Intelligence Group |
| Financial Extortion Scale | Historical campaigns by core members netted between €1.5 million and €2.7 million per major enterprise breach. | Dutch prosecutorial records |
Official Statements and Corporate Responses
As the fallout from the coordinated arrests continues to reverberate across the technology and aerospace sectors, affected organizations have issued formal statements addressing the breaches and ongoing investigations.
-
Boeing Corporate Communications:
"We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter with the Jeppesen ForeFlight team."
-
Jeppesen ForeFlight Leadership:
"Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."
-
Neo Security (Regarding Pepijn van der Stap):
Neo Security’s owner, Benjamin Korper, confirmed that outside forensic investigators were retained immediately following the September 15 raid on Van der Stap’s residence. Korper stated that initial audits found no evidence that Van der Stap compromised internal company infrastructure or client networks during his tenure as "offensive security lead."

The Dark Underbelly: Murder-For-Hire Allegations
While Khader’s detention in Jordan highlights the cross-border nature of modern digital extortion, developments in the Netherlands regarding Pepijn van der Stap have introduced an alarming dimension to the investigation.
According to investigative reporting by Dutch daily RTL, Dutch law enforcement officials harbor serious suspicions that Van der Stap attempted to orchestrate at least two murders abroad. Prosecutors are evaluating whether the former software engineer and vulnerability disclosure volunteer crossed the threshold from digital extortionist into physical contract violence.
The juxtaposition of Van der Stap’s public rehabilitation—posing as a reformed white-hat researcher delivering talks and securing employment at legitimate cybersecurity firms like Neo Security—with allegations of orchestrating transnational violence has shocked the European security community. The dramatic raid utilizing flash-bang grenades by Amsterdam’s specialized tactical units underscores the gravity of the intelligence held by prosecutors.
Future Outlook: The Fragmented Horizon of Cyber Extortion
The simultaneous detention of Saif Al-din Khader in Amman and the arrest of Pepijn van der Stap in Amsterdam mark a watershed moment in the containment of the ShinyHunters ecosystem. However, industry experts caution that dismantling an infrastructure does not eliminate the threat actors behind it.
- Decentralized Retaliation: With the primary darknet forums and Telegram command-and-control channels dismantled or seized, remaining freelancers are expected to scatter into smaller, more clandestine cells.
- Scrutiny on SaaS Security: The exploitation of Oracle PeopleSoft served as a stark reminder that legacy enterprise software platforms remain primary vectors for initial access. Organizations will face mounting regulatory pressure to accelerate zero-day patch management.
- The End of the "Brand": The public humiliation of Khader by rival hacker groups on Telegram—combined with law enforcement infiltration of proxy channels—has severely degraded the currency of the ShinyHunters name. Future attacks will likely operate under entirely novel, highly ephemeral designations.
As federal investigators continue debriefing cooperating witnesses in Amman and Amsterdam, the investigation serves as an enduring cautionary tale: in the interconnected architecture of modern global commerce, the digital misdeeds of a single individual can rapidly bridge the gap between suburban bedrooms, corporate boardrooms, and international geopolitical security.