A teenager in Amman, Jordan, suspected of leading the ShinyHunters data theft and extortion group has been detained and is reportedly cooperating with the FBI to identify other members of the gang. The suspect, who goes by the hacker handle Rey, was held while ShinyHunters was attempting to extort a business unit recently divested by Boeing, the aerospace company whose planes are flown by the employer of Rey's father, Royal Jordanian Airlines.

On October 3, Reuters cited three unnamed sources in reporting that a suspected ShinyHunters member in Amman named Saif Al-din Khader was detained by Jordanian authorities and was cooperating with the FBI. KrebsOnSecurity identified Rey as Khader in a November 2025 profile in which the young man admitted working with multiple ransomware groups. Rey was also the subject of a September 28 report about Dutch police arresting 24-year-old convicted cybercriminal Pepijn van der Stap on suspicion of aiding ShinyHunters in data thefts and extortions.

Following Van der Stap's arrest on the evening of September 15, Rey took control of the ShinyHunters brand and publicly claimed to have stolen sensitive data from the FBI and extorted the ransomware group Cl0p. He taunted both the FBI and Cl0p with memes posted to his Twitter/X account, while including images of the avatar used by Van der Stap's former alias, Umbreon, in an apparent attempt to frame the Dutchman for both hacks.

ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability, CVE-2026-35273, in Oracle's PeopleSoft software-as-a-service platform, which companies broadly use to manage hiring, human resources, benefits and payroll. Oracle quickly issued a fix for the flaw, which ShinyHunters first exploited as a zero-day in June, and Mandiant released web application firewall rules for organizations unable to apply the update quickly enough. ShinyHunters later used a URL-encoding trick to bypass those rules.

In a September 25 report, security experts at Mandiant and the Google Threat Intelligence Group confirmed that ShinyHunters mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across higher education, technology, healthcare, agriculture, transportation and government. Reuters reported October 5 that the FBI removed a contractor at Accenture over a failure to patch the FBI recruitment website, exposing sensitive data on more than 5,000 FBI personnel, including unit and specialization, as well as medical and psychiatric records.

Two sources familiar with the ShinyHunters investigation said a navigation and digital aviation unit recently divested by Boeing was among the victims being extorted when Rey was apprehended, with the theft allegedly including sensitive information that could pose operational safety and security risks. Boeing acknowledged the extortion attempts and said the incident concerned data stolen from Jeppesen ForeFlight, a subsidiary it sold in November 2025 to the private equity firm Thoma Bravo for $10.55 billion.

A Jeppesen ForeFlight spokesperson said the company has seen no impact on its end and that based on its investigation there was no impact to its operations or products. Rey allegedly claimed on Telegram in early 2025 that his father was an airline pilot, and malware that compromised his family's shared computer collected data showing his father used the same credentials at multiple Royal Jordanian Airlines employee portals. Dutch outlet RTL reported September 29 that investigators suspect Van der Stap tried to orchestrate at least two murders abroad.

More company and startup news from TechManNews.