In one of the most significant international cyber-law enforcement operations in recent years, Jordanian security authorities—in close coordination with the Federal Bureau of Investigation (FBI)—have detained Saif Al-din Khader, a teenage cybercriminal operating under the online moniker “Rey.” Suspected of assuming the leadership mantle of the notorious ShinyHunters extortion syndicate, Khader is reportedly cooperating with federal agents to identify key members and affiliates across the globe.
Khader’s apprehension in Amman, Jordan, marks a dramatic turning point in a high-stakes intelligence campaign. At the time of his arrest, Khader was allegedly orchestrating an aggressive extortion attempt against Jeppesen ForeFlight, a premier aviation navigation and logistics firm recently divested by aerospace giant Boeing to the private equity firm Thoma Bravo for $10.55 billion. The breach threatened critical aviation operational security data and highlighted the systemic vulnerabilities lurking within global corporate supply chains.
The takedown of Khader is the latest domino to fall in a sweeping multi-jurisdictional dragnet. Just weeks prior, Dutch authorities conducted a high-risk tactical raid in Amsterdam to arrest 24-year-old Pepijn van der Stap (alias “Umbreon”), a convicted cybercriminal turned security researcher suspected of facilitating ShinyHunters’ data theft operations.
Together, these developments illuminate the fractured, franchise-like evolution of modern ransomware syndicates. What began years ago as a tightly knit network of French threat actors has transformed into an opportunistic, affiliate-driven criminal ecosystem—one characterized by high-profile zero-day exploits, dangerous underground feuds, and volatile extortion campaigns targeting government institutions and Fortune 500 enterprises alike.
Detailed Chronology of the ShinyHunters Collapse
[May 2026] FBI issues Flash Advisory warning against paying ShinyHunters.
[June 2026] ShinyHunters begins exploiting Oracle PeopleSoft zero-day (CVE-2026-35273).
[Sept 15, 2026] Dutch Police execute tactical raid; arrest Pepijn van der Stap ("Umbreon").
[Sept 16-22, 2026] "Rey" takes control of ShinyHunters handles; boasts of FBI/Cl0p breaches.
[Sept 25, 2026] Mandiant & GTIG publish report on mass PeopleSoft zero-day exploitation.
[Sept 28-29, 2026] KrebsOnSecurity contacts Khader's family; Rey purges social media; Dutch press reveals murder-for-hire probe against Van der Stap.
[Oct 3-5, 2026] Jordanian authorities arrest Saif Al-din Khader ("Rey"); Reuters reveals FBI contractor (Accenture) removal over unpatched systems.
1. May – June 2026: The Zero-Day Offensive
The FBI’s Cyber Division issued an aggressive public Flash Advisory warning the global business community against negotiating with or paying ransoms to ShinyHunters. The advisory cited the group’s escalating use of aggressive tactics, including physical swatting, direct harassment of victim executives, and fabricated threats involving non-existent sensitive media.
In response, ShinyHunters initiated a mass-exploitation campaign weaponizing a critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft, a human capital management platform widely used for payroll, hiring, and personnel administration. Although the initial goal was to compromise the FBI’s primary PeopleSoft recruitment infrastructure, early attempts were stymied by initial perimeter controls.
2. September 15, 2026: The Amsterdam Raid
Dutch tactical police executed a dramatic nighttime raid using flash-bang grenades on an apartment in Amsterdam’s Rivierenbuurt neighborhood. Officers arrested Pepijn van der Stap, who had publicly presented himself as a "reformed" cybercriminal serving as the offensive security lead at Dutch firm Neo Security. Investigators seized digital assets connecting Van der Stap to ongoing ShinyHunters extortion schemes.
3. September 16 – 22, 2026: Posturing, Memes, and Frame-Jobs
Following Van der Stap’s arrest, 19-year-old Saif Al-din Khader ("Rey") seized control of ShinyHunters’ public broadcast channels and social media profiles. On platform X (formerly Twitter), Khader posted taunting memes claiming responsibility for exfiltrating sensitive records from an unpatched FBI recruitment portal and extorting the rival Russian ransomware group Cl0p.
