The Fall of ‘Rey’: Inside the Collapse of the ShinyHunters Cyber-Extortion Empire

In a dramatic shift that has sent shockwaves through the global cybercriminal underground, a teenager from Amman, Jordan, suspected of orchestrating the recent resurgence of the notorious hacking collective ShinyHunters, has been detained by local authorities. The suspect, known online by the handle “Rey,” is reportedly cooperating with the FBI, providing investigators with a treasure trove of intelligence on the inner workings of one of the internet’s most persistent and aggressive data theft syndicates.

The detention of the suspect, identified by KrebsOnSecurity as Saif Al-din Khader, marks a turning point in a high-stakes cat-and-mouse game that pitted a young, tech-savvy freelancer against the world’s most powerful law enforcement agencies. Khader’s arrest occurred while the ShinyHunters brand was in the midst of a brazen extortion campaign targeting a business unit recently divested by the global aerospace giant Boeing—a company whose aircraft are central to the operations of the employer of Khader’s own father, Royal Jordanian Airlines.

A Chronology of Chaos: From Prodigy to Informant

The trajectory of the ShinyHunters brand has been anything but linear. Originally emerging in 2019, the group became synonymous with massive data breaches and the sale of billions of records on the dark web. However, the iteration of the group that dominated headlines in 2026 was a far cry from the original collective, most of whom were French nationals who had been apprehended by authorities years prior.

The Rise and Fall of the "Franchise"

Security researchers describe the modern ShinyHunters as a decentralized franchise—a digital version of the Dread Pirate Roberts archetype. Following the September 15 arrest of 24-year-old Dutch cybercriminal Pepijn van der Stap (alias “Umbreon”) by Dutch police, the mantle of the ShinyHunters brand was immediately seized by Khader.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Khader, who had been profiled by KrebsOnSecurity in November 2025 for his ties to ransomware groups, wasted no time. Following the Dutchman’s arrest—a raid involving flash-bang grenades and elite Dutch units—Khader launched a series of high-profile attacks. He openly boasted about infiltrating FBI databases and extorting the infamous ransomware group Cl0p, using social media to taunt both agencies and rival hackers. In a calculated effort to deflect heat, Khader even utilized images of Van der Stap’s “Umbreon” avatar in his posts, attempting to frame the imprisoned Dutchman for his own ongoing exploits.

The PeopleSoft Vulnerability

The technical backbone of this recent crime spree was the mass exploitation of CVE-2026-35273, a critical vulnerability in Oracle’s PeopleSoft platform. Widely used by enterprises for HR, payroll, and benefits management, the software became a prime target for the group.

Beginning in June, ShinyHunters began utilizing this zero-day exploit to harvest data across diverse sectors, including healthcare, education, and government. When security firms like Mandiant issued firewall rules to mitigate the threat, Khader and his associates successfully bypassed these protections using advanced URL-encoding techniques. This persistence allowed them to gain a foothold in sensitive systems, ultimately leading to the exposure of data belonging to over 5,000 FBI personnel, including sensitive medical and psychiatric records—a breach that resulted in the termination of an Accenture contractor responsible for the oversight of the recruitment portal.

The Boeing Connection: A Conflict of Interests

Perhaps the most surreal element of the investigation involves the intersection of Khader’s personal life and his criminal activities. Sources familiar with the FBI investigation confirmed that at the time of his arrest, Khader was actively extorting Jeppesen ForeFlight, a navigation and digital aviation unit that Boeing divested in November 2025 for $10.55 billion.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The irony is striking: Khader’s father is a long-term employee of Royal Jordanian Airlines, a carrier that relies heavily on Boeing’s fleet. In 2025, security researchers discovered that a family computer shared by the Khaders had been compromised by password-stealing malware. The stolen data revealed that the father used identical credentials to access multiple internal portals for Royal Jordanian Airlines, suggesting that the teenager may have had more than just a passing interest in aviation infrastructure.

Following inquiries by the press, Khader abruptly scrubbed his social media presence, including the Twitter/X account used to mock the FBI. However, his GitHub blog remained active, revealing a deep-seated fixation on the Cl0p ransomware group, including a detailed post doxing two Russian men he identified as the core developers of that operation.

Official Responses and Industry Fallout

The repercussions of these breaches have forced a defensive posture from both corporate and government entities.

  • Boeing’s Stance: In a brief statement, a Boeing spokesperson acknowledged the extortion attempts, noting, “We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter.”
  • Jeppesen ForeFlight’s Defense: The subsidiary claimed that its own internal investigation showed no impact on operations, asserting that their "proactive security posture" had shielded their products and data from the fallout.
  • The FBI’s Warning: In May 2026, the FBI issued a rare, pointed advisory regarding ShinyHunters. The agency warned that the group had moved beyond simple data theft, engaging in harassment, swatting, and the weaponization of false claims about sensitive personal information. The hackers, in a bizarre turn, claimed they attacked the FBI specifically to counter this warning, which they perceived as a threat to their "business model."

Implications: A New Era of Digital Mercenaries

The "ShinyHunters" of 2026 represent a dangerous evolution in the cybercrime ecosystem. They are less of a cohesive group and more of a loose confederation of freelancers who leverage the infamy of a stolen brand name to legitimize their extortion demands.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The Murder-for-Hire Allegations

The investigation into Pepijn van der Stap has added a dark, violent dimension to the story. Dutch media reports suggest that Van der Stap—who had been positioning himself as a "reformed" hacker and "offensive security lead" at a Dutch cybersecurity firm—is under investigation for allegedly ordering at least two murders abroad. This revelation has sent shockwaves through the cybersecurity industry, where the "reformed hacker" narrative has long been a subject of debate.

The "Battle" for the Brand

As Khader sits in detention, a Telegram channel aptly named “The Battle” has emerged as the primary source of discourse regarding the group’s collapse. Participants, many of whom are members of the same criminal milieu, have roundly mocked Khader for his "amateurish" attempts to manage the brand. Administrators of the channel claim that Khader’s actions caused upwards of $200 million in damages while simultaneously alienating the criminal community by drawing excessive heat from the FBI.

The Future of Ransomware

The arrest of Khader and the subsequent neutralization of the ShinyHunters brand highlights a critical reality for cybersecurity: the "Dread Pirate Roberts" model of cyber-extortion is inherently unstable. Because the brand is built on a legacy of fear and reputation, it is constantly vulnerable to "succession by arrest." As the FBI and international law enforcement agencies continue to dismantle these nodes of influence, the cybercrime community is being forced to reckon with the fact that no handle, no matter how famous, is beyond the reach of a determined global manhunt.

For now, the digital underworld remains in a state of flux. While the ShinyHunters website has been taken offline, the vulnerability of global infrastructure to persistent, opportunistic extortionists remains a stark reality for the corporate world. As the FBI processes the intelligence provided by "Rey," the industry awaits the next iteration of the brand—or, perhaps, the final realization that the age of the superstar hacker is drawing to a close.