Suspected ShinyHunters Leader Detained in Jordan and Cooperating with FBI
- A teenager in Amman, Jordan, suspected of leading the data theft group ShinyHunters, has been detained and is reportedly cooperating with the FBI to identify other members of...
- According to two sources familiar with the investigation cited by KrebsOnSecurity, the FBI's probe gained urgency due to the attempted extortion of the former Boeing unit.
- Rey's alleged involvement intersects with his family background.
A teenager in Amman, Jordan, suspected of leading the data theft group ShinyHunters, has been detained and is reportedly cooperating with the FBI to identify other members of the hacking syndicate. Reuters reported on October 3, 2026, that Saif Al-din Khader, who uses the hacker handle Rey, was taken into custody by Jordanian authorities. KrebsOnSecurity first identified Rey as Khader in a November 2025 profile, where he admitted working with multiple ransomware groups. The detention occurred while ShinyHunters was extorting Jeppesen ForeFlight, a navigation and digital aviation unit recently divested by global aerospace firm Boeing. Boeing manufactures the aircraft flown by Royal Jordanian Airlines, the employer of Rey’s father.
Extortion Target Involves Boeing Spin-off And Airline Ties
According to two sources familiar with the investigation cited by KrebsOnSecurity, the FBI’s probe gained urgency due to the attempted extortion of the former Boeing unit. The incident involved the theft of sensitive information that sources indicated could pose operational safety and security risks. Boeing sold Jeppesen ForeFlight to private equity firm Thoma Bravo in November 2025 for $10.55 billion. In a statement to KrebsOnSecurity, Boeing acknowledged the extortion claims involving data stolen from the subsidiary, noting an active review with the Jeppesen ForeFlight team. Jeppesen ForeFlight stated that an investigation revealed no impact on operations or products.
Rey’s alleged involvement intersects with his family background. Rey claimed on Telegram in early 2025 that his father worked as a pilot for Royal Jordanian Airlines, an airline mostly controlled by the Jordanian government. While that claim remained unverified, a password-stealing malware infection on the family computer in the November 2025 profile showed Rey’s father using identical credentials across multiple employee portals for Royal Jordanian Airlines. Royal Jordanian Airlines did not respond to requests for comment. Following a media inquiry sent to Rey’s father, Rey deleted his social media accounts, including a Twitter/X account used to taunt the FBI and the Cl0p ransomware group.
PeopleSoft Vulnerability Drove Mass Exploitation And Arrests
The current crackdown follows a series of high-profile cyberattacks tied to the PeopleSoft vulnerability designated as CVE-2026-35273. Security experts at Mandiant and the Google Threat Intelligence Group released a report on September 25, 2026, confirming that ShinyHunters mass-exploited the Oracle software-as-a-service platform to steal data across higher education, technology, healthcare, agriculture, transportation, and government sectors. Oracle issued a patch for the zero-day vulnerability after ShinyHunters began exploiting it in June 2026. BleepingComputer reported in June 2026 that the group’s initial goal was to breach the FBI’s PeopleSoft database, though those attempts failed.
The breach of an FBI recruitment website exposed sensitive records for over 5,000 personnel, including units, specializations, and medical files. Reuters reported on October 5, 2026, that the FBI removed an Accenture contractor over failures to patch the compromised recruitment site. The arrests surrounding the network also include 24-year-old Dutch cybercriminal Pepijn van der Stap, whom Dutch police arrested on September 15, 2026. Following Van der Stap’s arrest, Rey assumed control of the ShinyHunters brand, using memes and the avatar of Van der Stap’s former hacker alias, Umbreon, in an attempt to frame the Dutchman for simultaneous hacks against the FBI and Cl0p.
Collaborator Arrests And Allegations Expand Investigation
Dutch daily RTL reported on September 29, 2026, that investigators suspect Van der Stap tried to orchestrate at least two murders abroad. Van der Stap had recently served part of a four-year prison sentence for extortion and data theft yielding between €1.5 million and €2.7 million. In a September 9, 2026, interview, Van der Stap stated he worked as an offensive security lead at Neo Security. Neo Security owner Benjamin Korper told Reuters that forensic investigators visited his office on September 15, 2026, and that an outside firm found no evidence of malicious activity against Neo Security or its clients.
Within cybercrime channels on Telegram, commentators criticized Rey for hijacking the ShinyHunters name. Administrators of a Telegram server called The Battle stated that Rey caused over $200 million in damages while using group aliases to negotiate ransoms with a 25 to 30 percent cut.