In an apparent maneuver to deflect federal scrutiny, Khader deliberately embedded the avatar of "Umbreon"—Van der Stap’s historic alias—into his public posts, attempting to frame the arrested Dutchman for the fresh breaches.
4. September 25 – 29, 2026: The Net Tightens
Security analysts at Mandiant and the Google Threat Intelligence Group (GTIG) published definitive research showing that ShinyHunters had bypassed Mandiant’s recommended Web Application Firewall (WAF) mitigations using a basic URL-encoding evasion technique. The vulnerability was actively being leveraged to plunder databases across higher education, healthcare, technology, and government sectors.
Simultaneously, investigative efforts traced Khader’s real-world identity through compromised log data linked to his father’s employee portal at Royal Jordanian Airlines. Hours after press inquiries were submitted to the family home, Khader panicked and began purging his online footprints, deleting Telegram channels and X accounts. Concurrently, explosive reports surfaced from Dutch media outlet RTL revealing that Van der Stap was under investigation for allegedly soliciting murder-for-hire contracts abroad.
5. October 3 – 5, 2026: Detainments and Contractual Fallout
Jordanian intelligence forces detained Khader in Amman while he was actively negotiating the extortion of Boeing’s former business unit, Jeppesen ForeFlight. Reports confirmed Khader immediately began cooperating with federal agents. Days later, reporting confirmed that the FBI had terminated a third-party contractor at Accenture for failing to apply critical Oracle PeopleSoft patches, which directly enabled the compromise of sensitive medical, psychiatric, and assignment records belonging to more than 5,000 FBI personnel.
Supporting Context & Technical Metrics
Technical Breakdown: The Oracle PeopleSoft Exploit
The technical catalyst behind ShinyHunters’ mid-2026 campaign centered on CVE-2026-35273, a high-severity flaw within Oracle PeopleSoft SaaS instances.
Oracle issued emergency patch; Mandiant released initial WAF rules for unpatched systems.
WAF Evasion
Threat actors adopted custom URL-encoding and character obfuscation to bypass signature checks.
Organizations required full application-level patch deployment; WAF rules proved insufficient.
Data Exfiltration
Automated scraping of backend relational databases containing PII, payroll, and medical disclosures.
Deployment of zero-trust network architectures and strict data loss prevention (DLP) telemetry.
The exploit permitted threat actors to bypass authentication controls and execute direct database queries, leading to mass exfiltration before enterprises could effectively stage enterprise-wide patches.
+------------------------+ Bypass WAF via +-------------------------+
| ShinyHunters / Rey | -----------------------> | Oracle PeopleSoft SaaS |
| Threat Actor Group | URL-Encoding Trick | Vulnerability |
+------------------------+ +-------------------------+
|
v
+-------------------------+
| Database Compromise & |
| Exfiltration of PII |
+-------------------------+
FBI Data Exposure: Over 5,000 agency personnel had their records stolen via an Accenture-managed portal, compromising unit assignments, specialized operational roles, and highly sensitive psychiatric and medical evaluation records.
Corporate Target Value: Jeppesen ForeFlight, the central target during Khader’s arrest, represented a $10.55 billion asset newly acquired by private equity firm Thoma Bravo, carrying sensitive flight-planning and digital aviation intelligence.
Historical Extortion Revenue: Prior legal proceedings against Pepijn van der Stap established that early-stage ShinyHunters campaigns netted illicit revenues estimated between €1.5 million and €2.7 million.
The Cybercrime Franchise Model & Underground Backlash
The structural composition of ShinyHunters has evolved considerably from its origins. Initially driven by a localized core of French hackers—most of whom were arrested between 2021 and 2024—the "ShinyHunters" identity transitioned into a decentralized cybercrime franchise.
ORIGINAL SHINYHUNTERS MODERN FRANCHISE MODEL
+---------------------------+ +---------------------------+
| Core French Hackers | | Brand License / PGP Keys |
| (Centralized Leadership) | | (Controlled by "Rey") |
+---------------------------+ +---------------------------+
| |
v v
+---------------------------+ +---------------------------+
| Direct Breach & Extortion | | Autonomous Affiliates |
| Operations | | (25-30% Cut to Broker) |
+---------------------------+ +---------------------------+
Brand Ownership via PGP Keys: Khader acquired historic PGP keys and darknet credentials associated with the original syndicate, reviving defunct underground channels and the notorious BreachForums platform.
The Affiliate Model: Operating as a broker, Khader allowed independent threat actors to feed stolen SaaS credentials into his brand framework in exchange for a 25% to 30% commission on collected extortion payouts.
Underground Fracture: This commercialization caused significant friction within the cybercrime underground. Monitoring channels such as "The Battle" on Telegram accused Khader of being an inexperienced "greenhorn" who ruined the syndicate’s reputation. Critics alleged that Khader systematically burned darknet assets, failed to protect infrastructure, and brought unnecessary heat from international intelligence agencies by mounting reckless PR stunts against the FBI and rival groups like Cl0p.
The Royal Jordanian Connection
Khader’s exposure was accelerated by poor operational security (OpSec) in his domestic environment. Digital forensic analysis of password-stealing malware logs revealed that a personal computer shared within the Khader household had been infected by an infostealer. The resulting telemetry captured login credentials belonging to Khader’s father across multiple internal employee systems at Royal Jordanian Airlines. Telegram interactions from early 2025 corroborated these findings, where Khader openly boasted that his father flew long-haul commercial routes—aircraft fleets almost entirely manufactured by Boeing.
Official Statements & Responses
The fallout from the investigation has prompted responses across the corporate, cybersecurity, and law enforcement landscapes:
Boeing Spokesperson: "We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter with the Jeppesen ForeFlight team."
Jeppesen ForeFlight Official Statement: "Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."
Benjamin Korper, Owner of Neo Security (regarding former employee Pepijn van der Stap): "An outside firm has been hired to investigate whether Van der Stap hacked Neo Security or its customers. So far, forensic investigators have found no evidence that he acted against his employer or our clients."
Pepijn van der Stap (in an interview prior to his September 15 arrest): "You can throw a bunch of nice words at someone, but you can’t convince them if they don’t want to be convinced. I’m doing what I can to repay victims, and that’s all I can do. If someone doesn’t want to believe me, then that’s on them."
ShinyHunters Command (in statements released to The Register following the FBI hack): "Our attack demonstrated our technical capabilities and directly refuted the misinformation disseminated by the FBI, journalists, and industry researchers… This was fundamentally a public relations and marketing initiative for our business."
Future Outlook & Industry Implications
1. Extraterritorial Law Enforcement Acceleration
The swift arrest and subsequent extradition or cooperation frameworks established between the FBI, Jordanian authorities, and the Dutch National Police reflect a maturing global posture against cybercrime. Sovereignty gaps that historically provided safe harbors for threat actors are closing rapidly, particularly when critical infrastructure, aviation safety, or federal law enforcement databases are compromised.
The FBI’s dismissal of its third-party contractor at Accenture signals a shift toward zero-tolerance accountability for enterprise vendor management. Organizations will face mounting legal and regulatory pressure to mandate strict, real-time patch compliance for external software-as-a-service (SaaS) integrators, moving beyond contractual service-level agreements (SLAs) to active continuous-monitoring enforcement.
3. The Collapse of Ransomware "Brand Equity"
The ShinyHunters saga illustrates the intrinsic instability of brand-name cybercrime syndicates. As original core developers are arrested or driven underground, the franchising of brand names to teenage affiliates leads to volatile decision-making, sloppy operational security, and destructive infighting. Future threat intelligence frameworks will increasingly focus on tracking individual human operators, infrastructure patterns, and broker networks rather than static brand identities.
4. Enterprise Shift Away from SaaS Vulnerability Exposure
The widespread exploitation of CVE-2026-35273 highlights the lingering risks of enterprise SaaS integration. As cybercriminals bypass traditional Web Application Firewalls using simple encoding techniques, security architectures will increasingly transition toward strict identity-based perimeter controls, mandatory micro-segmentation, and rigorous zero-trust frameworks to neutralize initial access before lateral movement can occur.